Gridinsoft security desk

Security Blog

Fresh malware news, scam explainers, removal guides, browser fixes, and field notes from the Gridinsoft research team. Start with the alert, then move to the fix.

Ghost-Sender spoofed email passing a mail gateway despite SPF DKIM and DMARC failures.

Top story ·

Ghost-Sender Spoofing

Ghost-Sender shows how Exchange Online tenants with external MX gateways can receive spoofed internal-looking mail. Check the risk and safe mitigations.

DesckVB RAT Malspam

DesckVB RAT malspam abuses DoubleClick redirects before dropping a ZIP, script loader, and .NET RAT. Check what to…

Kirki CVE-2026-8206

Kirki 6.0.0 through 6.0.6 can let unauthenticated attackers route password reset links to their own inbox. Update to…

Guides

View all
Defender tampering alert showing a disabled real-time protection switch and the MpTamperSrvDisableAV.H detection.

Practical guide · 8 min read

Trojan:Win32/MpTamperSrvDisableAV.H Alert

Trojan:Win32/MpTamperSrvDisableAV.H is a Defender tampering alert. Check the affected path, restore protection safely, scan the PC, and decide whether reinstall is necessary.

Repair desk

View all

Security lab · Jun 7, 2026

Neshta.Virus.FileInfector.DDS

Neshta.Virus.FileInfector.DDS is a file-infector alert. Learn what to check, when it may be a false positive, and how to clean Windows safely.

Jun 1, 2026

Notepad++ XML File Risk

Notepad++ 8.9.6.1 fixes config.xml and shortcuts.xml code execution flaws. Learn who is affected, how to update,…

Jun 1, 2026

Extension Keeps Returning?

If a browser extension keeps reinstalling itself, remove the source that restores it: sync, browser policy,…

Jun 1, 2026

VFXmed Virus Warning

Downloaded a VFXmed installer? Learn why cracked VFX software is risky, what Themida/DLL-hijack/infostealer alerts mean, and…

May 31, 2026

VectorGatewa.exe Removal

VectorGatewa.exe keeps coming back after a game download? Learn what the file means, how to remove…

May 31, 2026

Fake Adidas Fan Kit 2026 Scam

Got an Adidas Fan Kit 2026 WhatsApp link? Check why msgdeal.cc/offerwa.cc prize pages, quizzes, sharing prompts,…

May 29, 2026

Lively.Watchdog.exe Check

Lively.Watchdog.exe is usually part of Lively Wallpaper, but suspicious copies can be malware. Check the path,…

May 29, 2026

sdaCollector.vbs: Is It Safe?

sdaCollector.vbs is usually tied to Slate Digital Connect, but path, startup entry, hash, and Possible Threat…

Latest from every desk

Troubleshooting

UDisplay.exe Safety Check

UDisplay.exe can belong to a USB display or USB-to-HDMI adapter, but unknown paths, auto-start…

Troubleshooting

K-Lite Infatica Removal

Found Infatica after installing K-Lite Codec Pack? Learn what it means, how to remove…

Troubleshooting

Newtab.art Redirect

Newtab.art redirects searches or new tabs? Remove suspicious extensions, browser policies, startup tasks, sync…

Troubleshooting

Travel-now.cc Virus

Remove Travel-now.cc from Chrome by deleting suspicious extensions, fixing search settings, revoking notifications, checking…

AI Assistant

Hello! 👋 How can I help you today?