Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

291 lab records

Latest note ·

Meduza Stealer

The Malware world evolves constantly, and it would be reckless to ignore newcomers and their potential. Meduza Stealer appears to be a pretty potent stealer variant with its unique features and marketing model. Additionally,...

Field note ·

RegAsm.exe: Safe or Malware?

RegAsm.exe is a legitimate Microsoft .NET tool, but malware can imitate or abuse it. Check the...

Field note ·

What Is TextInputHost.exe?

TextInputHost.exe is usually a safe Microsoft Windows input process. Learn how to verify its path and...

Research log

02

Sniffing and Spoofing: Difference, Meaning

Record ·

Users are increasingly encountering malicious links that, when clicked, unleash a different kind of computer destruction. In this case, users must be aware of...

03

Csrss.exe Trojan Virus

Record ·

Csrss.exe is an important Windows process, which may sometimes consume a lot of system resources and puzzle the users with such behavior. Some people...

05

What Is UsoClient.exe? Safe or Virus?

Record ·

UsoClient.exe is a legitimate Windows Update component, not a virus when it runs from C:WindowsSystem32UsoClient.exe and is signed by Microsoft Windows. It belongs to...

06

What Is AcroTray.exe?

Record ·

AcroTray.exe is normally an Adobe Acrobat background component used for PDF-related actions such as conversion, printing workflows, and Acrobat integration. It is not a...

07

Behavior:Win32/Fynloski.gen!A

Record ·

Behavior:Win32/Fynloski.gen!A is a heuristic detection of Microsoft Defender that flags activities of Fynloski malware. This malicious program allows attackers to control the infected system...

10

What Is OmApSvcBroker.exe?

Record ·

What is OmApSvcBroker.exe? OmApSvcBroker.exe is usually an MSI Center, MSI Dragon Center, or MSI NBFoundation Service process. On MSI laptops and motherboards it can...

11

How to Remove Advanced Window Manager Adware

Record ·

Advanced Window Manager is potentially unwanted software that floods users' systems with advertisements. It pretends to be a tool that adds new functionality to...

12

Program:Win32/Uwamson.A!ml

Record ·

Win32/Uwamson.A!ml is a specific name of a Microsoft Defender detection. This designation indicates that the suspicious program or file scanned by the antivirus has...

13

PUABundler:Win32/MemuPlay: What It Is and Removal

Record ·

PUABundler:Win32/MemuPlay is a Microsoft Defender detection that should be judged by the affected file path, source, signature, and behavior, not by the name alone....

14

PUADlManager:Win32/Sepdot Removal

Record ·

PUADlManager:Win32/Sepdot is a Microsoft Defender potentially unwanted app detection, usually tied to a downloader, wrapper, or installer that may add unwanted components. Users often...

16

Pornographic Virus Alert From Microsoft

Record ·

The Pornographic Virus Alert from Microsoft is a fake tech support warning. Do not call the number: close the browser, block the site, remove...

AI Assistant

Hello! 👋 How can I help you today?