Security Blog
Security Blog
Malware analysis, security tips and product news from the Adlice team.

Your Outdated Software Is an Open Door for Hackers
We’ve all done it. A little popup appears in the corner of the screen: “Update available.” You click “Remind me later” without a second thought. Maybe you’re in the middle of something. Maybe you just don’t want to deal with a restart right now. Totally understandable. The problem is that hackers ar

Online Course Scam: How to Spot Fake Courses & Stay Safe
The e-learning boom has a dark side. The online course scam is now a full-blown industry. Beyond bad advice, many online gurus now use their platforms to spread malicious software. The FTC’s 2025 Ransomware Report highlights how tech support scams and malware-based attacks continue to target consume

Windows 10 Updates Are Ending — Don’t Let Your PC Become a Target
Microsoft will stop free updates for Windows 10 in October 2025. Unpatched systems will face growing risks. Here’s how Adlice Protect keeps you safe. The End of an Era Microsoft has officially confirmed that Windows 10 support ends on October 14, 2025.After that date, your computer will no longer re

Your Computer is Slow? Here are The Best Tools to Speed Things Up
A slow computer is one of the most frustrating things you can face. Whether you’re trying to work, play, or just browse the internet, waiting for your PC to respond can feel like forever. The good news? You don’t need to buy a new machine right away. With the right optimizations and tools, you can…

SmartScreen Block: We need your help !
If you’ve ever tried to install one of our software and encountered a SmartScreen block, you know how frustrating it can be. Microsoft SmartScreen is a security feature designed to protect users by warning them about unknown or unverified software. While this system is meant to shield users from pot

RogueKiller becomes Adlice Protect !
RogueKiller, our in-house Anti-malware scanner and protection, has been around for more than 15 years. Today, we have decided to rebrand for a more “explicit” brand name, ADLICE PROTECT, and to add new major features. Take the tour. SUMMARY WARNING. Due to certificate changes, with have problems wit

Introducing: Community Updates for UCheck
UCheck now uses a list of 10000+ software from a “Community list” to extend version check capatiblities. Take the tour.

Defend Against Online Scams: A Comprehensive Guide to Online Safety
In today’s digital age, the internet has revolutionized the way we live, work, and connect with others. However, this interconnectedness also exposes us to the risk of online scams. Online scams come in various forms, from phishing emails and fake websites to identity theft and financial fraud. To p

Internet Safety for Children: How to Keep Your Kids Safe Online
As technology has evolved, so has the way we communicate, socialize and learn. Unfortunately, this evolution has also brought about new risks and challenges, especially for children. The internet can be a dangerous place for children if they are not properly protected. Therefore, it is essential for

How to Keep Your Passwords Safe: Tips and Tricks
Learn how to keep your passwords safe with these expert best practices. Discover the importance of strong passwords to protect you online.

Introducing: RogueKiller Clipboard Protection
RogueKiller Anti-malware is already protecting against different kind of threats, but what if a malware is very new, totally unknown and tries to steal your most critical data, like credit card information or your bank account password ? We thought about it, and made the clipboard protection module.

Introducing: UCheck PUP Protection
Some software monetize themselves with partnerships with other companies, and bundling their installers with optional software offers. Starting with UCheck 3.10, PUP Protection is available (BETA) and prevents optional offers to install on the system when running a setup

Introducing: RogueKiller Data Leak Protection
After a company is victim of a Ransomware, they are asked a ransom to recover the files and avoid them to be leaked online. This is why we have developed DLP, for Data Leak Prevention, in our RogueKiller Anti-malware product.

What is a Computer Worm ? How to Remove ?
Computers worms are designed to leverage vulnerabilities that allow them to gain control over a device then scan the network for other vulnerable devices and so one

What is a Trojan ? How to Remove ?
Trojan horses usually use social engineering, like a pirated software or a fake Office document send by mail, to gain control over a computer. Once installed, they usually hide themselves from the system and make it impossible for the user to remove.

What is an Adware ? How to Remove ?
Adware (ad-ware) are a quite recent thread, compared of the others. They begin to rise in popularity with the decline of the shareware license model. Instead of offering trial version of the software they developed, software writers began to include ads in their installers

What is a Virus ? How to Remove ?
Computer viruses were the first kind of malware that were developed. At the beginning, they were not malicious per se (the first computer virus “Creeper”, developed in 1970 only displayed a message), but soon after malicious ones begin to appear and counter-measures known as “anti-virus” software we

How to Avoid Being Hacked: The Ultimate Guide
With the development of broadband Internet connections, online/cloud-based services have become more and more numerous. Your data is not only located on your computer anymore but on a multitude of online servers. Not only you now should consider what could happen if your computer gets infected, but

Introducing RogueKiller 14
We are pleased to announce our flagship, RogueKiller Anti-malware, is finally available for version 14 BETA testing. Version 14 is a very big milestone for us because it introduces a major new feature that customers have been asking us for a long time: Real Time Protection. Let’s take a look. Real T

Introducing UCheckCMD
We are proud to present you today a new software (or rather a new variant of an existing software) that was many times requested by our customers, UCheckCMD. Test it now !

