OpenDrive virus: why web.opendrive.com shows up in malware alerts, and what to do if a file from it installed Remcos

OpenDrive is a legitimate cloud storage service, not a virus, but criminals upload files to it that hide malware and point their loaders at them. On 9 and 10 September 2026 URLhaus listed eight such file addresses on web.opendrive.com, all tagged RemcosRAT and stego. Here is what that means, how to tell a bad OpenDrive file from a normal one, and how to clean a Windows PC if one ran.

Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a script or loader that downloaded a file from web.opendrive.com keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove OpenDrive virus (Remcos RAT delivered through web.opendrive.com) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Four pairs of URLhaus reports for web.opendrive.com on 9 and 10 September 2026, tagged RemcosRAT, rat and stego, all offline
The eight URLhaus reports for OpenDrive file addresses, September 2026. There is no screenshot of a site here: the service is cloud storage, and our check was a plain request from our server.

OpenDrive virus (Remcos RAT delivered through web.opendrive.com): summary

TypeA legitimate cloud storage service abused to deliver malware: eight files tagged RemcosRAT, rat and stego
RiskHigh if a script or attachment you opened fetched one of the files. None if you only saw opendrive.com in a log or use the service yourself
SymptomsOften none. Unknown startup entries, a Defender detection named Remcos, accounts opened elsewhere
How to get rid of itChange passwords and sign out sessions from another device, run Microsoft Defender Offline, remove startup entries, reset Windows if unsure
Our check (8 October 2026)Plain request from our server: HTTP 404 at the bare host name. Reported files not requested; all eight offline
Running since / first seenDomain registered 13 April 2003; first files reported 9 September 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesMicrosoft uses Backdoor:Win32/Remcos and variants such as Backdoor:Win32/Remcos.PDD!MTB. We found no published name for these eight exact files; we did not scan them
NameOpenDrive virus (malware delivered through web.opendrive.com)
Domain registered13 April 2003
Evidence8 write-ups by security sites; details still limited
First seen9 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked8 October 2026

Facts checked on 8 October 2026 against the URLhaus data for web.opendrive.com in our job record, RDAP, one plain request from our server (no browser), OpenDrive's own terms and site, and reports by Microsoft, MITRE ATT&CK, Cofense, LevelBlue SpiderLabs and Check Point. We did not download the reported files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What OpenDrive is, and why a security tool may call it a virus

OpenDrive is not a virus. It is a cloud storage service from OpenDrive, LLC in Palo Alto, California, where people store, sync, back up and share files. Its own site says the idea started in 2007 and that nearly 2 million people have used it. Like any storage service that lets you share a file by link, it can also be used by criminals to keep a file that their malware downloads later. The service is safe; some of the files people upload to it are not.

In September 2026 the abuse.ch project URLhaus listed eight such file addresses on web.opendrive.com. All eight are tagged RemcosRAT, rat and stego: a remote access trojan for Windows, hidden inside another file. All eight were offline when we read the data on 8 October 2026.

OpenDrive's own terms forbid this. Section 10 says users may not store or send material that contains viruses, trojan horses or other harmful code, and section 12 lets OpenDrive close the account and destroy the data of anyone who breaks the rules.

  1. 1

    What URLhaus lists

    Eight file addresses on web.opendrive.com, all through the service's download interface, /api/v1/download/file.json/ followed by a file id and ?inline=1. Four were added on 9 September 2026 and four on 10 September 2026. Every entry has the threat label malware_download, the reporter abuse_ch and the status offline.

  2. 2

    What the tags mean

    RemcosRAT and rat name Remcos, a remote control program for Windows that criminals use as a remote access trojan. stego is short for steganography: data hidden inside another file, often a picture, so that the file looks harmless to a filter. Together they describe a file that carries a hidden part for a loader that is already running.

  3. 3

    What we could not confirm

    We did not download the files, so we cannot show what is inside them, which Remcos build they carry or where it reports to. URLhaus tags are reports from automated systems and analysts, not a full analysis. We also do not know which emails or pages pointed at these files or how many people met them.

  4. 4

    What this means for you

    If your browser, antivirus or firewall only showed the name opendrive.com, nothing is proven: almost every visit to that address is someone opening their own files. The risk is for a person who opened an attachment, script or installer that then fetched one of these files in the background.

