Per il corretto funzionamento del sito, è necessario attivare il supporto di JavaScript nel browser.
Trojan.KillProc2.28868
Aggiunto al database dei virus Dr.Web:
2025-07-16
La descrizione è stata aggiunta:
2025-07-18
Technical Information
Malicious functions
Terminates or attempts to terminate
the following system processes:
%WINDIR%\explorer.exe
<SYSTEM32>\taskhost.exe
<SYSTEM32>\dwm.exe
the following user processes:
Modifies file system
Creates the following files
%WINDIR%y1s2fctrp3
%CommonProgramFiles%\microsoft shared\porn mzwpstr8n 7vepaqjm .mpeg.exe
%ProgramFiles%\dvd maker\shared\jxaglwti 8ok6yf cum girls ash .mpg.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\lpcu5ai3 vjq39c1gwy legs b37oavmx289 (y8oxsqa,hyo87il).rar.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\xakmpl lpcu5ai3 girls wifey .mpg.exe
%ProgramFiles%\microsoft office\office14\groove\xml files\space templates\s2fkave sperm nom72kl kfp2yqq 50+ (g6u8n4r,sonja).zip.exe
%ProgramFiles%\microsoft office\templates\0287zh gay 8ok6yf l9hwcs7vvnphd9 latex .mpeg.exe
%ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\nude hot (!) qq6w54yfhtqrbwcslg (36mho73,cy4xpd).mpg.exe
%ProgramFiles%\windows journal\templates\sperm [free] nrb42wq .zip.exe
%ProgramFiles%\windows sidebar\shared gadgets\wep6b08 mnho9y54 ihthd33 sm .rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\0287zh ddqayq horse epyxwn titts ae2sd7u4xh .avi.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\eq7k2xcxt lpcu5ai3 cum 7vepaqjm .rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\f1i7cm nude mzwpstr8n l9hwcs7vvnphd9 kfp2yqq .zip.exe
%CommonProgramFiles(x86)%\microsoft shared\viaz50 nude horse hot (!) hotel .rar.exe
%ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\4h1e2a346 sperm uncut .zip.exe
%ProgramFiles(x86)%\windows sidebar\shared gadgets\upfgetx lpcu5ai3 gay 7vepaqjm feet (gina).rar.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\lpcu5ai3 8ok6yf nom72kl mg9fvb2xk9 (cy4xpd).zip.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\upfgetx 8ok6yf [milf] ash sgoibhh .zip.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\7b6fhxi tsomq34 girls 50+ .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\gay wep6b08 epyxwn 6tl9zg0uqa .avi.exe
%ALLUSERSPROFILE%\templates\7b6fhxi ddqayq 7nd83wovj 7vepaqjm .zip.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\nude sgu4m7oc kfp2yqq 40+ .mpeg.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\0287zh horse 7nd83wovj epyxwn .mpeg.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\jxaglwti cum sperm nom72kl cock (dehod0).mpeg.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\porn bd1l5ir big (36mho73).mpg.exe
%ALLUSERSPROFILE%\templates\h93bklf bd1l5ir ihthd33 girly .zip.exe
C:\users\default\appdata\local\microsoft\windows\<INETFILES>\fac71w2 h93bklf h93bklf nom72kl (cy4xpd,y8oxsqa).mpg.exe
C:\users\default\appdata\local\temp\mzwpstr8n cum bq4kno cock js80j73 .avi.exe
C:\users\default\appdata\local\<INETFILES>\gay hot (!) jxqgtp sweet .rar.exe
C:\users\default\appdata\roaming\microsoft\windows\templates\f1i7cm horse uncut zmc8ujp (sonja,sonja).rar.exe
C:\users\default\templates\gzn4ud7e nude epyxwn titts nrb42wq .mpeg.exe
%LOCALAPPDATA%\microsoft\windows\<INETFILES>\0287zh xxx apv53deiq9fw .avi.exe
%TEMP%\viaz50 8ok6yf nom72kl ihthd33 hole .rar.exe
%LOCALAPPDATA%\<INETFILES>\black 7nd83wovj bd1l5ir [milf] hole sm (cy4xpd).mpg.exe
%LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\z1qxwcd 8ok6yf big (sonja).zip.exe
%LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\gay [milf] 50+ .avi.exe
%LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\wpjwijv nom72kl ihthd33 sm .rar.exe
%APPDATA%\microsoft\templates\asian sperm gay [milf] young (haj1oyikd).rar.exe
%APPDATA%\microsoft\windows\templates\mzwpstr8n yzw1afy l9hwcs7vvnphd9 jxqgtp gh5b6gd7wrv .avi.exe
%APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\f07qtt cum tsomq34 l9hwcs7vvnphd9 lzxyhb7k (y8oxsqa,2hbt8wr).mpg.exe
%APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\f07qtt xakmpl mnho9y54 ihthd33 boobs .mpeg.exe
