Step-by-Step Malware Removal Instructions

Safewinodws.com Ads
Notification Spam

Safewinodws.com Ads

During a routine inspection of rogue sites, our researchers discovered safewinodws[.]com. This webpage is designed to load deceptive content, promote browser notification spam, and redirect visitors to other unreliable/harmful pages. Most visitors to safewinodws[.]com and websites akin to it - en

SearchAim Adware (Mac)
Mac Virus

SearchAim Adware (Mac)

We have discovered the SearchAim application after executing a fake Adobe Flash Player installer downloaded from a deceptive page. While installed, SearchAim displayed various untrustworthy advertisements. Thus, we have concluded that SearchAim is an advertising-supported application. Ou

OpenSea Email Scam
Phishing/Scam

OpenSea Email Scam

The "OpenSea email scam" refers to a phishing spam campaign targeting OpenSea - NFT (Non-Fungible Token) marketplace accounts. These fake letters lure recipients into disclosing their account log-in credentials by claiming that they need to move their listings to avoid their expiration and additio

Ourcoolposts.com Ads
Notification Spam

Ourcoolposts.com Ads

Ourcoolposts[.]com is a website that uses a clickbait technique to trick visitors into allowing it to show notifications. We have discovered ourcoolposts[.]com while clicking on shady ads and visiting pages that use questionable advertising networks. In most cases, sites like ourcoolposts[.]com ge

Gcyi Ransomware
Ransomware

Gcyi Ransomware

Gcyi is a ransomware-type program designed to encrypt data and demand ransoms for the decryption. Our researchers found and obtained a sample of this malware from VirusTotal. We have determined that Gcyi belongs to the Djvu ransomware family. During analysis, this ransomware appended the filename

MURK Ransomware
Ransomware

MURK Ransomware

MURK is ransomware that was discovered by our team while examining the malware samples submitted to VirusTotal. It was found that MURK encrypts files (and modifies their filenames) and generates two files containing ransom notes - "info.txt" and "info.hta". It is part of the Phobos ransomware fami

TradeValor Adware (Mac)
Mac Virus

TradeValor Adware (Mac)

We have discovered the TradeValor application after clicking on a pop-up displayed by a deceptive page, implying that Adobe Flash Player is out of date. After installation, TradeValor started showing annoying advertisements. Thus, we concluded that TradeValor is an advertising-supported applicat

Worthyrid.com Ads
Notification Spam

Worthyrid.com Ads

During a routine inspection of rogue websites, our research team found the worthyrid.com site. It pushes browser notification spam and redirects visitors to other untrustworthy/harmful pages. Users typically access webpages like worthyrid[.]com via redirects caused by sites using deceptive adverti

SpeedTestMe Adware
Adware

SpeedTestMe Adware

Discovered by our researchers while inspecting sites that use rogue advertising networks, SpeedTestMe is a browser extension endorsed as an Internet speed testing tool. It is supposedly capable of measuring webpage loading times, download speeds, etc. Having analyzed this extension, we can conclud

Qmam4 Ransomware
Ransomware

Qmam4 Ransomware

Qmam4 is a piece of malicious software categorized as ransomware. Our research team found this malware during a routine inspection of new submissions on VirusTotal. While analyzing a sample of Qmam4, we learned that it renames the encrypted files by appending their filenames with a random charact