Kind of threat
Malware delivered through a legitimate cloud storage service: eight files tagged RemcosRAT, rat and stego
The service
OpenDrive, cloud storage, backup and file sharing from OpenDrive, LLC. The domain opendrive.com was registered on 13 April 2003 through Wild West Domains, LLC (RDAP, read 8 October 2026)
Where the files were
hxxps://web.opendrive[.]com/api/v1/download/file.json/<file id>?inline=1, eight different file ids
URLhaus entries
8 file addresses, added 9 and 10 September 2026; all 8 offline on 8 October 2026
Delivery trick
A file hidden inside another file (stego), fetched by a script or loader that a person already ran
Platform
Windows. Remcos is a Windows program; nothing we read says Mac, iPhone or Android

What OpenDrive virus (Remcos RAT delivered through web.opendrive.com) does on an infected PC

What we checked on 8 October 2026, and what we could not

We sent one plain request from our server to https://web.opendrive.com/ on 8 October 2026, with no browser and no clicks. It answered HTTP 404 Not Found. For a storage service, a bare host name that serves only a web app or an interface often has nothing at its root, so this answer says nothing about safety either way. It does not test the eight reported files, and a quiet answer clears nothing.

Our check, 8 October 2026

  • The service answersHTTP 404 with the page title 404 Not Found at the bare address. No redirect, no notification request.
  • Domain registrationopendrive.com, registered 13 April 2003, registrar Wild West Domains, LLC, with delete, renew, transfer and update locks. A registration of more than 23 years is what a real service looks like.
  • URLhaus listingEight file addresses under /api/v1/download/file.json/, all tagged RemcosRAT, rat and stego, added on 9 and 10 September 2026.
  • Are the files still served?All eight are marked offline by URLhaus. That usually means the files or the account were removed.
  • What we did not doWe did not request or download the reported files and did not run them. Other files of the same kind may appear under new accounts at any time.

Safe service, abused by some uploaders web.opendrive.com itself belongs to a legitimate and long running storage service. The danger is in specific files that criminals upload and then point their loaders at. Judge how the file reached you, not the domain.

The eight reports, in order

The reports cover two afternoons. Dates and tags come from the URLhaus data in our job record; the times are UTC. The file id at the end of each address is base64 text, and decoded it reads as two numbers and a short code, for example 18_73770802_i8bTZ.

Four pairs of URLhaus reports for web.opendrive.com on 9 and 10 September 2026, all tagged RemcosRAT, rat and stego and all offline
The eight URLhaus reports for OpenDrive file addresses, read on 8 October 2026. There is no screenshot of a site here: the files were offline and our check was a plain request from our server.
  1. 13 April 2003

    opendrive.com is registered

    RDAP shows the domain registered on 13 April 2003 through Wild West Domains, LLC. OpenDrive says the idea for the service started in 2007.

  2. 9 September 2026, 18:35

    First pair of files

    abuse_ch adds two file addresses whose ids begin with 18 and differ only in the last digits, 73770802 and 73770805. Tags: RemcosRAT, rat, stego.

  3. 9 September 2026, 18:36

    Second pair, one minute later

    Two more addresses are added, with ids beginning 16, numbered 205617966 and 205618285. Same three tags.

  4. 10 September 2026, 15:20

    Third pair

    About 21 hours later abuse_ch adds two ids beginning 20, numbered 37813705 and 37813737. Same tags.

  5. 10 September 2026, 15:21

    Fourth pair

    One minute after that, two ids beginning 11, numbered 88657116 and 88658047. Same tags. No further reports follow.

  6. 8 October 2026

    All offline, and our check

    All eight entries are marked offline. Our plain request to the bare host name gets HTTP 404.

Our reading of the pattern: the files come in four pairs, and each pair shares the first number of its id. That fits two files uploaded together each time, for example a script and the picture it decodes, in four places or accounts. It is an inference from the decoded ids, not something a report states.

How criminals use cloud storage like OpenDrive, and why it works for them

A storage service does not run the files it keeps, in the same way a warehouse does not open every box. Criminals take advantage of the trust that mail filters, firewalls and people give to a well known address.

