Malware errors

19 errors. Choose the message that matches your computer.

19 errors
Malware

ADWARE_POPUP_LOOP

This diagnosis detects persistence registry keys, browser push notifications, or scheduled tasks displaying random popup ads, redirection screens, or background browser processes. This can also stem from installing…

low · Open step-by-step guide
Malware

BROWSER_HIJACKER_REDIRECT

This diagnosis detects unauthorized modification of default web browser homepages, search engines, and shortcuts, redirecting users to malicious advertising search portals. It sometimes comes down to adware wrappers…

medium · Open step-by-step guide
Malware

DNS_HOSTS_REDIRECT

This diagnosis detects unauthorized local DNS redirect entries added to the Windows Hosts file, preventing access to security updates and redirecting legitimate sites to phishing portals. Work through the steps below…

high · Open step-by-step guide
Malware

HIGH_CPU_CRYPTOMINER

This diagnosis identifies background mining scripts or binaries running under spoofed system process names (e.g. lsass.exe, svchost.exe), causing high CPU/GPU resource utilization, thermal throttling, and severe…

high · Open step-by-step guide
Malware

KEYLOGGER_TROJAN_SPY

This diagnosis detects spyware hooks capturing keyboard inputs, screenshots, or clipboard data, transmitting the records to remote command-and-control servers. The usual suspects are phishing link execution or…

critical · Open step-by-step guide
Malware

RANSOMWARE_ENCRYPTION_ATTACK

This diagnosis detects ransomware-like active encryption behavior on system folders, resulting in encrypted document extensions, ransom notes (.txt/.html), and locked administrative panels. Typical causes include…

critical · Open step-by-step guide
Malware

SECURITY_SERVICE_DISABLED

This diagnosis identifies active registry or group policy modifications that disable Windows Defender, Security Center services, and Windows Update, leaving the operating system vulnerable. This can also stem from…

critical · Open step-by-step guide
Malware

WANNACRY_RANSOMWARE

WannaCry is a notorious ransomware cryptoworm that targeted computers running Microsoft Windows by encrypting data and demanding ransom payments in Bitcoin. It propagates using the EternalBlue exploit (CVE-2017-0144)…

critical · Open step-by-step guide
Malware

PETYA_NOTPETYA_WIPER

Petya/NotPetya is a highly destructive wiper malware masquerading as ransomware. It targets Windows computers, encrypting the Master File Table (MFT) and overwriting the Master Boot Record (MBR) to completely prevent…

critical · Open step-by-step guide
Malware

EMOTET_BOTNET_LOADER

Emotet is an advanced, modular banking trojan that operates primarily as a downloader or loader for other malware (such as TrickBot or Ryuk). It spreads through malicious email attachments (macros) and propagates…

critical · Open step-by-step guide
Malware

RYUK_RANSOMWARE

Ryuk is a sophisticated ransomware variant targeting large enterprises and critical infrastructure. It is typically deployed manually by attackers after gaining access via phishing (often via Emotet or TrickBot) and…

critical · Open step-by-step guide
Malware

LOCKBIT_3_RANSOMWARE

LockBit 3.0 (also known as LockBit Black) is a highly aggressive ransomware-as-a-service (RaaS) variant. It employs advanced anti-analysis techniques, disables security tools, and encrypts files using a…

critical · Open step-by-step guide
Malware

QAKBOT_STEALER_BACKDOOR

Qakbot (or Qbot) is a long-standing information-stealing Trojan and backdoor. It captures banking credentials, keystrokes, and emails, and acts as an entry point for ransomware gangs to deploy larger payloads like…

high · Open step-by-step guide
Malware

REDLINE_INFO_STEALER

RedLine Stealer is a widely distributed malware-as-a-service info-stealer. It harvests cached browser passwords, credit card details, cookies, autocomplete data, FTP credentials, and cryptocurrency wallet keys from…

high · Open step-by-step guide
Malware

CLOP_RANSOMWARE

Clop is a ransomware family known for pioneering large-scale data extortion campaigns. It famously exploited zero-day vulnerabilities in managed file transfer (MFT) software, such as MOVEit Transfer (CVE-2023-34362),…

critical · Open step-by-step guide
Malware

LAZARUS_BLUENOROFF_APT

Lazarus and its sub-group Bluenoroff are state-sponsored advanced persistent threat (APT) actors. They target global financial institutions, SWIFT networks, cryptocurrency exchanges, and blockchain platforms using…

critical · Open step-by-step guide
Malware

VOLT_TYPHOON_APT

Volt Typhoon is a state-sponsored cyber actor that targets critical infrastructure. They use 'Living-off-the-Land' (LotL) techniques—using legitimate built-in administrative tools like PowerShell, wmic, and netsh—to…

critical · Open step-by-step guide
Malware

ROOTKIT-DETECTED

A kernel-level rootkit has been detected on the system. Rootkits modify the Windows kernel, bootloader, or firmware to hide their presence from standard antivirus tools.

critical · Open step-by-step guide
Malware

CRYPTOMINER-HIGH-CPU

A cryptocurrency mining malware is silently consuming CPU and GPU resources. Symptoms include unexplained 100% CPU or GPU utilization, elevated electricity consumption, fan noise during idle periods, and system…

high · Open step-by-step guide

You don’t need to know the technical name.

Tell us what you see. We’ll help you narrow down the problem.

Find by symptom