La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Trojan.KillProc2.29662

Aggiunto al database dei virus Dr.Web: 2025-07-17

La descrizione è stata aggiunta:

Technical Information

Malicious functions
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\explorer.exe
  • <SYSTEM32>\taskhost.exe
  • <SYSTEM32>\dwm.exe
the following user processes:
  • iexplore.exe
  • firefox.exe
Modifies file system
Creates the following files
  • %WINDIR%y1s2fctrp3
  • %CommonProgramFiles%\microsoft shared\z9z7rwe w6csjja14n1 hot (!) 40+ (karin,jenna).rar.exe
  • %ProgramFiles%\dvd maker\shared\f1i7cm 8ok6yf sperm vjq39c1gwy .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\beast [free] 779mipj .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\tsomq34 xxx hot (!) .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\z1qxwcd nude cum [milf] jxqgtp nmibe2 .zip.exe
  • %ProgramFiles%\microsoft office\templates\yzw1afy uncut .rar.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\mnho9y54 sgu4m7oc .avi.exe
  • %ProgramFiles%\windows journal\templates\sperm mnho9y54 sgu4m7oc .rar.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\0287zh xakmpl mzwpstr8n uncut .mpeg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\w6csjja14n1 [free] sgoibhh .mpg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\8r3baiec gay [bangbus] .mpeg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\ikdyfwhy h93bklf [free] .zip.exe
  • %CommonProgramFiles(x86)%\microsoft shared\8r3baiec yzw1afy horse big 779mipj .avi.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\gzn4ud7e 8ok6yf ihthd33 boobs shoes .rar.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\zc8giv9 horse l9hwcs7vvnphd9 gsva2xn .rar.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\xxx 7nd83wovj epyxwn hole lady (jade).mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\s2fkave horse mnho9y54 [free] lzxyhb7k .zip.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\zc8giv9 nude bd1l5ir [milf] jxqgtp ejn547rbxhd1 .mpeg.exe
  • %ALLUSERSPROFILE%\templates\mnho9y54 sperm uncut ash .zip.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\h93bklf horse big .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\black h93bklf vjq39c1gwy titts (dehod0,dxocjwba).zip.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\8ok6yf big jxqgtp sgoibhh .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\f07qtt bd1l5ir wep6b08 l9hwcs7vvnphd9 fishy .avi.exe
  • %ALLUSERSPROFILE%\templates\asian yzw1afy girls zn3tvn .zip.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\viaz50 horse mnho9y54 ihthd33 (hyo87il).zip.exe
  • C:\users\default\appdata\local\temp\upfgetx mzwpstr8n girls 6tl9zg0uqa .avi.exe
  • C:\users\default\appdata\local\<INETFILES>\ddqayq apv53deiq9fw 8pfmdyy .mpeg.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\8ok6yf mnho9y54 nom72kl cock ol6p1tua .avi.exe
  • C:\users\default\templates\z1qxwcd 7nd83wovj porn [milf] b37oavmx289 .rar.exe
  • %TEMP%\7b6fhxi nude bq4kno cock balls (rdl1tfkz,36mho73).mpeg.exe
  • %LOCALAPPDATA%\<INETFILES>\gay sperm hot (!) boots .rar.exe
  • %LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\z1qxwcd h93bklf nom72kl feet .mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\ddqayq epyxwn .mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\ddqayq mnho9y54 hot (!) .avi.exe
  • %APPDATA%\microsoft\templates\s2fkave wep6b08 nude [free] cock fishy (y8oxsqa,jade).rar.exe
  • %APPDATA%\microsoft\windows\templates\xxx [milf] boobs .zip.exe
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\z9z7rwe yzw1afy xakmpl [milf] .mpeg.exe
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\ikdyfwhy mnho9y54 7vepaqjm boobs qx2j1b5 .avi.exe
  • %HOMEPATH%\templates\zc8giv9 wep6b08 wep6b08 big kfp2yqq .avi.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\fac71w2 w6csjja14n1 gay ihthd33 titts .mpg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\0287zh horse mzwpstr8n vjq39c1gwy .mpeg.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\xakmpl bd1l5ir 7vepaqjm 6tl9zg0uqa .rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\upfgetx bd1l5ir tsomq34 epyxwn 40+ (c4w8hqa,jade).rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\wep6b08 tsomq34 ihthd33 boobs .avi.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\ddqayq [bangbus] feet nrb42wq .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\4h1e2a346 ihthd33 lady (gina,sonja).avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\tsomq34 hot (!) .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\eq7k2xcxt sperm porn [milf] 8bgkvshe1 .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\ikdyfwhy horse epyxwn legs .avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\ikdyfwhy nude big 6tl9zg0uqa .avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\ nom72kl .zip.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\gzn4ud7e 7nd83wovj hot (!) .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\gay girls (cy4xpd,g6u8n4r).mpeg.exe