Five steps of a Remcos chain: a phishing email, a script that runs, a download of a picture-like file from a storage link, the hidden loader decoded and run in memory, Remcos taking control
The chain as vendors describe stego Remcos campaigns. OpenDrive only stores the file; the step that does the harm is a file the person opened.
  1. 1

    Any account can share a file by link

    OpenDrive lists file and folder sharing and hotlinking among its features, and its free Basic account gives at least 5 GB. A direct download link to an uploaded file is exactly what a loader needs.

  2. 2

    The address looks trusted

    Cofense wrote on 20 May 2026 that image hosting and cloud collaboration services are abused because security tools find it hard to tell normal traffic from a malicious picture. Blocking a whole storage service would break normal work for its users.

  3. 3

    The hidden part does not look like a program

    In the campaigns Cofense describes, a picture that looks like a desktop background carries a .NET loader that a script decodes. LevelBlue SpiderLabs found PNG files with an executable appended between text markers, which had to be reversed and base64 decoded before it could run.

  4. 4

    Files are replaced faster than they are removed

    The pairs in our data appear in a few minutes and are reported as a group. When one account is closed, a campaign simply uploads to the next. That is why these eight entries going offline does not mean the campaign has ended.

What Remcos is

Remcos is sold as remote control software, which is why its own features are the danger: whoever runs it can use your PC as if sitting at it.

QuestionWhat the sources saySource
What is it?A closed source tool marketed as remote control and surveillance software by a company called Breaking Security, used in malware campaignsMITRE ATT&CK S0332, modified 23 April 2026
What can it do?Log keystrokes, take screenshots, record the microphone, use the webcam, read and change the clipboard, upload, download and delete files, run commandsMITRE; Microsoft, Backdoor:Win32/Remcos
How does it arrive?Phishing emails with documents or archives posing as invoices and orders; in stego campaigns a script fetches a picture that hides the loaderCheck Point; Cofense, 20 May 2026
How does it hide?Injects itself into a legitimate process such as Windows Explorer or a browser and runs from memoryCofense; Check Point; MITRE
How does it stay?A registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\RunMITRE; LevelBlue SpiderLabs
How common is it?Cofense counted Remcos in 27% of the steganography campaigns it tracked, the largest share of any familyCofense, 20 May 2026

What OpenDrive virus (Remcos RAT delivered through web.opendrive.com) can steal or download

What Remcos can take from a Windows PC

A remote access trojan gives a person a seat at your computer, so the list below is what such a person can do, not what one build does on its own. Each item is named by at least one source.

Reported as possible

  • Every key you type
  • Screenshots of your screen
  • Your webcam
  • Your microphone
  • Clipboard contents
  • Saved passwords
  • Files searched for and taken
  • Files deleted or uploaded
  • Your PC used as a proxy
  • Extra malware downloaded
DataDetailSource
KeystrokesA keylogger that records what you type, including new passwordsMITRE; Microsoft
Screen, camera, soundAutomatic screenshots, webcam pictures and microphone recordingMITRE; Microsoft
ClipboardReads and changes what you copy, which matters for copied wallet addressesMITRE
FilesSearch, upload, download, delete and zip files for sendingMITRE
ControlRemote command line, process control, shutdown and restartMITRE
NetworkTurns the PC into a SOCKS5 proxy for other trafficMITRE

What this can cost you

Seeing opendrive.com in a log costs nothing. The risks below are for a Windows PC where a script or loader fetched one of these files and Remcos then ran.

  • High

    Passwords and accounts

    A keylogger records what you type into every site, including the new passwords you set. Changing passwords from the infected PC does not help.

  • High

    Someone using your PC live

    Remcos is not a one off theft. The controller can come back at any time, watch the screen and act while you are signed in.

  • High

    Money and crypto

    A watched bank session, a changed wallet address on the clipboard or a stolen wallet file can all lead to payments that cannot be reversed.

  • Medium

    Private files, camera and microphone

    Documents, photos and anything said near the PC are exposed while the trojan runs.

  • Medium

    Your employer's network

    Check Point says a Remcos infection can lead to follow on attacks, including ransomware, through stolen logins.

