Pour le fonctionnement correct du site, vous devez activer JavaScript dans votre navigateur.
Trojan.KillProc2.25485
Added to the Dr.Web virus database:
2025-07-10
Virus description added:
2025-07-11
Technical Information
Malicious functions
Terminates or attempts to terminate
the following system processes:
%WINDIR%\explorer.exe
<SYSTEM32>\taskhost.exe
<SYSTEM32>\dwm.exe
the following user processes:
Modifies file system
Creates the following files
%WINDIR%y1s2fctrp3
%CommonProgramFiles%\microsoft shared\asian horse epyxwn 40+ (gina).mpeg.exe
%ProgramFiles%\dvd maker\shared\xxx vjq39c1gwy (g6u8n4r,36mho73).mpg.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\asian h93bklf sgu4m7oc latex .avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\8r3baiec bd1l5ir beast bq4kno .mpg.exe
%ProgramFiles%\microsoft office\office14\groove\xml files\space templates\gay xxx girls boobs sweet .rar.exe
%ProgramFiles%\microsoft office\templates\jxaglwti 8ok6yf lpcu5ai3 uncut .zip.exe
%ProgramFiles%\windows journal\templates\gzn4ud7e porn gay nom72kl .mpeg.exe
%ProgramFiles%\windows sidebar\shared gadgets\z9z7rwe ddqayq 7vepaqjm .rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\viaz50 8ok6yf apv53deiq9fw girly (dxocjwba).rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\7nd83wovj vjq39c1gwy eigt45 (sonja).mpeg.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\wep6b08 uncut .rar.exe
%CommonProgramFiles(x86)%\microsoft shared\asian nom72kl yzw1afy sgu4m7oc gsva2xn (hyo87il).mpeg.exe
%ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\yzw1afy [milf] .rar.exe
%ProgramFiles(x86)%\windows sidebar\shared gadgets\horse nude vjq39c1gwy fw58kpr41ob1w .avi.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\sperm sgu4m7oc ash (sonja,sonja).zip.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\xakmpl nom72kl ejn547rbxhd1 (haj1oyikd,2hbt8wr).avi.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mzwpstr8n cum hot (!) .mpg.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\viaz50 mzwpstr8n girls (jade).zip.exe
%ALLUSERSPROFILE%\templates\z9z7rwe nom72kl ihthd33 nmibe2 (karin).avi.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\bd1l5ir ihthd33 sm .zip.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\black lpcu5ai3 horse hot (!) gh5b6gd7wrv (sonja).mpeg.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mnho9y54 [free] 8bgkvshe1 (jade,rdl1tfkz).mpg.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\ikdyfwhy horse bd1l5ir epyxwn cock mg9fvb2xk9 .mpg.exe
%ALLUSERSPROFILE%\templates\beast sgu4m7oc 8bgkvshe1 .mpg.exe
C:\users\default\appdata\local\microsoft\windows\<INETFILES>\ikdyfwhy 8ok6yf uncut (jade,dehod0).rar.exe
C:\users\default\appdata\local\temp\mnho9y54 xakmpl nom72kl nmibe2 (sonja).mpg.exe
C:\users\default\appdata\local\<INETFILES>\porn l9hwcs7vvnphd9 lady .avi.exe
C:\users\default\appdata\roaming\microsoft\windows\templates\7b6fhxi nude xakmpl uncut glans .rar.exe
C:\users\default\templates\lpcu5ai3 7nd83wovj sgu4m7oc .mpeg.exe
%LOCALAPPDATA%\microsoft\windows\<INETFILES>\7b6fhxi xakmpl [free] jxqgtp .rar.exe
%TEMP%\w6csjja14n1 lpcu5ai3 apv53deiq9fw hole .mpg.exe
%LOCALAPPDATA%\<INETFILES>\bd1l5ir apv53deiq9fw kfp2yqq 40+ (y8oxsqa,jenna).rar.exe
%LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\porn [bangbus] boots (hyo87il,hyo87il).mpeg.exe
%LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\nom72kl mzwpstr8n [milf] (haj1oyikd,gina).rar.exe
%LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\wpjwijv bd1l5ir sgu4m7oc .zip.exe
%APPDATA%\microsoft\templates\eq7k2xcxt xakmpl sgu4m7oc boots .avi.exe
%APPDATA%\microsoft\windows\templates\f1i7cm nom72kl apv53deiq9fw fw58kpr41ob1w .zip.exe
%APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\viaz50 8ok6yf [bangbus] .avi.exe
%HOMEPATH%\templates\z9z7rwe sperm [bangbus] feet (c4w8hqa,2hbt8wr).rar.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\nom72kl cum 7vepaqjm kfp2yqq eigt45 (sarah,c4w8hqa).mpg.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\eq7k2xcxt gay apv53deiq9fw glans boots .avi.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\jxaglwti porn 8ok6yf big hole (rdl1tfkz).mpg.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\black lpcu5ai3 wep6b08 [milf] girly .rar.exe
%WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\w6csjja14n1 mnho9y54 nom72kl lzxyhb7k .mpg.exe
%WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\asian tsomq34 sgu4m7oc gsva2xn .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\w6csjja14n1 girls 50+ .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\beast apv53deiq9fw feet gsva2xn .mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\mnho9y54 girls boobs .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\zc8giv9 horse nom72kl hairy (2hbt8wr).zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\upfgetx xakmpl 7vepaqjm feet fishy (dxocjwba).avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\8ok6yf nude sgu4m7oc kfp2yqq 6tl9zg0uqa .zip.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\sperm sgu4m7oc balls .mpg.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\nom72kl hot (!) fw58kpr41ob1w .mpeg.exe
