Step-by-Step Malware Removal Instructions

RDP Stealer
Trojan

RDP Stealer

RDP stealer is a malicious program that targets Remote Desktop Protocol (RDP) log-in credentials. Its developers are offering this stealer for sale on the Web. Hence, how this malware is distributed depends on the cyber criminals using it at the time. This stealer targets specific informat

ParaceratheriumBugtiense Malicious Extension
Adware

ParaceratheriumBugtiense Malicious Extension

In the course of our examination of the ParaceratheriumBugtiense browser extension, we came across troubling activities, including the activation of the "Managed by your organization" function in Chrome settings and the collection of user data. Our encounter with ParaceratheriumBugtiense stemmed f

Loda RAT
Trojan

Loda RAT

Loda, a remote access trojan (RAT), has remained actively employed by various threat actors since 2016. Its capabilities encompass activities like password theft, collecting sensitive data, keylogging, screen capture, and disseminating additional malicious payloads. Typically, Loda is delivered vi

Rapid Spell Check Extension Browser Hijacker
Browser Hijacker

Rapid Spell Check Extension Browser Hijacker

Upon evaluating Rapid Spell Check Extension, it became evident that its primary intention is to function as a browser hijacker, aiming to promote find.msrc-nav.com, a fake search engine. This extension alters browser settings to assert control. To prevent potential harm, users whose browsers have

Adobe PDF Shared Email Scam
Phishing/Scam

Adobe PDF Shared Email Scam

Upon inspecting this email, we determined it to be a phishing attempt, posing as a notification regarding a shared document. Scammers employ this method to deceive recipients into visiting a fake website and divulging sensitive information. Consequently, we strongly advise recipients to refrain fr

IchthyostegaStensioei Malicious Extension
Adware

IchthyostegaStensioei Malicious Extension

During our investigation into the IchthyostegaStensioei browser extension, we discovered concerning actions such as enabling the "Managed by your organization" feature within Chrome settings and gathering user data. Our encounter with IchthyostegaStensioei arose as a result of our examination of a

Getpotectnow.click Ads
Notification Spam

Getpotectnow.click Ads

While checking out suspect websites, our research team discovered the getpotectnow[.]click rogue page. It operates by promoting scams and browser notification spam. This webpage can also redirect visitors to different (likely dubious/malicious) sites. Most users access pages like getpotectnow[.]c

Generalprotection.click Ads
Notification Spam

Generalprotection.click Ads

Generalprotection[.]click is a rogue page that our researchers discovered during a routine inspection of dubious websites. It is designed to run scams and push spam browser notifications. Additionally, this webpage can redirect users to other (likely unreliable/dangerous) sites. Visitors to gener

Alvaro Ransomware
Ransomware

Alvaro Ransomware

Alvaro is a ransomware-type program designed to encrypt files and demand ransoms for their decryption. After we launched a sample of Alvaro on our test system, it encrypted files and altered their filenames. Titles of the affected files were appended with the attackers' email, a unique ID assigne

Incoming Messages Were Not Delivered Email Scam
Phishing/Scam

Incoming Messages Were Not Delivered Email Scam

Our inspection of the "Incoming Messages Were Not Delivered" email revealed that it is spam. This letter claims that several messages failed to reach the recipient's inbox. This mail targets email passwords, which are extracted through a phishing site disguised as an account sign-in page.