Malware

Remove Salat trojan

Salat trojan is a data-stealing type of malware. The reason it’s classified as a stealer type of malware is that it aims to steal highly sensitive information from the infected device. It’s a very serious infection that users will not necessarily notice because it stealthily stays in the background. It has several worrying features, including the ability to steal files…

Remove Pe32s ransomware

Pe32s ransomware is file-encrypting malware that will encrypt certain files on the infected device. This malware can be recognized by the .pe32s extension it adds to encrypted files. Once files are encrypted, users will not be able to open them unless they first use a decryptor on them. However, getting the decryptor is not going to be easy because only the…

Remove NativeWorm stealer trojan (Android)

NativeWorm Android trojan is a malicious trojan-type of infection that targets Android devices. The trojan has several worrying features, including the ability to access the Contacts applications and read SMS messages. The trojan infection may not be noticeable initially, which would allow it to remain installed for a long time. Successful infection can have serious consequences for users as the…

Remove DieStealer stealer trojan

DieStealer is classified as a stealer trojan that targets personal information. It’s a very dangerous infection because it targets highly sensitive information (e.g. passwords) and can remain unnoticed for a long period of time. Successful infection can have very serious consequences because it could mean loss of personal information, hijacked accounts, and even financial loss.

Remove Orion Hackers ransomware

Orion Hackers ransomware is file-encrypting malware that targets personal files. Once it successfully infects a computer, it encrypts certain files on the computer, which prevents users from opening them. It’s a very dangerous type of malware because it’s not always possible to recover encrypted files.

Remove “Spam Activity Originating From Your Address” email

The “Spam Activity Originating From Your Address” email is part of a phishing campaign that tries to phish users’ email account login credentials. The email is disguised as a security alert informing recipients about supposed massive spam activity from their accounts. Supposedly, recipients’ email accounts have been compromised and will be permanently deleted if users don’t take action within 24…

Remove “Capital One – Account Restricted” email

The “Capital One – Account Restricted” email is part of a phishing campaign that tries to trick users into revealing their Capital One login credentials. The email looks like a notification from Capital One and informs recipients that their accounts have been restricted because they’re under review. If users want their accounts to be reinstated, they need to verify them…

Remove “Roundcube Account Will Be Suspended” email

The “Roundcube Account Will Be Suspended” email is a phishing attempt that targets Roundcube login credentials. The email claims that your account will soon be suspended from sending and receiving emails because of illegal activity detected in the account. The email encourages users to click on the provided button to supposedly secure their accounts but if users click on it,…

Remove Cloak ransomware

Cloak ransomware is file-encrypting malware that essentially takes files hostage and demands payment for their recovery. The malware targets personal files because they are the ones users are usually willing to pay for. The ransomware can be identified by the .crYpt extension it adds to encrypted files. If your files suddenly have that extension, you will not be able to…

Remove “Capital One – Document Is Ready” email

The “Capital One – Document Is Ready” email is part of a phishing campaign that intends to steal users’ Capital One login credentials. There has been an increase in phishing email targeting specifically Capital One credentials so users need to be very careful. This particular phishing email is disguised as a notification from the bank about a supposed document being…