%HOMEPATH%\templates\eq7k2xcxt nom72kl wep6b08 l9hwcs7vvnphd9 lady .rar.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\xxx girls (g6u8n4r,karin).mpg.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\7b6fhxi mnho9y54 wep6b08 [bangbus] fw58kpr41ob1w .rar.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\eq7k2xcxt mnho9y54 yzw1afy bq4kno legs .rar.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\nom72kl vjq39c1gwy eigt45 (rdl1tfkz).zip.exe
%WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\s2fkave ddqayq 7nd83wovj bq4kno fishy .mpeg.exe
%WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\gzn4ud7e horse sperm [milf] 6tl9zg0uqa (dxocjwba).rar.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\gzn4ud7e nom72kl h93bklf [milf] .mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\upfgetx porn sgu4m7oc boots (y8oxsqa).mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zc8giv9 cum porn l9hwcs7vvnphd9 .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\cum girls hairy (sandy).zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\f1i7cm wep6b08 horse nom72kl cock rv0y8n (sonja,cy4xpd).mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\jxaglwti 7nd83wovj beast 7vepaqjm (sandy).mpg.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\wpjwijv mzwpstr8n 7nd83wovj vjq39c1gwy balls .mpeg.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\f07qtt xxx yzw1afy sgu4m7oc .mpeg.exe
%WINDIR%\assembly\temp\sperm gay [milf] zn3tvn (sandy).rar.exe
%WINDIR%\assembly\tmp\4h1e2a346 beast mzwpstr8n sgu4m7oc zn3tvn (y8oxsqa).zip.exe
%WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\ikdyfwhy horse w6csjja14n1 apv53deiq9fw .rar.exe
%WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\asian w6csjja14n1 nude big .rar.exe
%WINDIR%\pla\templates\porn hot (!) b37oavmx289 .mpg.exe
%WINDIR%\security\templates\0287zh 8ok6yf epyxwn feet .mpg.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\s2fkave h93bklf cum uncut ash .zip.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\temp\fac71w2 xakmpl tsomq34 l9hwcs7vvnphd9 glans zn3tvn .zip.exe
%WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\w6csjja14n1 w6csjja14n1 [milf] ejn547rbxhd1 .zip.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\4h1e2a346 7nd83wovj mnho9y54 l9hwcs7vvnphd9 jxqgtp (sarah).mpeg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\temp\yzw1afy xxx [free] boobs 50+ (c4w8hqa).rar.exe
%WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\f1i7cm bd1l5ir [free] boots .rar.exe
%WINDIR%\syswow64\config\systemprofile\ddqayq ddqayq bq4kno nmibe2 .mpeg.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\ikdyfwhy w6csjja14n1 xxx [free] b37oavmx289 .mpeg.exe
%WINDIR%\syswow64\fxstmp\f1i7cm horse 7nd83wovj girls legs latex (dxocjwba,jenna).avi.exe
%WINDIR%\syswow64\ime\shared\eq7k2xcxt horse porn big .avi.exe
%WINDIR%\syswow64\config\systemprofile\asian w6csjja14n1 yzw1afy l9hwcs7vvnphd9 zn3tvn (y8oxsqa).zip.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\gzn4ud7e tsomq34 xakmpl hot (!) .mpeg.exe
%WINDIR%\syswow64\fxstmp\7b6fhxi gay apv53deiq9fw (c4w8hqa,dxocjwba).rar.exe
%WINDIR%\syswow64\ime\shared\fac71w2 tsomq34 cum hot (!) glans .mpeg.exe
%WINDIR%\temp\h93bklf [milf] titts .zip.exe
%WINDIR%\winsxs\installtemp\zc8giv9 7nd83wovj 7vepaqjm sgoibhh .zip.exe
Miscellaneous
Searches for the following windows
ClassName: 'Progman' WindowName: ''
ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
Curing recommendations
Windows
macOS
Linux
Android
If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space .
If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.
If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
Switch off your device and turn it on as normal.
Find out more about Dr.Web for Android
Scaricate Dr.Web per Android
Gratis per 3 mesi
Tutti i componenti di protezione
Rinnovo versione di prova tramite AppGallery/Google Pay
Continuando a utilizzare questo sito, l'utente acconsente al nostro utilizzo di file Cookie e di altre tecnologie per la raccolta di informazioni statistiche sui visitatori. Per maggiori informazioni
OK