Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

305 lab records

Field note ·

OnePlatform PUA Removal

PUADIManager:Win32/OnePlatform is a Microsoft Defender PUA alert for bundled installers. Remove the wrapper, check browsers/startup, and...

Field note ·

Trojan:PowerShell/AgentTesla.SHD!MTB Removal

Defender detected Trojan:PowerShell/AgentTesla.SHD!MTB? Keep it quarantined, scan for dropped files, check startup persistence, and change passwords...

Research log

01

Can Malware Activate Later? What to Do

Record ·

Yes, malware can activate later after an EXE runs. Check persistence, account symptoms, Defender history, and run a full scan before trusting the PC.

03

Service Miner Removal Guide

Record ·

A suspicious Windows service miner can persist through services, scheduled tasks, and startup entries. Learn what paths to check, how to remove it safely,...

15

Markedoneofthe.com Redirect Removal

Record ·

Is Markedoneofthe.com a virus? Markedoneofthe.com is usually a redirect/adware symptom, not a normal website you need to keep. Block notifications if the site is...

AI Assistant

Hello! 👋 How can I help you today?