Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

291 lab records

Latest note ·

SUPERLOCK Ransomware Virus Simple Step-by-Step Removal Guide

SUPERLOCK is a ransomware infection that aims at blocking access to the files and demanding a payment for getting them back. Users can distinguish the encrypted files by them containing an additional .superlock extension,...

Field note ·

Trojan:PDF/Phish.A

Trojan:PDF/Phish.A is detection of a PDF file which potentially carries a malicious link or script designed...

Field note ·

Trojan:PowerShell/Malscript!MSR

Trojan:PowerShell/Malscript!MSR refers to a detection linked to malicious script activity. This type of malware typically exploits...

Field note ·

TrojanDownloader:HTML/Elshutilo

TrojanDownloader:HTML/Elshutilo is script-based malware designed to download additional payloads onto the target system. Since detection is...

Research log

01

Is Opera GX Safe?

Record ·

Opera GX is a legitimate Chromium-based browser made by Opera for gamers, but “safe” depends on what you mean. It is not malware when...

02

Aruba.it Email Scam

Record ·

The Aruba.it email scam is a phishing campaign using fake emails that appear to be from Aruba S.p.A., a well-known Italian company providing domain...

03

Arma dei Carabinieri Virus

Record ·

The *Arma dei Carabinieri* message is a banner that may appear on your PC, attempting to mimic notifications from Italy's national gendarmerie. Cybercriminals use...

04

Trojan:Win32/Offloader.EA!MTB

Record ·

Trojan:Win32/Offloader.EA!MTB is malware designed to establish unauthorized access to a target system or deliver a payload of additional malware. This detection is sometimes associated...

06

PUA:Win32/WebCompanion: Meaning and Removal

Record ·

PUA:Win32/WebCompanion is a Defender detection for Adaware Web Companion or related bundled installs. Remove unwanted browser and system changes.

08

PUABundler:Win32/MediaGet: What It Is and How to Remove It

Record ·

PUABundler:Win32/MediaGet is a Microsoft Defender detection for MediaGet-related bundled software. MediaGet is commonly associated with torrent/pirated-content workflows and may install extra components or unwanted...

09

PrimeLookup Extension Removal Guide

Record ·

PrimeLookup is a Chrome extension that may unexpectedly appear among your browser's add-ons, causing your search queries to be redirected. As a browser hijacker,...

12

Trojan:Script/Obfuse!MSR

Record ·

Trojan:Script/Obfuse!MSR is a generic detection of a malicious script that abuses command interpreters to execute commands or binaries. What distinguishes this threat from others...

13

What is the Hkbsse.exe Process?

Record ·

Hkbsse.exe is a name of a process related to Amadey Dropper, that you can observe while browsing through the system. This malware delivers other...

15

Trojan:Win32/Commandrob.A!ml Threat Analysis

Record ·

Trojan:Win32/Commandrob.A!ml is a heuristic detection associated with suspicious network activity. It may refer to a wide range of malicious programs, or be a false...

16

Azurestaticapps.net

Record ·

Azurestaticapps.net is a selection of pages registered on genuine Microsoft hosting, that try scaring the user by false malware infection claims. In fact, it...

AI Assistant

Hello! 👋 How can I help you today?