Step-by-Step Malware Removal Instructions

LogicCheck Adware (Mac)
Mac Virus

LogicCheck Adware (Mac)

LogicCheck is an adware-type application that generates advertisements and can read webpage contents and browsing history. We have discovered this application while inspecting deceptive pages offering to install software updates. In most cases, apps like LogicCheck are downloaded and installed u

Solana POP-UP Scam
Phishing/Scam

Solana POP-UP Scam

We have examined this page and concluded that it is a fake Solana website (an identical copy) offering to register for participation in an ignition hackathon and win up to $5 million in prizes. Typically, scams of this kind are promoted via Twitter, Discord, Telegram, and other sites or apps, vari

Whisper Stealer Malware
Trojan

Whisper Stealer Malware

Whisper Stealer is an information stealer targeting Chromium and Gecko browsers, cryptocurrency wallets, Discord tokens, and Telegram sessions (and other data). It is promoted (and sold) on hacker forums. There are five available subscription plans: 250 rubles for one month, 600 rubles for three

ActiveHandler Adware (Mac)
Mac Virus

ActiveHandler Adware (Mac)

ActiveHandler is a rogue application that our researchers discovered while inspecting new submissions to VirusTotal. After analyzing this app, we determined that it operates as adware and is part of the AdLoad malware family. Adware may require certain conditions (e.g., system/browser or

ZombieBoy Trojan
Trojan

ZombieBoy Trojan

ZombieBoy is the name of a cryptomining Trojan that uses the EternalBlue exploit to spread and DoublePulsar backdoor to load and execute its modules. It is used for cryptocurrency mining and remote control. Additionally, it includes an intranet scanner module. ZombieBoy's remote access mod

Webpushpull.com Ads
Notification Spam

Webpushpull.com Ads

Our research team discovered the webpushpull[.]com rogue webpage while inspecting shady sites. It is designed to promote browser notification spam and redirect visitors to other (likely untrustworthy/malicious) websites. Most users enter such pages through redirects caused by websites that use ro

Youtube_ad_remover Adware
Adware

Youtube_ad_remover Adware

While inspecting dubious download pages, our research team discovered the youtube_ad_remover browser extension. Based on its name, we can presume that this extension promises to eliminate advertisements displayed on YouTube videos. After analyzing the youtube_ad_remover browser extension, we dete

Saumeechoa.com Ads
Notification Spam

Saumeechoa.com Ads

Saumeechoa[.]com is a rogue webpage that loads dubious content, promotes browser notification spam, and redirects visitors to other (likely unreliable or malicious) sites. Our researchers found this page while inspecting untrustworthy websites. Users typically access rogue sites unintentionally. M

Notfreeads.com Ads
Notification Spam

Notfreeads.com Ads

Notfreeads[.]com is an untrustworthy website that uses a clickbait technique to trick visitors into allowing it to show notifications. Also, it redirects visitors to another virtually identical page (notadslife[.]com). We have discovered notfreeads[.]com while inspecting illegal movie streaming si