Step-by-Step Malware Removal Instructions

SMSSpy Malware (Android)
Trojan

SMSSpy Malware (Android)

SMSSpy refers to a piece of malicious software masquerading as various applications of legitimate e-commerce platforms. This malware aims to obtain victims' online banking credentials and thus gain access to the funds stored in the accounts. At the time we researched SMSSpy, it targeted Malaysian

Sapphire Miner Malware
Trojan

Sapphire Miner Malware

Sapphire is the name of a cryptocurrency miner. This malware is sold in hacker forums for 75 euros. Sapphire can mine XMR (Monero), ERGO, ETC (Ethereum Classic), and ETH (Ethereum) cryptocurrencies. Additionally, this miner can avoid being detected by Windows Defender, hide from Task Manager and

Ghas Ransomware
Ransomware

Ghas Ransomware

During a routine inspection of VirusTotal submissions, our research team discovered yet another ransomware-type program belonging to the Djvu family. The program in question is named - Ghas. Once launched onto our test machine, this ransomware began encrypting files and appending their filenames

MATILAN Ransomware
Ransomware

MATILAN Ransomware

We have discovered MATILAN while inspecting malware samples submitted to VirusTotal. It was found that MATILAN is ransomware designed to encrypt files, append the ".MATILAN" extension to filenames, and generate three ransom notes. Before logging into Windows, a ransom note appears on a black scre

Qall Ransomware
Ransomware

Qall Ransomware

Qall is a ransomware-type program that our researchers found while inspecting new malware submissions to VirusTotal. We determined that this malicious program belongs to the Djvu ransomware family. After being executed on our test system, this ransomware encrypted files and appended their filenam

Hajd Ransomware
Ransomware

Hajd Ransomware

Hajd is the name of ransomware belonging to the Djvu ransomware family. Our team has discovered this variant on VirusTotal. Hajd encrypts files and appends the ".hajd" extension to their filenames. Also, it creates a text file named "_readme.txt". This file contains a ransom note. An example of h

Qpss Ransomware
Ransomware

Qpss Ransomware

Our team has discovered a new ransomware variant belonging to the Djvu family called Qpss. The purpose of Qpss is to encrypt files. Additionally, it appends the ".qpss" extension to filenames and creates the "_readme.txt" file (a ransom note). We have found this ransomware while examining malware

Systemsecuritys.com Ads
Notification Spam

Systemsecuritys.com Ads

Systemsecuritys[.]com is a rogue webpage that our researchers found while inspecting dubious websites. This page is designed to load deceptive material, push browser notification spam, and redirect visitors to other (likely unreliable/malicious) sites. Most users enter systemsecuritys[.]com and s

PancakeSwap Email Scam
Phishing/Scam

PancakeSwap Email Scam

After inspecting this "PancakeSwap" email, our researchers determined that it is spam that operates as a phishing scam. The letter claims that the recipient's cryptocurrency wallet will be suspended if it is not validated. This spam mail promotes a phishing page, which closely mimics the genuine P

FFDroider Stealer
Trojan

FFDroider Stealer

FFDroider is a malicious program classified as a stealer. It is designed to extract and exfiltrate sensitive data from infected devices. FFDroider targets popular social media and e-commerce platforms in particular. FFDroider has been observed evading detection by masquerading as the Teleg