Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

310 lab records

Latest note ·

sdaCollector.vbs: Is It Safe?

sdaCollector.vbs is usually tied to Slate Digital Connect, but path, startup entry, hash, and Possible Threat detections decide whether to keep or remove it.

Field note ·

Kiicvoq Apps Removal Guide

Kiicvoq Apps appeared on your PC? Learn why it is treated as a PUA, how to...

Research log

01

Is Ace AI Browser Safe? Checks and Removal Guide

Record ·

Check an Ace AI Browser installer before running it. Identify unwanted installs, remove Ace Browser or matching AceLauncher components, and stop recurring redirects.

02

Carbonate Browser: Is It Safe or a PUA?

Record ·

Carbonate Browser looks like a PUA when it changes defaults, comes from bundles, or returns after uninstall. Check files and remove leftovers safely.

04

OnePlatform PUA Removal

Record ·

PUADIManager:Win32/OnePlatform is a Microsoft Defender PUA alert for bundled installers. Remove the wrapper, check browsers/startup, and scan for adware leftovers.

05

Trojan:PowerShell/AgentTesla.SHD!MTB Removal

Record ·

Defender detected Trojan:PowerShell/AgentTesla.SHD!MTB? Keep it quarantined, scan for dropped files, check startup persistence, and change passwords from a clean device if anything ran.

06

Can Malware Activate Later? What to Do

Record ·

Yes, malware can activate later after an EXE runs. Check persistence, account symptoms, Defender history, and run a full scan before trusting the PC.

08

Service Miner Removal Guide

Record ·

A suspicious Windows service miner can persist through services, scheduled tasks, and startup entries. Learn what paths to check, how to remove it safely,...

AI Assistant

Hello! 👋 How can I help you today?