Malware errors
19 errors. Choose the message that matches your computer.
ADWARE_POPUP_LOOP
This diagnosis detects persistence registry keys, browser push notifications, or scheduled tasks displaying random popup ads, redirection screens, or background browser processes. This can also stem from installing…
MalwareBROWSER_HIJACKER_REDIRECT
This diagnosis detects unauthorized modification of default web browser homepages, search engines, and shortcuts, redirecting users to malicious advertising search portals. It sometimes comes down to adware wrappers…
MalwareDNS_HOSTS_REDIRECT
This diagnosis detects unauthorized local DNS redirect entries added to the Windows Hosts file, preventing access to security updates and redirecting legitimate sites to phishing portals. Work through the steps below…
MalwareHIGH_CPU_CRYPTOMINER
This diagnosis identifies background mining scripts or binaries running under spoofed system process names (e.g. lsass.exe, svchost.exe), causing high CPU/GPU resource utilization, thermal throttling, and severe…
MalwareKEYLOGGER_TROJAN_SPY
This diagnosis detects spyware hooks capturing keyboard inputs, screenshots, or clipboard data, transmitting the records to remote command-and-control servers. The usual suspects are phishing link execution or…
MalwareRANSOMWARE_ENCRYPTION_ATTACK
This diagnosis detects ransomware-like active encryption behavior on system folders, resulting in encrypted document extensions, ransom notes (.txt/.html), and locked administrative panels. Typical causes include…
MalwareSECURITY_SERVICE_DISABLED
This diagnosis identifies active registry or group policy modifications that disable Windows Defender, Security Center services, and Windows Update, leaving the operating system vulnerable. This can also stem from…
MalwareWANNACRY_RANSOMWARE
WannaCry is a notorious ransomware cryptoworm that targeted computers running Microsoft Windows by encrypting data and demanding ransom payments in Bitcoin. It propagates using the EternalBlue exploit (CVE-2017-0144)…
MalwarePETYA_NOTPETYA_WIPER
Petya/NotPetya is a highly destructive wiper malware masquerading as ransomware. It targets Windows computers, encrypting the Master File Table (MFT) and overwriting the Master Boot Record (MBR) to completely prevent…
MalwareEMOTET_BOTNET_LOADER
Emotet is an advanced, modular banking trojan that operates primarily as a downloader or loader for other malware (such as TrickBot or Ryuk). It spreads through malicious email attachments (macros) and propagates…
MalwareRYUK_RANSOMWARE
Ryuk is a sophisticated ransomware variant targeting large enterprises and critical infrastructure. It is typically deployed manually by attackers after gaining access via phishing (often via Emotet or TrickBot) and…
MalwareLOCKBIT_3_RANSOMWARE
LockBit 3.0 (also known as LockBit Black) is a highly aggressive ransomware-as-a-service (RaaS) variant. It employs advanced anti-analysis techniques, disables security tools, and encrypts files using a…
MalwareQAKBOT_STEALER_BACKDOOR
Qakbot (or Qbot) is a long-standing information-stealing Trojan and backdoor. It captures banking credentials, keystrokes, and emails, and acts as an entry point for ransomware gangs to deploy larger payloads like…
MalwareREDLINE_INFO_STEALER
RedLine Stealer is a widely distributed malware-as-a-service info-stealer. It harvests cached browser passwords, credit card details, cookies, autocomplete data, FTP credentials, and cryptocurrency wallet keys from…
MalwareCLOP_RANSOMWARE
Clop is a ransomware family known for pioneering large-scale data extortion campaigns. It famously exploited zero-day vulnerabilities in managed file transfer (MFT) software, such as MOVEit Transfer (CVE-2023-34362),…
MalwareLAZARUS_BLUENOROFF_APT
Lazarus and its sub-group Bluenoroff are state-sponsored advanced persistent threat (APT) actors. They target global financial institutions, SWIFT networks, cryptocurrency exchanges, and blockchain platforms using…
MalwareVOLT_TYPHOON_APT
Volt Typhoon is a state-sponsored cyber actor that targets critical infrastructure. They use 'Living-off-the-Land' (LotL) techniques—using legitimate built-in administrative tools like PowerShell, wmic, and netsh—to…
MalwareROOTKIT-DETECTED
A kernel-level rootkit has been detected on the system. Rootkits modify the Windows kernel, bootloader, or firmware to hide their presence from standard antivirus tools.
MalwareCRYPTOMINER-HIGH-CPU
A cryptocurrency mining malware is silently consuming CPU and GPU resources. Symptoms include unexplained 100% CPU or GPU utilization, elevated electricity consumption, fan noise during idle periods, and system…