Step-by-Step Malware Removal Instructions

DeFi Protocol Authentication Scam
Phishing/Scam

DeFi Protocol Authentication Scam

Our team has discovered that this is a scam website designed to trick visitors into revealing sensitive information. It is disguised as a DeFi Protocol platform to appear legitimate. Falling for this scam can result in irreversible cryptocurrency theft. Thus, if encountered, this page should be cl

News-gikaji.com Ads
Notification Spam

News-gikaji.com Ads

News-gikaji[.]com is a rogue webpage designed to deceive visitors into permitting browser notification delivery. Additionally, this page can produce redirects to different (likely unreliable/malicious) websites. Most users access news-gikaji[.]com and similar webpages via redirects caused by sites

News-gebece.com Ads
Notification Spam

News-gebece.com Ads

While reviewing suspect websites, our research team happened upon news-gebece[.]com. This rogue page operates by promoting browser notification spam. It can also redirect users to other (likely unreliable/hazardous sites. News-gebece[.]com and similar webpages are most commonly accessed via redire

Chainlink Treasury Pool Scam
Phishing/Scam

Chainlink Treasury Pool Scam

We have examined this website (chain.link-treasurypools[.]com) and found that it is a fraudulent website offering to claim free tokens. Also, the site mimics the original Chainlink platform (chain.link) to appear legitimate. The purpose of the fake page is to drain victims' wallets. IMPORTAN

CCLand Ransomware
Ransomware

CCLand Ransomware

Our team discovered CCLand during an analysis of samples uploaded to VirusTotal. Upon inspecting the malware, we concluded that it is ransomware that encrypts files. In addition to encrypting data, CCLand appends the ".ccl" extension to filenames and drops a ransom note, "RECOVER_README.txt". An

Ouseperwaganis.com Ads
Notification Spam

Ouseperwaganis.com Ads

We have found that ouseperwaganis[.]com is designed to mislead users into consenting to get its notifications. If allowed, it can send deceptive messages, such as fake alerts, to promote shady websites. Because of this, the site (and others like it) should be avoided, and any notification requests

Ptifirelaria.com Ads
Notification Spam

Ptifirelaria.com Ads

Ptifirelaria[.]com is a rogue webpage discovered by our researchers during a routine investigation. After inspecting this page, we learned that it endorses spam browser notifications and redirects users to other (likely dubious/harmful) sites. Most visitors to ptifirelaria[.]com and similar webpag

Advoiderce.com Ads
Notification Spam

Advoiderce.com Ads

While browsing untrustworthy sites, our research team discovered the advoiderce[.]com rogue webpage. Upon examination, we found that it is yet another site that promotes browser notification spam through a CAPTCHA-themed lure. This page can also redirect users elsewhere, likely unreliable or malic

BAFAIAI Ransomware
Ransomware

BAFAIAI Ransomware

Our researchers found the BAFAIAI ransomware while inspecting new file submissions to the VirusTotal site. This malicious program is part of the MedusaLocker ransomware family. BAFAIAI encrypts files and creates a ransom note. It adds a ".BAFAIAI" extension to their filenames. For example, a file

Eternidade Stealer
Trojan

Eternidade Stealer

Eternidade is a malicious program written in the Delphi programming language. It is a stealer and banking trojan capable of extracting sensitive data from infected devices. Eternidade has been used to target users in Brazil. This malware can self-spread through WhatsApp spam. Eternidade is