  • Low

    Nothing, if you only saw the name

    A blocked request or a log line with opendrive.com is not an infection. Most such requests are people opening their own files.

What you may notice, and what you may not

Remote access trojans are built to be quiet. Most victims notice nothing; the signs below come from the sources and are not certain.

SignWhat the reports show
A startup entry you did not makeMITRE says Remcos can add itself to the HKCU Run key so it starts at every sign in
A Defender detection named RemcosMicrosoft uses Backdoor:Win32/Remcos and variants such as Backdoor:Win32/Remcos.PDD!MTB
A file or registry key named RemcosMicrosoft's sample created a registry key HKEY_CURRENT_USER\SOFTWARE\Remcos-YTPKR1; names vary by build
Webcam light on, odd mouse movesThe tool can use the camera and the screen. This follows from the features; it is our reading
Accounts you did not touchNew sign ins, reset emails, messages you did not send. This follows from stolen logins
Nothing at allRunning in memory inside a trusted process is the point of the loader

How to check the PC for OpenDrive virus (Remcos RAT delivered through web.opendrive.com)

How to tell a bad OpenDrive link or file from a normal one

Look at how the file reached you and what opened it. The domain alone tells you nothing either way.

SignNormal useAbuse in the reports
How you met itA colleague or friend shared a folder you expectedAn unexpected email about an invoice, order or payment
What you openedA document, photo or video you can previewA .js, .vbs, .hta, .lnk or a zipped file that you had to run
Who downloads itYou, in the browser, with a visible downloadA script or program in the background, with no window
The addressA share page you can view in the browserA raw /api/v1/download/file.json/ link with ?inline=1, called by a program
What happens nextYou see the fileNothing visible, or a decoy document opens while something runs

The single rule that covers all eight reports: a file that only works after you run a script, enable content or open an attachment you did not expect is the dangerous part, wherever it is stored.

Check your PC before you delete anything

The question that matters: did you open an unexpected attachment, script or archive around 9 or 10 September 2026, or any time after? If you only saw the name opendrive.com in a log, you can stop here. If yes or you are not sure, do these checks. None of them deletes anything.

Use another device for banking, email and work until you finish.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the cable. A remote access trojan needs the connection to be used.

  2. 2

    Look at Protection history

    Open Windows Security > Virus & threat protection > Protection history. Write down any detection with Remcos in its name and the date.

  3. 3

    Look at what starts with Windows

    Open Settings > Apps > Startup and Task Manager's Startup apps. An entry with no publisher or a random name that runs from a user folder is worth a note.

  4. 4

    Open Task Scheduler

    Press Start, type Task Scheduler, open Task Scheduler Library and look for tasks that run a script from a user folder. Note them; do not delete yet.

  5. 5

    Find the file you opened

    Look in Downloads and your email for the attachment from that time. A .js, .vbs, .hta or an archive that held one is the likely start.

How to remove OpenDrive virus (Remcos RAT delivered through web.opendrive.com)

How to remove OpenDrive virus (malware delivered through web.opendrive.com)

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library.

    Select each task you do not recognise and read the Actions tab: a task that starts a file in %AppData% or %Temp%, runs powershell with a long encoded line, or opens a web address belongs to OpenDrive virus (malware delivered through web.opendrive.com) or a similar program.

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever OpenDrive virus (malware delivered through web.opendrive.com) installed usually starts with Windows.

    Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The tags and every source we read describe a Windows threat. OpenDrive is just as reachable from any device, but nothing we read says these files run on anything else.

Your deviceWhat we knowWhat to do
MacMITRE lists Remcos for Windows onlyNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source describes these files on iOSNothing to remove. Change passwords you typed into a strange page
AndroidNo source mentions them on AndroidNothing to remove for this threat

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything you typed or stored on it while the trojan was there. Another device first, then the PC.

Five steps in order: disconnect, change passwords from another device and sign out sessions, run Microsoft Defender Offline, check startup entries, reset Windows if unsure
The order of actions if a file from an OpenDrive link ran on a PC. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, because it resets everything else, then bank, work, cloud storage and crypto. Anything typed on the PC while it was watched is already known.

