Nathan Bookshire

Browser Hijacker

How to delete Searchisty Extension from Chrome

The Searchisty extension is yet another rogue extension we detected recently, together with FortyFy and NebulaNanoel. All of the mentioned extensions are created by malware actors to enforce an active managed by organization state on the browser, to...

Browser Hijacker

How to remove FortyFy Extension from Chrome

FortyFy is a type of rogue browser extension that security researchers categorize as a browser hijacker. It is similar to other recently detected rogue apps like PubQuo and the Bing Redirect virus, and another extension that is installed with...

Trojan

How to uninstall the Boinc Malware 

We ran into a bit of a weird situation in our research. A trojan masquerades as a legitimate program. Such a thing isn’t new – security threats do it all the time, especially trojans, which is what’s happening here. What’s new here is that the...

News

Polyfill.io infects 100k websites with malware

If you’ve been following the latest cybersecurity news, you might have heard about the recent supply chain attack involving Polyfill.io. I somehow missed this until today, due to, well, researching other malware. But the attack proved...

Browser Hijacker

How to Remove PubQuo

PubQuo is a type of potentially unwanted software that displays the typical traits of a browser hijacker. It automatically changes the settings of Chrome, Edge, and other Chromium browsers upon installation, and it does this without requesting...

Browser Hijacker

PubSurf Removal Instructions

Fake apps have become so common nowadays as browser hijacker components that many people believe they are no threat at all. The current PubSurf infection is one of several rebrands we’ve seen recently – namely JoisApp, TjboApp and...

Trojan

How to remove the Warmcookie Backdoor Malware

This page is dedicated to educating victims on what Warmcookie does and to its removal. A big thank you for the security researchers who made their information public, including Elastic and Esentire. Without the notice they gave everyone, we...

Adware

Removal instructions for the CiviApp virus

What is CiviApp? CiviApp is a browser hijacker that also exhibits characteristics of a Trojan Horse. It’s kind of an unorthodox thing to say since these things are quite well separated – one infects the browser, the other background...