Introducing RogueKiller V13
We are proud to announce that our popular Anti-maware RogueKiller new version, that we’ve been working on hardly for the past year, has been released ! Test it now.

Introducing Adlice Diag
We are proud to announce that our new project, that we’ve been working on hardly for the past year, has been released ! It is called Adlice Diag, and it will be your favorite software when it comes to diagnose a machine’s health…

KMS Activators, Are They Malware?
Infections related to the use of hacktools like Windows Loader or KMSPico are rising. Learn how malware authors use them to spread cryptominers, ransomwares and ultimately take control of your newly installed operating system.

What happens on the Darknet ?
Alpha bay, Silk Road, Hansa: They made the headlines of newspapers for weeks. They were underground markets offering several illicit goods and services and were shut down in 2013 and 2017. All were using Tor, currently the most used parallel Internet network, called Darknet. DARKNET Computers connec

New Trend in Malware: Crypto miners (Bitcoin, Monero)
A major increase in the number of malware featuring cryptominers has been observed. Discover the way malware writers make money with them.

How to Hack with Mimikatz: Tutorial
If you are a hacker, you probably already know about mimikatz. This tool is widely used by hackers to retrieve passwords. Learn how to use.

CCleaner Delivers Floxif Malware
Popular cleanup tool CCleaner was compromised to deliver the Floxif malware. Learn how this happened and find if you are at risk.

How to Remove Adware.Lsmo / Myking.top
Infected with Adware.Lsmo ? Follow this step-by-step guide for malware removal of the Adware.Lsmo infection and clean your machine.

What is Code Signing?
Code signing is required to load drivers in Windows. Also, they tell users if an application can be trusted and launched. Learn how it works.

How to setup your malware honeypot (V2)
Catch malware with your own Honeypot – Learn how to deploy a honeypot in 10 minutes with this step by step guide about Cuckoo sandbox. Easy sandboxing.

Cuckoo Sandbox Customization (V2)
Get an anti-malware removal report with a very simple cuckoo sandbox customization. Learn how Cuckoo works and how to add custom modules.

How to Remove Malware from my PC
Your machine is infected? Try this step by step guide to get rid of most malware and cleanup your machine from nasty infections.

Macro malware, the biggest online threat
Macro malware are known for decades but still remain the preferred infection method for infecting machines with Ransomware, Trojans, … Learn how it works.

MongoDB Ransomware is spreading
Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database now.

Introducing: Adlice Labs
We, at Adlice Software, have started from scratch 5 years ago. Today, I’m proud to show you the way we work with our brand new Labs, Adlice Labs.

Exploits Explained, Exploit Kits (Part 3)
Discover exploitation methods, exploits development and inner workings and learn about the countermeasures that exists to protect your infrastructure.

Google Chrome: How to Bypass Secure Preferences
Google Chrome protects its user preferences using a hashing mechanism. However, there’s a way to bypass this, and it’s quite used by malware in the wild.

Fileless Malware using Powershell: Analysis & Removal
Fileless malware has always been popular and widely covered (Example: Poweliks). Study of a fileless malware stored in the task scheduler.

MRF: Introducing Sample Page
MRF (Malware Repository Framework) V4.2 has been released. Take a look at the awesome new features (and bugfixes) it brings. Try it now!

Adlice PEViewer : Bring Analysis to the Next Level
Adlice PEViewer is a PE parsing tool helping you in your everyday malware analysis and debugging. Learn how it works and how amazing it can be.

Exploits Monetizing, Exploit Kits (Part 2)
Discover the inner working of the places where transactions between exploits dealers take place and the conditions of such transactions.

RogueKiller, Inside WMI Scanner
Quick approach about Windows Management Instrumentation (WMI). Meet Adware Yeabests, hiding in the WMI and see how RogueKiller takes care of it.

Exploits Definition, Exploit Kits (Part 1)
Exploits and Exploit kits play a major role in the spread of malware. Learn how they work and how to protect yourself from such threats.

