Step-by-Step Malware Removal Instructions

Mlock Ransomware
Ransomware

Mlock Ransomware

During a routine inspection of new submissions on VirusTotal, our researchers found yet another ransomware-type program belonging to the MedusaLocker family. This malicious program named Mlock - encrypted and renamed the files on our test machine. It added the ".mlock5" extension to filenames, e.

Meovideo.ru Ads
Notification Spam

Meovideo.ru Ads

We have discovered the meovideo[.]ru while visiting illegal movie streaming, adult dating, torrent, and similar sites that use questionable advertising networks. After examining meovideo[.]ru, we learned that it displays deceptive content to trick visitors into agreeing to receive untrustworthy no

BestMusicSearches Browser Hijacker
Browser Hijacker

BestMusicSearches Browser Hijacker

BestMusicSearches is a rogue browser extension. After analyzing it, our researchers classified it as a browser hijacker. BestMusicSearches operates by modifying browser settings to promote (via redirects) the bestmusicsearches.com fake search engine. Following installation onto our test sy

BATLOADER Malware
Trojan

BATLOADER Malware

BATLOADER is part of the infection chain where it is used to perform the initial compromise. This malware is used to execute payloads like Ursnif. Our team has discovered BATLOADER after executing installers for legitimate software (such as Zoom, TeamViewer Visual Studio) bundled with this malware

Power Off Adware
Adware

Power Off Adware

Power Off is a rogue application supposedly capable of managing program processes, e.g., launching, scheduling, restarting, shutting down, etc. Our researchers determined that this piece of software operates as advertising-supported software (adware) - by running intrusive advertisement campaigns.

360 Ransomware
Ransomware

360 Ransomware

Discovered by Boanbird, 360 is the name of a ransomware-type program. When we launched a sample on our test system, it encrypted files and appended their filenames with the ".360" extension. For example, a file originally titled "1.jpg" appeared as "1.jpg.360", "2.jpg" as "2.jpg.360", and so on. O

Worldcoolfeed.com Ads
Notification Spam

Worldcoolfeed.com Ads

Worldcoolfeed[.]com is a deceptive website that we have discovered while examining torrent, illegal movie streaming, and similar sites that use questionable advertising networks. We found that the purpose of worldcoolfeed[.]com is to trick visitors into allowing it to show notifications and redire

Gomorrah Stealer
Trojan

Gomorrah Stealer

Gomorrah is an information-stealing malware. We obtained a sample from VirusTotal and subsequently analyzed this malicious program. We discovered that it primarily targets account credentials and credit card numbers. Gomorrah stealer begins its operations by gathering data about the follow

Cat4er Ransomware
Ransomware

Cat4er Ransomware

During a routine inspection of new malware submissions to VirusTotal, our research team found the Cat4er ransomware. When a sample was launched on our test machine, this malware encrypted files and appended them with the ".Cat4er" extension. For example, a filename like "1.jpg" appeared as "1.jpg

Chillsearch.xyz Redirect (Mac)
Mac Virus

Chillsearch.xyz Redirect (Mac)

The chillsearch.xyz address (a fake search engine) became known to us after using a couple of fake Adobe Flash Player installers downloaded from deceptive websites. We have found that those installers hijacked a web browser - our browser opened chillsearch.xyz every time we entered a search quer