  2. 2

    Sign out every session

    Use each account's option to sign out of all devices, and turn on two step sign in so a password alone is not enough.

  3. 3

    Tell your employer

    If the PC had work accounts or you opened the file at work, tell IT the same day. A remote access trojan on one PC can be the start of a wider attack.

  4. 4

    Move crypto

    If a wallet was on the PC, make a new wallet on a clean device and move the funds.

Keep a PC out of this kind of chain

The storage link is the middle of the chain. Every write-up we read starts with a person opening a file.

Do

  • Treat an unexpected invoice, order or payment email with an attachment as an attack until proven otherwise.
  • Show file endings in File Explorer so a script posing as a document is visible.
  • Keep Windows and Microsoft Defender updated.
  • Use a password manager and two step sign in.
  • Report a bad OpenDrive file to support@opendrive.com with the full link, and to URLhaus.

Don't

  • Do not block the whole of opendrive.com if people in your company use it.
  • Do not trust a file just because it is stored on a known service.
  • Do not run .js, .vbs or .hta files from email.
  • Do not change passwords on the PC you suspect.
  • Do not treat a clean quick scan as proof after you ran an unknown script.

Questions about OpenDrive virus (Remcos RAT delivered through web.opendrive.com)

Is OpenDrive a virus?

No. OpenDrive is a cloud storage, backup and file sharing service run by OpenDrive, LLC in California, and its domain has been registered since 2003.

It is reported only because some people upload malicious files to it and point their malware at them. Its own terms forbid storing viruses and trojans. The service is safe; specific files can be dangerous.

Why did my antivirus block web.opendrive.com?

Most likely it blocked one file address, not the service. Look at the full link in the alert. If you were opening a folder someone shared with you on purpose, it may be a block on that one file.

If the alert came after you opened an unexpected attachment or script, treat it as an attack and follow the checks on this page.

What files were reported on OpenDrive?

URLhaus lists eight file addresses on web.opendrive.com, added on 9 and 10 September 2026 in four pairs. All eight are tagged RemcosRAT, rat and stego, and all eight were offline on 8 October 2026.

We did not download them, so their exact content is not confirmed by us. Each pair shares the first number of its decoded file id.

What is Remcos?

Remcos is a remote control program for Windows sold by a company called Breaking Security and widely used by criminals as a remote access trojan. MITRE ATT&CK and Microsoft say it can log keystrokes, take screenshots, use the webcam and microphone, read the clipboard and move files. Microsoft detects it as Backdoor:Win32/Remcos and related names.

What does stego mean in these reports?

It is short for steganography, hiding data inside another file. Cofense describes pictures that look like desktop backgrounds but carry a hidden .NET loader, and LevelBlue SpiderLabs found PNG files with a program appended between text markers. Looking at such a picture does nothing; a script that is already running decodes it.

I opened an attachment that may have used an OpenDrive link. What now?

Disconnect the PC, change your passwords from another device and sign out all sessions, then run Microsoft Defender Offline and check what starts with Windows.

If you are unsure, reset Windows. Tell your employer if work accounts were on the PC. Do not type new passwords on the PC you suspect.

Is it safe to use OpenDrive?

Yes, as a service. Storing and sharing your own files there carries the same risk as any other cloud storage.

What matters is a file someone else sends you and how you open it. Never run a script or an attachment you did not expect, wherever its download link points.

How do I report a malicious OpenDrive file?

Send the full link to OpenDrive at support@opendrive.com, the address its terms give for questions and notices. You can also submit the link to URLhaus at abuse.ch, which shares reports with security vendors and network operators who block such files.

Include the date you received it and, if you can, the email or page that pointed to it. Do not send the file itself as an attachment.

Does this affect my iPhone, Android phone or Mac?

Nothing we read says these files run on a phone or a Mac. Remcos is a Windows program, and MITRE lists Windows as its only platform.

If you typed a password into a strange page on any device, change it from a device you trust. The scripts that fetch the files are Windows scripts too.

Will Fortect remove OpenDrive virus (malware delivered through web.opendrive.com)?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For OpenDrive virus (malware delivered through web.opendrive.com), follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: OpenDrive virus (Remcos RAT delivered through web.opendrive.com)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year