Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

291 lab records

Field note ·

Fake Instagram Hacking Services

Instagram hacking scams is an old-new direction of online fraud that targets people who want to...

Field note ·

Stopabit Virus

Stopabit is an unwanted application that has almost no useful functionality. Users can see its promotions...

Research log

01

Weather Zero Virus or Adware?

Record ·

Weather Zero is an unwanted weather-style app that may show ads, redirects, or browser notification spam. Here is how to remove it and clean...

02

Bloom.exe

Record ·

Bloom.exe is a malicious miner that masquerades as a legitimate process. Its job is to use the victim's device to mine cryptocurrency for con...

03

Trojan:Win32/Tnega!MSR Removal

Record ·

Trojan:Win32/Tnega!MSR is commonly searched as a Defender Trojan alert, but Microsoft’s public threat entry currently describes HackTool:Win32/Tnega!MSR. Either way, treat the detection as unsafe:...

05

PUA:Win32/Caypnamer.A!ml: What It Is and Removal

Record ·

PUA:Win32/Caypnamer.A!ml is a Microsoft Defender detection that should be judged by the affected file path, source, signature, and behavior, not by the name alone....

06

Virus:Win32/Floxif.H Removal

Record ·

Virus:Win32/Floxif.H is a severe Microsoft Defender file-infector alert. Learn how to remove it, rescan safely, and handle infected files or backups.

07

Virus:Win32/Grenam.VA!MSR Removal

Record ·

Virus:Win32/Grenam.VA!MSR is a serious Microsoft Defender virus alert, not a normal PUA warning. Grenam-family malware is associated with file infection behavior, meaning it can...

09

Trojan:Win32/Znyonm

Record ·

Trojan:Win32/Znyonm is a detection often seen during the backdoor malware activity in the background. Such malware can escalate privileges, enable remote access, or deploy...

10

Internet Is A Dangerous Place

Record ·

The "Internet Is A Dangerous Place" scam is a novel type of threatening email message that targets people with threats of intimidation and exposure....

12

PUADlManager:Win32/OfferCore Removal

Record ·

PUADlManager:Win32/OfferCore is a Defender detection for an installer or downloader that can deliver bundled unwanted apps and browser changes.

13

PUA:Win32/Vigua.A: Meaning and Removal

Record ·

PUA:Win32/Vigua.A usually points to unwanted optimizers, scareware, or bundled tools. Remove the app, browser changes, and scheduled tasks.

14

What Is sihost.exe?

Record ·

sihost.exe, or Shell Infrastructure Host, is a legitimate Windows process that helps run the desktop shell: Start menu, taskbar, notifications, background visuals, and other...

15

Win.MxResIcn.Heur.Gen

Record ·

Antivirus engine of MaxSecure, a well-known cybersecurity vendor, currently shows massive amounts of false positive detection with the name Win.MxResIcn.Heur.Gen. It touches numerous legitimate...

16

IP Stresser & DDoS Booter

Record ·

The toolkit of cybersecurity specialists in companies does not consist only of security tools. To imitate the intruders, they apply using the tools like...

AI Assistant

Hello! 👋 How can I help you today?