Step-by-Step Malware Removal Instructions

Servicio De Administración Tributaria Email Scam
Phishing/Scam

Servicio De Administración Tributaria Email Scam

Our team has examined this email and learned that it is part of a phishing campaign. Scammers behind it attempt to trick recipients into providing sensitive information via the provided website. The email is disguised as a letter from the Ministry of Finance of Spain. It is written in the Spanish

ZareuS Ransomware
Ransomware

ZareuS Ransomware

ZareuS is ransomware that encrypts files and appends the ".ZareuS" extension to filenames. We discovered this ransomware on the VirusTotal page (while checking the page for recently submitted samples). ZareuS provides contact and payment instructions in its ransom note, a text file named "HELP_DEC

ElementForce Adware (Mac)
Mac Virus

ElementForce Adware (Mac)

While inspecting new submissions to VirusTotal, our research team discovered the ElementForce application. After analyzing this piece of software, we learned that it is adware belonging to the AdLoad malware family. Adware enables the placement of third-party graphical content (various a

BasicTransaction Adware (Mac)
Mac Virus

BasicTransaction Adware (Mac)

BasicTransaction is the name of a rogue application that we found while inspecting new submissions to VirusTotal. Our analysis of this app revealed that it operates as advertising-supported software (adware) and belongs to the AdLoad malware family. Adware is designed to deliver intrusiv

Moonshadow Ransomware
Ransomware

Moonshadow Ransomware

While inspecting new malware submissions to VirusTotal, our researchers discovered the Moonshadow ransomware. We determined that this malicious program is part of the VoidCrypt ransomware family. After we launched a sample of Moonshadow on our test system, it encrypted files and altered their nam

FIXED Ransomware
Ransomware

FIXED Ransomware

Our team discovered FIXED while inspecting malware samples submitted to the VirusTotal page. We found that FIXED is ransomware that encrypts files and appends ".FIXED" extension to filenames. For example, it renames "1.jpg" to "1.jpg.FIXED", "2.png" to "2.png.FIXED", and so forth. Also, FIXED crea

News-fesihe.cc Ads
Notification Spam

News-fesihe.cc Ads

News-fesihe[.]cc is designed to trick visitors into agreeing to receive notifications and redirect them to other shady pages. As a rule, pages like news-fesihe[.]cc are visited inadvertently. Our team has discovered news-fesihe[.]cc while examining various illegal movie streaming pages, torrent si

R3tr0 Ransomware
Ransomware

R3tr0 Ransomware

R3tr0 (also known as RETRO-ENCRYPTED) is ransomware belonging to the Dharma family. We discovered it while checking the VirusTotal website for recently submitted malware samples. R3tr0 encrypts files and appends the victim's ID, r3tr0crypt@tuta.io email address, and ".r3tr0" extension to filenames

EfficientRecord Adware (Mac)
Mac Virus

EfficientRecord Adware (Mac)

EfficientRecord is a rogue application that our research team discovered while inspecting new submissions to VirusTotal. After analyzing this app, we determined that it operates as advertising-supported software (adware) and belongs to the AdLoad malware family. Adware is designed to dis

Scan-pro-guard.com Ads
Notification Spam

Scan-pro-guard.com Ads

During a routine inspection of questionable websites, our research team discovered the scan-pro-guard[.]com page. It promotes deceptive content, pushes spam browser notifications, and redirects visitors to different (likely untrustworthy/malicious) sites. Most users enter webpages like scan-pro-g