La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Trojan.KillProc2.25259

Aggiunto al database dei virus Dr.Web: 2025-07-10

La descrizione è stata aggiunta:

Technical Information

Malicious functions
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\explorer.exe
  • <SYSTEM32>\taskhost.exe
  • <SYSTEM32>\dwm.exe
the following user processes:
  • iexplore.exe
  • firefox.exe
Modifies file system
Creates the following files
  • %WINDIR%y1s2fctrp3
  • %CommonProgramFiles%\microsoft shared\black xakmpl nom72kl l9hwcs7vvnphd9 hole nmibe2 .mpg.exe
  • %ProgramFiles%\dvd maker\shared\horse [bangbus] titts .zip.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\ bq4kno hole eigt45 .zip.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\beast hot (!) feet .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\f1i7cm 8ok6yf mzwpstr8n vjq39c1gwy .zip.exe
  • %ProgramFiles%\microsoft office\templates\upfgetx xakmpl gay nom72kl mg9fvb2xk9 .rar.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\mzwpstr8n epyxwn eigt45 .rar.exe
  • %ProgramFiles%\windows journal\templates\ [bangbus] glans (jenna,y8oxsqa).mpg.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\sperm uncut feet (haj1oyikd,2hbt8wr).avi.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\8r3baiec bd1l5ir mnho9y54 ihthd33 cock (haj1oyikd,g6u8n4r).mpeg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\beast big (sarah).zip.exe
  • %CommonProgramFiles(x86)%\microsoft shared\ikdyfwhy sperm nom72kl ejn547rbxhd1 .zip.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\nom72kl ihthd33 .mpeg.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\nom72kl hot (!) .avi.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\horse epyxwn hole 779mipj (jade).avi.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\s2fkave cum yzw1afy ihthd33 cock .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\gay uncut mg9fvb2xk9 .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\f1i7cm ddqayq horse sgu4m7oc girly .rar.exe
  • %ALLUSERSPROFILE%\templates\fac71w2 h93bklf mnho9y54 [milf] glans .rar.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\ girls hole .avi.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\f07qtt bd1l5ir horse ihthd33 .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\upfgetx nude gay uncut .avi.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\horse nom72kl qx2j1b5 (sonja,dxocjwba).rar.exe
  • %ALLUSERSPROFILE%\templates\z9z7rwe horse beast [free] ol6p1tua (gina,liz).mpg.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\upfgetx wep6b08 sperm vjq39c1gwy titts (jenna,cy4xpd).mpeg.exe
  • C:\users\default\appdata\local\temp\z9z7rwe 7nd83wovj gay [free] rv0y8n (sonja,dxocjwba).avi.exe
  • C:\users\default\appdata\local\<INETFILES>\fac71w2 7nd83wovj horse big .mpg.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\horse big rv0y8n .avi.exe
  • C:\users\default\templates\f1i7cm 8ok6yf sgu4m7oc hole .avi.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\black cum yzw1afy uncut b37oavmx289 .zip.exe
  • %TEMP%\black bd1l5ir yzw1afy vjq39c1gwy glans hotel .mpg.exe
  • %LOCALAPPDATA%\<INETFILES>\tsomq34 7vepaqjm .rar.exe
  • %LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\upfgetx cum yzw1afy apv53deiq9fw gh5b6gd7wrv .mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\eq7k2xcxt 7nd83wovj tsomq34 vjq39c1gwy hole .mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\gzn4ud7e w6csjja14n1 sperm 7vepaqjm glans girly .mpeg.exe
  • %APPDATA%\microsoft\templates\8r3baiec ddqayq xxx vjq39c1gwy boots .avi.exe
  • %APPDATA%\microsoft\windows\templates\f07qtt h93bklf gay sgu4m7oc cock sweet (sarah).avi.exe
  • %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\tsomq34 uncut zmc8ujp .mpg.exe
  • %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\mnho9y54 uncut boots .avi.exe
  • %HOMEPATH%\templates\z9z7rwe 7nd83wovj xxx bq4kno zmc8ujp .mpeg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\gay uncut gsva2xn .zip.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\black bd1l5ir horse [milf] shoes .zip.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\mnho9y54 vjq39c1gwy hole ash (c4w8hqa).avi.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\ddqayq gay l9hwcs7vvnphd9 (g6u8n4r).mpeg.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\tsomq34 uncut ejn547rbxhd1 (sandy,sarah).rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\gzn4ud7e h93bklf nom72kl big zmc8ujp .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\fac71w2 7nd83wovj sperm uncut glans nrb42wq (y8oxsqa).mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\lpcu5ai3 sgu4m7oc hole gh5b6gd7wrv .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\upfgetx bd1l5ir lpcu5ai3 [milf] mg9fvb2xk9 .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\gzn4ud7e horse mnho9y54 uncut .avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\horse uncut fw58kpr41ob1w (dehod0,c4w8hqa).mpeg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\black bd1l5ir beast 7vepaqjm 40+ (rdl1tfkz,karin).avi.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\beast ihthd33 nrb42wq .avi.exe
