Step-by-Step Malware Removal Instructions

PINEFLOWER Malware (Android)
Trojan

PINEFLOWER Malware (Android)

PINEFLOWER is the name of a malware family targeting Android operating systems. Malicious programs belonging to PINEFLOWER have a wide variety of functionalities, e.g., the ability to cause chain infections (download/install additional malware), steal data, spy, and others. Mandiant researchers h

Gallery Adware
Adware

Gallery Adware

While examining a suspicious page, we discovered an unreliable application called Gallery. After downloading and installing this app, we learned that it generates advertisements (it functions as adware). We also noticed several processes named "nwjs" running in the Task manager while the Gallery a

BluelightFurry Adware (Mac)
Mac Virus

BluelightFurry Adware (Mac)

BluelightFurry is a rogue app that our researchers found while investigating new submissions to VirusTotal. After analyzing this application, we determined that it is adware belonging to the AdLoad malware family. BluelightFurry operates by running intrusive ad campaigns, and it may also have br

Request To Terminate/Disable Your Email Scam
Phishing/Scam

Request To Terminate/Disable Your Email Scam

After inspecting this email, we learned that it is sent by scammers who aim to trick unsuspecting recipients into providing personal information. The scammers behind this email are pretending to be email service providers. They use a phishing website to extract information from recipients.

Gaqtfpr Ransomware
Ransomware

Gaqtfpr Ransomware

Our research team discovered the Gaqtfpr ransomware-type program while inspecting new submissions to VirusTotal. We determined that this program is part of the Snatch ransomware family. When we launched a sample of Gaqtfpr on our testing system, it encrypted files and appended their filenames wit

Servidoracessobanco Ransomware
Ransomware

Servidoracessobanco Ransomware

Servidoracessobanco is ransomware that belongs to a ransomware family called Amnesia. Our malware researchers discovered it while examining samples submitted to VirusTotal. The purpose of Servidoracessobanco ransomware is to encrypt files (keep them inaccessible until they are decrypted). Additio

Password Is Scheduled To Expire Email Scam
Phishing/Scam

Password Is Scheduled To Expire Email Scam

"Password Is Scheduled To Expire" is yet another spam email. After inspecting this letter, we determined that it operates as a phishing scam. This fake message notifies the recipient that their email account password is about to expire and requires immediate action (i.e., reconfirming the old pas

Eeyu Ransomware
Ransomware

Eeyu Ransomware

While inspecting malware samples submitted to the VirusTotal page, we discovered ransomware (which is part of the Djvu family) called Eeyu. It encrypts files and appends its extension to filenames. For example, Eeyu renames "1.jpg" to "1.jpg.eeyu", "2.png" to "2.png.eeyu", etc. Also, it drops the

Gnik Ransomware
Ransomware

Gnik Ransomware

Gnik is ransomware belonging to the Dharma family. Our team discovered this ransomware while inspecting malware samples submitted to VirusTotal. We found that Gnik prevents victims from accessing their files by encrypting them. It also modifies filenames and provides two ransom notes. Gnik displa

DisLight Adware
Adware

DisLight Adware

DisLight is a rogue browser extension that our researchers discovered while inspecting dubious software-promoting websites. This extension promises to enable dark mode for simple design webpages. Instead, it operates as advertising-supported software (adware). Adware enables the placement