Step-by-Step Malware Removal Instructions

Nerbian RAT
Trojan

Nerbian RAT

Nerbian is the name of a remote access Trojan (RAT). RATs allow attackers to control infected computers remotely. Nerbian is a RAT written in the Go programming language. It can log keystrokes and capture the screen. It also may have additional capabilities. We discovered it after receiving an ema

Ifla Ransomware
Ransomware

Ifla Ransomware

During a routine inspection of new submissions to VirusTotal, our researchers found the Ifla ransomware-type program. We determined that this piece of malicious software is part of the Djvu ransomware family. After being launched onto our test system, this ransomware encrypted files and appended

Byya Ransomware
Ransomware

Byya Ransomware

Our team discovered Byya while examining the samples submitted to VirusTotal. They found that Byya is ransomware (malware that encrypts files). It appends the ".byya" extension to filenames (for example, renames "1.jpg" to "1.jpg.byya", "2.png" to "2.png.byya"), and generates the "_readme.txt" fil

Kruu Ransomware
Ransomware

Kruu Ransomware

Kruu is ransomware that our malware researchers have discovered while examining samples submitted to the VirusTotal page. We found that Kruu is part of the Djvu ransomware family. It encrypts files and appends the ".Kruu" extension to filenames. Also, it creates the "_readme.txt" file that contain

YouPDFSearch Browser Hijacker
Browser Hijacker

YouPDFSearch Browser Hijacker

After analyzing the YouPDFSearch browser extension, our researchers determined that it is a browser hijacker. Following successful installation onto our test machine, we learned that YouPDFSearch makes changes to browser settings in order to promote the youpdfsearch.com fake search engine.

Freenotifications.com Ads
Notification Spam

Freenotifications.com Ads

Freenotifications[.]com is a rogue website that our researchers found during a routine inspection of untrustworthy sites. This page is designed to push browser notification spam and redirect visitors to other (likely dubious/malicious) websites. Users typically access such webpages via redirects c

SearchZubi Browser Hijacker
Browser Hijacker

SearchZubi Browser Hijacker

SearchZubi is a browser extension, which we determined to be a browser hijacker. This piece of software modifies browser settings to promote the searchzubi.com fake search engine. When we installed SearchZubi onto our test system, it assigned searchzubi.com as the browser's default search

Donation Grant For You Email Scam
Phishing/Scam

Donation Grant For You Email Scam

After inspecting the "Donation Grant For You" email, we determined that it is spam. These scam letters attempt to trick recipients into believing that they will receive a massive amount of money as support to individuals and businesses suffering economic setbacks. This mail claims that recipients'

Blandcaptcha.top Ads
Notification Spam

Blandcaptcha.top Ads

While inspecting untrustworthy sites, we found the blandcaptcha[.]top webpage. It promotes browser notification spam through the use of fake CAPTCHA verification. Additionally, this page is capable of redirecting visitors to other (likely unreliable/malicious) websites. Most users enter pages lik

SearchMok Browser Hijacker
Browser Hijacker

SearchMok Browser Hijacker

SearchMok is a browser hijacker designed to promote a fake search engine. It hijacks a web browser by changing some of its settings to searchmok.com. Typically, browser-hijacking apps are promoted using questionable pages and other methods. We have discovered SearchMok while inspecting deceptive w