Ransomware : How to protect yourself against them
Ransomware became the threats of the web. Learn how they work, their effects, and how to protect yourself from such malware.

Cuckoo Sandbox Customization
Get an anti-malware removal report with a very simple cuckoo sandbox customization. Learn how Cuckoo works and how to add custom modules.

Free Stack for Small Development Teams
FREE stack for small development teams. Get your own with Gitlab, Trello, Freshdesk and more, everything connected into the same Slack chat.

How to Remove Potentially Unwanted Modification (PUM) ?
Got infected with a PUM (Ppotentially Unwanted Modification)? Follow this step by step guide to get rid of it. Our guide also includes a short analysis.

Infected PDF : How to Extract the payload ?
Infected PDF: Extract the payload – Infected PDFs have always been a popular way to infect computers, learn how it malicious PDF files are built.

Catch malware with your own Honeypot
Catch malware with your own Honeypot – Learn how to deploy a honeypot in 10 minutes with this step by step guide about Cuckoo sandbox. Easy sandboxing.

RunPE: How to hide code behind a legit process
RunPE: How to hide code behind a legit process – RunPE is a trick used by some malware to hide code into a legit process. Learn how to detect.

What’s a malware ? Definition of Virus, Adware, Spyware
This is a general explanation about different kind of online threats. What they do, and how. Introduction to viruses, malware, worms, adware and others.

BreakingNews PUP, Study of an aggressive rootkit
PUPs (for potentially unwanted programs) are harmless by design, most of the time. Here we will study a case where such program behaves like a rootkit.

Internet Explorer BHO: A spy in your browser
Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser. Learn how it works to better prevent further infections.

How to Remove Bootkit (Guide)
Got infected with a Bootkit (boot rootkit)? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

How to Remove Gootkit (Guide)
Got infected with Gootkit malware? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

How to Remove Zeus (Guide)
Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

Userland Rootkits: Part 1, IAT hooks
Userland Rootkits explained. This is the first part of this rootkit writing tutorial in which we will detail the basics about userland rootkits.

How to Remove Poweliks (Guide)
Got infected with Poweliks malware? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

KernelMode Rootkits: Part 3, kernel filters
KernelMode Rootkits explained. This is the third part of this rootkit writing tutorial in which we will detail the basics about kernel rootkits.

KernelMode Rootkits: Part 2, IRP hooks
KernelMode Rootkits explained. This is the second part of this rootkit writing tutorial in which we will detail the basics about kernel rootkits.

KernelMode Rootkits: Part 1, SSDT hooks
KernelMode Rootkits explained. This is the first part of this rootkit writing tutorial in which we will detail the basics about kernel rootkits.

Dear Antivirus, Why don’t you like me ?
We always rely on antiviruses to keep our machines safe and protected. This time, I got angry against them because of many false positives.

How to Remove Necurs (Guide)
Got infected with Necurs rootkit? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

How to Remove PUP (Guide)
Got infected with PUP (Potentially Unwanted Program)? Follow this step by step guide to get rid of it, and learn to avoid next infection.

Facebook Scams: A look behind the scene
You’ve all seen Facebook posts shared by your friends with attractive titles, waiting for you to click. We’ve clicked for you, and you will be deceived.

Chronicles of a PE Infector
Writing and Analysis of a portable executable (PE) infector. Educational tutorial on how to write your own PE infector that remains hidden in the system.

Symmi Ransomware Decryption
Anlysis of Win32.Symmi Ransomware – Learn how this ransomware encrypts your files, and how to defeat it to decrypt your personal data.

PE Smallest Executable
Learn how to modify a portable executable (pe) file to strip all the junk code and keep only the strict minimal bytes to keep it perfectly functional.

How to Remove Zekos (Guide)
Got infected with Zekos malware? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

How to Remove CryptoLocker (Guide)
Got infected with CryptoLocker ransomware? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

How to Remove Carberp (Guide)
Got infected with Carberp (Zeus/Zbot variant)? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.

How to Remove ZeroAccess (Guide)
Got infected with ZeroAccess (Sirefef) rootkit? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the rootkit.

How to Make an antivirus engine
Learn the theory with code snippets on how making your own robust and reliable Antivirus / Anti-malware engine. Step by step guide.

Carberp bootkit : How self-protection is effective
Analysis of the Carberp bootkit capabilities to hide into the system, and self protect its components with a filter driver.

Carberp anti-rapport : Beating Trusteer protection
Carberp Anti Rapport Trusteer – How the Carberp malware is defeating Anti Rapport (from Trusteer) to gain access to the bank account of a victim.