Step-by-Step Malware Removal Instructions

Dewd Ransomware
Ransomware

Dewd Ransomware

We have discovered a new Djvu ransomware variant called Dewd. It was discovered while analyzing the samples submitted to VirusTotal. After testing this ransomware, we found that it encrypts files and appends the ".dewd" extension to filenames. Also, it creates a text file named "_readme.txt". This

Thefreeadv.com Ads
Notification Spam

Thefreeadv.com Ads

Thefreeadv[.]com is a rogue site that our researchers discovered while inspecting shady websites. It operates by promoting spam browser notifications through deception, and this page can also redirect visitors to others (likely harmful/malicious ones). Users typically access webpages like thefree

Keep Your PC Updated With Norton! POP-UP Scam
Phishing/Scam

Keep Your PC Updated With Norton! POP-UP Scam

While inspecting rogue webpages, we discovered the "Keep Your PC Updated With Norton!" scam. This scheme implies that the user's system may be infected and is at risk, and urges them to keep their Norton anti-virus subscription up-to-date. At the time of research, this scam redirected to the offi

LokiLok Ransomware
Ransomware

LokiLok Ransomware

LokiLok is a piece of malicious software classified as ransomware, which our researchers discovered while inspecting new submissions to VirusTotal. After analyzing LokiLok, we determined that it is based on a ransomware-type program called Chaos. Once launched onto our test machine, LokiLok encry

Star-search.xyz Redirect
Browser Hijacker

Star-search.xyz Redirect

Star-search.xyz is a fake search engine that shows results generated by Bing. It does not generate any unique search results. Typically, fake search engines are promoted through browser hijackers. Most apps of this type are promoted/distributed using questionable methods. We have discovered star-s

Posttrendingblog.com Ads
Adware

Posttrendingblog.com Ads

Posttrendingblog[.]com is one of the many websites designed to trick visitors into allowing them to show notifications. Like most pages of this type, posttrendingblog[.]com displays deceptive contents. It also can redirect visitors to other websites of this kind. We have discovered posttrendingblo

ZipSome Adware (Mac)
Mac Virus

ZipSome Adware (Mac)

ZipSome is an adware-type application that we discovered during a routine inspection of new VirusTotal detections. We learned that this app runs intrusive advertisement campaigns (i.e., display) ads. Furthermore, we determined that ZipSome belongs to the AdLoad malware family. Adware-del

TopConverterSearch Browser Hijacker
Browser Hijacker

TopConverterSearch Browser Hijacker

We have discovered the TopConverterSearch application while inspecting various shady websites. After downloading and installing it, we found that it is a browser hijacker designed to promote topconvertersearch.com (a fake search engine). TopConverterSearch hijacks a web browser by modifying its se

SECRETO PROFESIONAL Y CONFIDENCIAL Email Virus
Phishing/Scam

SECRETO PROFESIONAL Y CONFIDENCIAL Email Virus

Our inspection of the "SECRETO PROFESIONAL Y CONFIDENCIAL" email revealed that it is spam used to proliferate malware. This letter is in Spanish and claims to contain highly confidential information in the attachment (although it does not specify further). This email is designed to trick recipien

Hachiman Screenlocker
Ransomware

Hachiman Screenlocker

Hachiman is screen-locking ransomware that locks the screen (operates as a screen locker) and displays a ransom note explaining how to unlock the screen. Hachiman was discovered by Karsten Hahn. It is worth mentioning that Hachiman does not encrypt any files. Screenshot of the ransom note disp