Step-by-Step Malware Removal Instructions

ZLoader Malware
Trojan

ZLoader Malware

ZLoader (also known as DELoader and Terdot) is a malicious program distributed through malicious web pages that display a fake error notification (e.g., "The 'Roboto Condensed' font was not found"). Research shows that ZLoader infects systems with another malicious program, a banking Trojan calle

Afrodita Ransomware
Ransomware

Afrodita Ransomware

Discovered by S!Ri, Afrodita is a part of the LockerGoga ransomware family. It encrypts data with the AES-256 and RSA-2048 encryption algorithms.  Afrodita also creates a ransom message within the "__README_RECOVERY_.txt" text file, which contains instructions about how to contact cyber criminals

Y2meta.com Suspicious Website
Adware

Y2meta.com Suspicious Website

Avoid the y2meta[.]com website, since it employs dubious advertising networks and provides an illegal video downloading service. Note that it is illegal to download videos from YouTube. Furthermore, y2meta[.]com contains various ads that redirect visitors to other untrustworthy websites. These are

Checkmail7@protonmail.com Ransomware
Ransomware

Checkmail7@protonmail.com Ransomware

Discovered by S!Ri and further researched by Raby, checkmail7@protonmail.com (or simply CheckMail) is a malicious program categorized as ransomware. It operates by encrypting data and demanding ransom payments for decryption. During the encryption process, this malware appends files with an exten

Bo3news.biz Redirect
Adware

Bo3news.biz Redirect

bo3news[.]biz redirects visitors to a variety or untrustworthy, potentially malicious websites. Browsers are often forced to open sites such as bo3news[.]biz by potentially unwanted applications (PUAs) installed on browsers or operating systems. In any case, people do not open them intentionally.

Dever Ransomware
Ransomware

Dever Ransomware

Belonging to the Phobos malware family, Dever is a ransomware-type malicious program. Infected devices have their data encrypted and a ransom is demanded from the victims for decryption software/tools. When Dever encrypts files, it renames them according to the following pattern: unique ID, devel

This Is A VIRUS. You Computer Is Blocked (File) Scam
Phishing/Scam

This Is A VIRUS. You Computer Is Blocked (File) Scam

"This is a VIRUS. You computer is blocked" is another technical support scam used by cyber criminals who claim to offer legitimate 'technical support'. They attempt to trick people into believing that their computers are infected/blocked and to make contact via the telephone number provided. Most

Olaldo.com Ads
Notification Spam

Olaldo.com Ads

When visited, olaldo[.]com opens a number of untrustworthy, deceptive websites including those that attempt to trick people into installing unwanted, potentially malicious software, participate in fake lotteries, and so on. Typically, browsers open websites such as olaldo[.]com automatically when

BitPyLock Ransomware
Ransomware

BitPyLock Ransomware

Discovered by MalwareHunterTeam, BitPyLock is malicious software classified as ransomware. Infected systems have their data encrypted and receive ransom demands for decryption tools. When BitPyLock encrypts, affected files are renamed with the ".bitpy" extension. For example, a filename like "1.j

Kangaroo (Apocalypse) Ransomware
Ransomware

Kangaroo (Apocalypse) Ransomware

Kangaroo ransomware was discovered by S!Ri. Like other software of this type, Kangaroo encrypts data, appends its own extension to the filename of each encrypted file and creates ransom messages. This ransomware renames all encrypted files by appending the ".missing" extension. For example, "1.jp