  • %WINDIR%\assembly\temp\gay [free] b37oavmx289 .rar.exe
  • %WINDIR%\assembly\tmp\nom72kl uncut .mpeg.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\beast epyxwn hole qq6w54yfhtqrbwcslg (liz).mpeg.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\f07qtt w6csjja14n1 gay [free] glans .zip.exe
  • %WINDIR%\pla\templates\upfgetx xakmpl horse [milf] feet .mpeg.exe
  • %WINDIR%\security\templates\z9z7rwe h93bklf mnho9y54 big cock ejn547rbxhd1 (g6u8n4r).mpeg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\f07qtt h93bklf tsomq34 big titts .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\fac71w2 ddqayq sperm big titts girly (c4w8hqa).rar.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\s2fkave 7nd83wovj nom72kl girls js80j73 .mpg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\xxx apv53deiq9fw (sarah).zip.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\8r3baiec nude xxx [free] 40+ .rar.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\xxx l9hwcs7vvnphd9 hole .avi.exe
  • %WINDIR%\syswow64\config\systemprofile\f1i7cm 8ok6yf mnho9y54 ihthd33 .mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\gzn4ud7e ddqayq mzwpstr8n epyxwn feet shoes (sarah).zip.exe
  • %WINDIR%\syswow64\fxstmp\wep6b08 beast [bangbus] feet zmc8ujp (liz).mpeg.exe
  • %WINDIR%\syswow64\ime\shared\s2fkave cum gay hot (!) shoes (sandy,c4w8hqa).rar.exe
  • %WINDIR%\syswow64\config\systemprofile\ uncut feet girly .zip.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\s2fkave porn lpcu5ai3 big titts shoes (dxocjwba).mpg.exe
  • %WINDIR%\syswow64\fxstmp\s2fkave 8ok6yf gay 7vepaqjm (dxocjwba).avi.exe
  • %WINDIR%\syswow64\ime\shared\mnho9y54 bq4kno glans zn3tvn .avi.exe
  • %WINDIR%\temp\f07qtt 8ok6yf sperm uncut hole rv0y8n .zip.exe
  • %WINDIR%\winsxs\installtemp\jxaglwti mnho9y54 big lzxyhb7k .mpg.exe
  • <Current directory>\sqjaed7r1vnw
  • %CommonProgramFiles%\microsoft shared\gay epyxwn .rar.exe
  • %ProgramFiles%\dvd maker\shared\8r3baiec ddqayq hot (!) cock shoes .mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\sperm hot (!) feet .mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\upfgetx bd1l5ir tsomq34 hot (!) lzxyhb7k .mpeg.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\f07qtt nude horse [free] girly .avi.exe
  • %ProgramFiles%\microsoft office\templates\yzw1afy [milf] (2hbt8wr).mpg.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\fac71w2 xakmpl horse apv53deiq9fw hole .avi.exe
  • %ProgramFiles%\windows journal\templates\nom72kl l9hwcs7vvnphd9 .mpg.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\upfgetx porn yzw1afy sgu4m7oc balls (36mho73,y8oxsqa).zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\gay [bangbus] feet .mpg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\fac71w2 ddqayq mzwpstr8n uncut titts gsva2xn .rar.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\black w6csjja14n1 tsomq34 big cock gh5b6gd7wrv .mpg.exe
  • %CommonProgramFiles(x86)%\microsoft shared\8r3baiec w6csjja14n1 mzwpstr8n [free] (jade).avi.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\fac71w2 7nd83wovj xxx l9hwcs7vvnphd9 titts .mpg.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\f07qtt nude xxx 7vepaqjm shoes .zip.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\gzn4ud7e xakmpl nom72kl vjq39c1gwy (karin).zip.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\z9z7rwe 8ok6yf gay 7vepaqjm glans .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mnho9y54 sgu4m7oc sweet .zip.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\fac71w2 horse mnho9y54 big balls .mpeg.exe
  • %ALLUSERSPROFILE%\templates\mzwpstr8n nom72kl (cy4xpd).rar.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\ ihthd33 sm .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\8r3baiec wep6b08 gay epyxwn cock lzxyhb7k (karin).zip.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mzwpstr8n ihthd33 boots .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\f1i7cm cum lpcu5ai3 apv53deiq9fw cock hairy (g6u8n4r).zip.exe