  • %WINDIR%\assembly\temp\f1i7cm ddqayq lpcu5ai3 nom72kl 50+ .mpeg.exe
  • %WINDIR%\assembly\tmp\z1qxwcd sperm l9hwcs7vvnphd9 glans gsva2xn (sonja,y8oxsqa).zip.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\4h1e2a346 w6csjja14n1 ihthd33 cock 779mipj (2hbt8wr,g6u8n4r).avi.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\7b6fhxi nude 8ok6yf hot (!) .mpeg.exe
  • %WINDIR%\pla\templates\nom72kl girls feet (rdl1tfkz).mpeg.exe
  • %WINDIR%\security\templates\black horse xxx ihthd33 ash balls .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\horse mzwpstr8n [bangbus] fishy (g6u8n4r).rar.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\beast ihthd33 779mipj .mpg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\horse sgu4m7oc hairy .mpg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\ikdyfwhy 7nd83wovj xxx epyxwn (2hbt8wr).avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\8ok6yf ddqayq sgu4m7oc gsva2xn .avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\asian wep6b08 mnho9y54 ihthd33 (2hbt8wr,liz).zip.exe
  • %WINDIR%\syswow64\config\systemprofile\mnho9y54 l9hwcs7vvnphd9 boots .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\porn [bangbus] feet .zip.exe
  • %WINDIR%\syswow64\fxstmp\ xxx ihthd33 glans balls .avi.exe
  • %WINDIR%\syswow64\ime\shared\porn horse vjq39c1gwy titts .mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\beast lpcu5ai3 ihthd33 (36mho73,karin).mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\tsomq34 ddqayq [milf] (2hbt8wr,haj1oyikd).mpeg.exe
  • %WINDIR%\syswow64\fxstmp\mnho9y54 w6csjja14n1 epyxwn .zip.exe
  • %WINDIR%\syswow64\ime\shared\s2fkave nom72kl big ae2sd7u4xh .mpeg.exe
  • %WINDIR%\temp\viaz50 ddqayq mnho9y54 vjq39c1gwy feet mg9fvb2xk9 .rar.exe
  • %WINDIR%\winsxs\installtemp\tsomq34 mzwpstr8n girls sgoibhh (jade,hyo87il).zip.exe
  • <Current directory>\sqjaed7r1vnw
  • %CommonProgramFiles%\microsoft shared\z9z7rwe horse [bangbus] fishy .mpg.exe
  • %ProgramFiles%\dvd maker\shared\gzn4ud7e nom72kl cum l9hwcs7vvnphd9 .mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\zc8giv9 bd1l5ir [bangbus] cock girly .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\z9z7rwe mnho9y54 mnho9y54 7vepaqjm mg9fvb2xk9 .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\eq7k2xcxt wep6b08 nude bq4kno .avi.exe
  • %ProgramFiles%\microsoft office\templates\upfgetx bd1l5ir h93bklf ihthd33 (karin).rar.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\wep6b08 sgu4m7oc hole nmibe2 (sandy,sonja).mpg.exe
  • %ProgramFiles%\windows journal\templates\0287zh nude [bangbus] (y8oxsqa).avi.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\black xxx ihthd33 ol6p1tua (jenna).avi.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\eq7k2xcxt h93bklf ddqayq [free] mg9fvb2xk9 .avi.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\upfgetx tsomq34 horse [free] .zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\7nd83wovj lpcu5ai3 vjq39c1gwy feet ash (sonja,g6u8n4r).mpg.exe
  • %CommonProgramFiles(x86)%\microsoft shared\f07qtt h93bklf [milf] titts .mpg.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\w6csjja14n1 horse 7vepaqjm .zip.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\gzn4ud7e bd1l5ir epyxwn .mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\jxaglwti big shoes .rar.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\xakmpl cum epyxwn sgoibhh .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\nom72kl beast nom72kl fw58kpr41ob1w .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\0287zh cum ihthd33 hole (jade,jade).avi.exe
  • %ALLUSERSPROFILE%\templates\8r3baiec xakmpl uncut ejn547rbxhd1 (jade).zip.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\ddqayq porn nom72kl .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\f1i7cm xakmpl nom72kl sgu4m7oc .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\z9z7rwe nude bd1l5ir sgu4m7oc sweet .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\8r3baiec lpcu5ai3 l9hwcs7vvnphd9 .mpg.exe
  • %ALLUSERSPROFILE%\templates\viaz50 beast big eigt45 .zip.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\beast nude [bangbus] (g6u8n4r).mpeg.exe
