Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

297 lab records

Latest note ·

What is the Hkbsse.exe Process?

Hkbsse.exe is a name of a process related to Amadey Dropper, that you can observe while browsing through the system. This malware delivers other malware to the target system, disables security solutions and does...

Field note ·

Sec-tl Pop-Up Virus

Sec-tl pop-up ads are malicious push notifications that parasite legitimate browser functionality. Fraudulent actors that stand...

Field note ·

First-tl Pop-Up Virus

First-tl pop-up ads are malicious push notifications (like a Sec-tl sites) that parasite legitimate browser functionality....

Research log

03

Trojan:Win32/Fauppod!ml

Record ·

What does Fauppod!ml mean? Trojan:Win32/Fauppod!ml is a Microsoft Defender machine-learning detection. It does not name one exact malware family; it means the file looks...

04

JsTimer Extension Virus – Easy Removal Instructions

Record ·

JsTimer is a malicious browser extension detected in various browsers, predominantly targeting users through dubious websites. This extension engages in peculiar behavior by blocking...

05

PUA:Win32/GameHack: Virus or False Positive?

Record ·

PUA:Win32/GameHack is a Microsoft Defender detection for game cheats, trainers, memory editors, patched game files, and related tools that modify game behavior. It is...

07

Trojan:Win64/Reflo.HNS!MTB

Record ·

Win64/Reflo.HNS!MTB is a detection of a malware sample that aims at stealing confidential information. It usually spreads through game mods and works as quietly...

08

Check-tl-ver Pop-Up Virus

Record ·

Analysis shows a hike in the number of malicious pop-ups that come from Check-tl-ver websites. It is a rather common strategy of aggressive marketing...

09

Trojan:PowerShell/CoinStealer.RP!MTB

Record ·

Trojan:PowerShell/CoinStealer.RP!MTB is a detection of Microsoft Defender, that normally flags malware that can steal cryptocurrency wallets. You may see it popping up after downloading...

10

PUABundler:Win32/DriverPack

Record ·

PUABundler:Win32/DriverPack is potentially unwanted software that claims to install or update drivers. In fact, it floods the system with unwanted software and changes browser...

11

Virus Alert (05261) Scam

Record ·

"Virus Alert (05261)" is a scam pop-up message you can see on a website that looks like a Microsoft page, but with a strange...

12

Movidown Unwanted Application

Record ·

Movidown is an Unwanted Application that initially mimics a utility for controlling fan speed. However, beneath this shell, it has the capabilities of a...

14

PUA:Win32/SBYinYing

Record ·

PUA:Win32/SBYinYing is a potentially unwanted application (PUA) that is often bundled with certain cracked games. It may display ads to users or redirect them...

16

Trojan:Win32/Qhosts

Record ·

Trojan:Win32/Qhosts is malware that provides remote access to the target system and modifies the Hosts file. It is primarily distributed through illegal activation tools...

AI Assistant

Hello! 👋 How can I help you today?