  • %ALLUSERSPROFILE%\templates\upfgetx ddqayq mnho9y54 apv53deiq9fw titts .zip.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\fac71w2 bd1l5ir nom72kl uncut (jade).zip.exe
  • C:\users\default\appdata\local\temp\xxx big feet .avi.exe
  • C:\users\default\appdata\local\<INETFILES>\horse ihthd33 .mpg.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\mnho9y54 [free] ejn547rbxhd1 .mpg.exe
  • C:\users\default\templates\horse [milf] titts .mpeg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\f07qtt nude horse 7vepaqjm (cy4xpd).zip.exe
  • %TEMP%\beast nom72kl feet .mpeg.exe
  • %LOCALAPPDATA%\<INETFILES>\s2fkave cum lpcu5ai3 epyxwn 6tl9zg0uqa .zip.exe
  • %LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\f1i7cm nude horse uncut (dxocjwba).mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\yzw1afy sgu4m7oc 50+ .mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\upfgetx wep6b08 sperm hot (!) hole .rar.exe
  • %APPDATA%\microsoft\templates\sperm 7vepaqjm b37oavmx289 .avi.exe
  • %APPDATA%\microsoft\windows\templates\upfgetx wep6b08 tsomq34 epyxwn hotel .mpeg.exe
  • %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\gay [free] balls .zip.exe
  • %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\gay epyxwn hole .avi.exe
  • %HOMEPATH%\templates\s2fkave 7nd83wovj mzwpstr8n [free] hole .avi.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\fac71w2 cum horse uncut glans lady .mpeg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\s2fkave w6csjja14n1 mzwpstr8n ihthd33 titts young .zip.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\f1i7cm h93bklf vjq39c1gwy (sarah).avi.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\xxx [milf] titts .rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\nom72kl 7vepaqjm young .zip.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\fac71w2 7nd83wovj tsomq34 [bangbus] (2hbt8wr).rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\mnho9y54 sgu4m7oc glans .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\xxx sgu4m7oc glans .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\f07qtt 7nd83wovj xxx uncut 40+ .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\tsomq34 nom72kl .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\upfgetx ddqayq beast hot (!) feet 8bgkvshe1 .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\lpcu5ai3 uncut glans .mpg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\tsomq34 [bangbus] .zip.exe
  • %WINDIR%\assembly\temp\upfgetx porn xxx girls cock .avi.exe
  • %WINDIR%\assembly\tmp\8r3baiec h93bklf horse [free] hole .rar.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\f1i7cm h93bklf yzw1afy [free] .avi.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\sperm apv53deiq9fw sm .rar.exe
  • %WINDIR%\pla\templates\mzwpstr8n girls .mpeg.exe
  • %WINDIR%\security\templates\8r3baiec wep6b08 horse vjq39c1gwy cock mg9fvb2xk9 .mpg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\fac71w2 7nd83wovj mnho9y54 l9hwcs7vvnphd9 feet .mpg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\fac71w2 porn mnho9y54 7vepaqjm titts ol6p1tua .mpeg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\ epyxwn (cy4xpd).mpeg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\sperm 7vepaqjm .avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\lpcu5ai3 [milf] fishy (rdl1tfkz,dxocjwba).mpeg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\nom72kl nom72kl hole .mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\black 7nd83wovj mzwpstr8n big balls (dehod0,liz).rar.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\f1i7cm wep6b08 lpcu5ai3 apv53deiq9fw feet .mpg.exe
  • %WINDIR%\syswow64\fxstmp\black bd1l5ir horse bq4kno feet latex .avi.exe
  • %WINDIR%\syswow64\ime\shared\gay ihthd33 40+ .avi.exe
  • %WINDIR%\syswow64\config\systemprofile\8r3baiec 8ok6yf tsomq34 ihthd33 ol6p1tua (rdl1tfkz,2hbt8wr).avi.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\nom72kl girls glans .zip.exe
  • %WINDIR%\syswow64\fxstmp\xxx bq4kno titts .avi.exe
  • %WINDIR%\syswow64\ime\shared\upfgetx nude sperm bq4kno rv0y8n .avi.exe
  • %WINDIR%\temp\nom72kl 7vepaqjm qx2j1b5 .mpg.exe
  • %WINDIR%\winsxs\installtemp\h93bklf gay [free] .mpeg.exe
Miscellaneous
Searches for the following windows
  • ClassName: 'Progman' WindowName: ''
  • ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
  • '%WINDIR%\explorer.exe'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android