Step-by-Step Malware Removal Instructions

YTStealer Malware
Trojan

YTStealer Malware

YTStealer is a piece of malicious software classified as a stealer. Malware within this category aims to steal a wide variety of sensitive data. However, YTStealer targets very specific information - one relating to victims' YouTube accounts. Thus the goal of the attackers behind this program is t

Harditem Ransomware
Ransomware

Harditem Ransomware

Harditem is a malicious program based on the Prometheus ransomware. We obtained a sample of this ransomware from VirusTotal. After Harditem was launched on our test machine, it encrypted files and appended their filenames with the ".harditem" extension. For example, a file initially titled "1.jpg

Tail Web Browser Hijacker
Browser Hijacker

Tail Web Browser Hijacker

Tail web is the name of an application that our team has discovered while inspecting shady websites. After downloading and adding this app to a browser, we found that it changes some settings. It hijacks a web browser to promote tailsearch.com. While testing this site, we found that it is a fake s

PortalUltra Adware (Mac)
Mac Virus

PortalUltra Adware (Mac)

PortalUltra is an application that our team has discovered after using a fake installer downloaded from a deceptive website. It was found that PortalUltra is a useless application designed to display annoying advertisements. Thus, we categorized this app as adware. Clicking ads (pop-ups,

Llqq Ransomware
Ransomware

Llqq Ransomware

Our malware researchers have discovered another ransomware belonging to the Djvu family called Llqq while examining malware samples submitted to the VirusTotal site. Llqq is designed to encrypt files and append its extension (".llqq" to filenames). It also creates a text file ("_readme.txt") conta

Serviceworker.click Ads
Notification Spam

Serviceworker.click Ads

While researching untrustworthy sites, we found the serviceworker[.]click rogue webpage. It promotes scams, pushes browser notification spam, and redirects visitors to different (likely dubious/malicious) websites. Most users enter such pages through redirects caused by sites using rogue advertis

Code Core Ransomware
Ransomware

Code Core Ransomware

While looking through new submissions to VirusTotal, our researchers discovered the Code Core ransomware. Malicious programs within this category are designed to encrypt data and demand ransoms for the decryption. Once a sample of Code Core was executed on our test machine, it encrypted files and

Chc Energy Email Virus
Phishing/Scam

Chc Energy Email Virus

After inspecting this "Chc Energy" email, we determined that it is spam designed to proliferate malware (malspam). This letter is presented as a notification regarding a blocked registration with CHC ENERGY. It must be emphasized that these fake emails are in no way associated with this or any ot

Skip Over Ads Adware
Adware

Skip Over Ads Adware

Skip Over Ads is the name of a rogue browser extension that our researchers discovered while inspecting dubious download sites. This piece of software promises to block and/or auto-skip advertisements on YouTube. Instead, as our analysis revealed, Skip Over Ads operates like adware - software that

Bahamut Spyware (Android)
Trojan

Bahamut Spyware (Android)

Bahamut is the name of Android malware with spyware functionality. Threat actors use Bahamut to steal sensitive information. The newest malware version targets various messaging apps and personally identifiable information. Once downloaded, installed, and launched, Bahamut asks to enable v