  • C:\users\default\appdata\local\temp\z9z7rwe tsomq34 ddqayq uncut (y8oxsqa).mpg.exe
  • C:\users\default\appdata\local\<INETFILES>\7b6fhxi wep6b08 mnho9y54 nom72kl titts zmc8ujp .zip.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\4h1e2a346 lpcu5ai3 apv53deiq9fw hotel .avi.exe
  • C:\users\default\templates\wpjwijv hot (!) nrb42wq .avi.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\8ok6yf horse [free] .zip.exe
  • %TEMP%\yzw1afy ihthd33 qx2j1b5 .zip.exe
  • %LOCALAPPDATA%\<INETFILES>\horse [milf] feet .zip.exe
  • %LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\zc8giv9 gay nom72kl bq4kno legs young .zip.exe
  • %LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\4h1e2a346 tsomq34 uncut .avi.exe
  • %LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\beast bd1l5ir bq4kno fw58kpr41ob1w (2hbt8wr).mpg.exe
  • %APPDATA%\microsoft\templates\fac71w2 yzw1afy girls .rar.exe
  • %APPDATA%\microsoft\windows\templates\ddqayq nom72kl hole .avi.exe
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\0287zh sperm sgu4m7oc .mpg.exe
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\horse l9hwcs7vvnphd9 glans 6tl9zg0uqa (c4w8hqa,jade).rar.exe
  • %HOMEPATH%\templates\mnho9y54 7vepaqjm .mpeg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\xxx bd1l5ir uncut jxqgtp qq6w54yfhtqrbwcslg .mpg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\wpjwijv yzw1afy 7vepaqjm kfp2yqq nrb42wq .avi.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\fac71w2 bd1l5ir girls feet .mpeg.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\eq7k2xcxt sperm l9hwcs7vvnphd9 hairy (jade,karin).mpg.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\sperm 8ok6yf nom72kl jxqgtp (hyo87il).mpeg.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\horse 8ok6yf epyxwn .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\4h1e2a346 sperm uncut young (jade).avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\h93bklf hot (!) jxqgtp .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\wpjwijv w6csjja14n1 [bangbus] .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\xakmpl tsomq34 7vepaqjm qx2j1b5 (gina).avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\bd1l5ir tsomq34 ihthd33 mg9fvb2xk9 .avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\z1qxwcd gay uncut .avi.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\8r3baiec wep6b08 cum vjq39c1gwy .zip.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\z1qxwcd porn nom72kl [milf] feet (g6u8n4r).mpg.exe
  • %WINDIR%\assembly\temp\jxaglwti ddqayq uncut sgoibhh (sonja).mpg.exe
  • %WINDIR%\assembly\tmp\ikdyfwhy h93bklf tsomq34 vjq39c1gwy b37oavmx289 (sonja,haj1oyikd).avi.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\horse ihthd33 .mpeg.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\h93bklf [bangbus] ash (y8oxsqa,liz).mpg.exe
  • %WINDIR%\pla\templates\h93bklf hot (!) shoes .avi.exe
  • %WINDIR%\security\templates\h93bklf uncut glans nrb42wq .mpg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\porn mzwpstr8n sgu4m7oc ash (haj1oyikd,y8oxsqa).rar.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\wep6b08 hot (!) 6tl9zg0uqa .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\z1qxwcd lpcu5ai3 epyxwn (jenna,2hbt8wr).avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\0287zh xxx tsomq34 uncut ash sweet (cy4xpd,karin).mpeg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\ddqayq [bangbus] .mpeg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\ddqayq hot (!) zmc8ujp .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\black ddqayq uncut (2hbt8wr,gina).mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\xakmpl uncut b37oavmx289 .avi.exe
  • %WINDIR%\syswow64\fxstmp\4h1e2a346 lpcu5ai3 l9hwcs7vvnphd9 legs (jade).mpg.exe
  • %WINDIR%\syswow64\ime\shared\bd1l5ir [bangbus] .zip.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\wep6b08 xxx vjq39c1gwy fishy .rar.exe
  • %WINDIR%\syswow64\fxstmp\4h1e2a346 nom72kl hot (!) ash .mpeg.exe
  • %WINDIR%\syswow64\ime\shared\tsomq34 7nd83wovj uncut (hyo87il,y8oxsqa).rar.exe
  • %WINDIR%\temp\f1i7cm nude wep6b08 7vepaqjm jxqgtp rv0y8n .zip.exe
  • %WINDIR%\winsxs\installtemp\wpjwijv ddqayq xxx 7vepaqjm legs hotel (hyo87il).avi.exe
Miscellaneous
Searches for the following windows
  • ClassName: 'Progman' WindowName: ''
  • ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
  • '%WINDIR%\explorer.exe'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android