Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

291 lab records

Latest note ·

Trojan:Win64/Zusy.CZ!MTB

Trojan:Win64/Zusy.CZ!MTB is a detection of Microsoft Defender that can flag several different types of malware. Being a heuristic detection, it can as well be a false positive, with no real threat to the system....

Field note ·

Trojan:Win32/Fauppod!ml

What does Fauppod!ml mean? Trojan:Win32/Fauppod!ml is a Microsoft Defender machine-learning detection. It does not name one...

Research log

01

PUA:Win32/GameHack: Virus or False Positive?

Record ·

PUA:Win32/GameHack is a Microsoft Defender detection for game cheats, trainers, memory editors, patched game files, and related tools that modify game behavior. It is...

03

Trojan:Win64/Reflo.HNS!MTB

Record ·

Win64/Reflo.HNS!MTB is a detection of a malware sample that aims at stealing confidential information. It usually spreads through game mods and works as quietly...

04

Check-tl-ver Pop-Up Virus

Record ·

Analysis shows a hike in the number of malicious pop-ups that come from Check-tl-ver websites. It is a rather common strategy of aggressive marketing...

05

Trojan:PowerShell/CoinStealer.RP!MTB

Record ·

Trojan:PowerShell/CoinStealer.RP!MTB is a detection of Microsoft Defender, that normally flags malware that can steal cryptocurrency wallets. You may see it popping up after downloading...

06

PUABundler:Win32/DriverPack

Record ·

PUABundler:Win32/DriverPack is potentially unwanted software that claims to install or update drivers. In fact, it floods the system with unwanted software and changes browser...

07

Virus Alert (05261) Scam

Record ·

"Virus Alert (05261)" is a scam pop-up message you can see on a website that looks like a Microsoft page, but with a strange...

08

Movidown Unwanted Application

Record ·

Movidown is an Unwanted Application that initially mimics a utility for controlling fan speed. However, beneath this shell, it has the capabilities of a...

10

PUA:Win32/SBYinYing

Record ·

PUA:Win32/SBYinYing is a potentially unwanted application (PUA) that is often bundled with certain cracked games. It may display ads to users or redirect them...

11

How to Turn Off Microsoft Defender Safely

Record ·

You can temporarily turn off Microsoft Defender Antivirus from Windows Security, but you should only do it for a specific trusted reason and turn...

12

Trojan:Win32/Qhosts

Record ·

Trojan:Win32/Qhosts is malware that provides remote access to the target system and modifies the Hosts file. It is primarily distributed through illegal activation tools...

13

PUABundler:Win32/YandexBundled

Record ·

PUABundler:Win32/YandexBundled is a detection of potentially unwanted application (PUA) associated with the Russian company Yandex. It is typically distributed as bundled software with repackaged...

16

Trojan:BAT/PSRunner.VS!MSR

Record ·

Trojan:BAT/PSRunner.VS!MSR is a detection of malware that executes malicious commands on a compromised system. It does not do much hurt by itself and rather...

AI Assistant

Hello! 👋 How can I help you today?