%WINDIR%\assembly\temp\mnho9y54 beast epyxwn zn3tvn .mpg.exe
%WINDIR%\assembly\tmp\asian lpcu5ai3 7vepaqjm mg9fvb2xk9 .avi.exe
%WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\7b6fhxi nom72kl beast 7vepaqjm (y8oxsqa).zip.exe
%WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\eq7k2xcxt horse [milf] ash .mpeg.exe
%WINDIR%\pla\templates\ikdyfwhy xxx beast uncut hole hairy .zip.exe
%WINDIR%\security\templates\ikdyfwhy tsomq34 7nd83wovj nom72kl titts (dxocjwba).avi.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\asian yzw1afy ihthd33 rv0y8n .mpeg.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\temp\f1i7cm lpcu5ai3 [bangbus] titts 40+ .zip.exe
%WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\asian nom72kl horse girls titts gsva2xn (rdl1tfkz).zip.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\7b6fhxi mnho9y54 bq4kno .mpeg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\temp\cum bq4kno kfp2yqq gh5b6gd7wrv .avi.exe
%WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\h93bklf xakmpl uncut 40+ .avi.exe
%WINDIR%\syswow64\config\systemprofile\4h1e2a346 beast [free] (hyo87il,sonja).mpeg.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\beast hot (!) .zip.exe
%WINDIR%\syswow64\fxstmp\viaz50 cum hot (!) .rar.exe
%WINDIR%\syswow64\ime\shared\s2fkave mnho9y54 [milf] 50+ .mpg.exe
%WINDIR%\syswow64\config\systemprofile\f1i7cm 8ok6yf beast nom72kl .zip.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\nom72kl hot (!) sm (y8oxsqa).mpeg.exe
%WINDIR%\syswow64\fxstmp\gzn4ud7e bd1l5ir yzw1afy ihthd33 cock .mpeg.exe
%WINDIR%\syswow64\ime\shared\8r3baiec lpcu5ai3 ddqayq hot (!) glans .zip.exe
%WINDIR%\temp\lpcu5ai3 hot (!) zn3tvn .rar.exe
%WINDIR%\winsxs\installtemp\s2fkave xakmpl lpcu5ai3 l9hwcs7vvnphd9 779mipj (jade).mpeg.exe
<Current directory>\sqjaed7r1vnw
%CommonProgramFiles%\microsoft shared\8r3baiec xakmpl mnho9y54 uncut shoes .mpg.exe
%ProgramFiles%\dvd maker\shared\f1i7cm xakmpl xxx bq4kno fishy (sonja,liz).avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\f1i7cm 7nd83wovj nom72kl vjq39c1gwy (jade).avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\z9z7rwe 7nd83wovj tsomq34 epyxwn (cy4xpd).zip.exe
%ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\xxx girls boots .mpg.exe
%ProgramFiles%\windows journal\templates\horse [bangbus] .avi.exe
%ProgramFiles%\windows sidebar\shared gadgets\8r3baiec horse beast apv53deiq9fw feet lzxyhb7k (cy4xpd).rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\xxx l9hwcs7vvnphd9 cock 8bgkvshe1 (g6u8n4r).avi.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\f1i7cm horse yzw1afy l9hwcs7vvnphd9 (c4w8hqa).zip.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\sperm l9hwcs7vvnphd9 feet b37oavmx289 .zip.exe
%CommonProgramFiles(x86)%\microsoft shared\sperm [bangbus] hole .rar.exe
%ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\black 8ok6yf horse girls (jade).avi.exe
%ProgramFiles(x86)%\windows sidebar\shared gadgets\f07qtt bd1l5ir sgu4m7oc .zip.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\sperm [milf] hole js80j73 .zip.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\8r3baiec 8ok6yf gay ihthd33 lady .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mnho9y54 uncut feet 8pfmdyy (dxocjwba).rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\eq7k2xcxt 8ok6yf yzw1afy nom72kl nrb42wq (jenna,dxocjwba).avi.exe
%ALLUSERSPROFILE%\templates\fac71w2 8ok6yf tsomq34 hot (!) hole .mpg.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\mzwpstr8n 7vepaqjm glans js80j73 (liz).rar.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\mzwpstr8n vjq39c1gwy glans .zip.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\xxx 7vepaqjm hole .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\beast nom72kl titts 8pfmdyy .avi.exe
C:\users\default\appdata\local\microsoft\windows\<INETFILES>\upfgetx h93bklf mzwpstr8n [milf] feet .rar.exe
C:\users\default\appdata\local\temp\gzn4ud7e 7nd83wovj horse ihthd33 .mpeg.exe
C:\users\default\appdata\local\<INETFILES>\upfgetx horse yzw1afy bq4kno feet (haj1oyikd,y8oxsqa).mpeg.exe
C:\users\default\appdata\roaming\microsoft\windows\templates\upfgetx 8ok6yf xxx uncut titts .zip.exe
C:\users\default\templates\f1i7cm nude sperm ihthd33 hole ol6p1tua .rar.exe
%LOCALAPPDATA%\microsoft\windows\<INETFILES>\f1i7cm horse yzw1afy [bangbus] hairy .zip.exe
%TEMP%\xxx 7vepaqjm (y8oxsqa).mpeg.exe
%LOCALAPPDATA%\<INETFILES>\horse [free] lzxyhb7k .mpg.exe
%LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\gzn4ud7e cum gay ihthd33 feet .avi.exe
%LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\8r3baiec w6csjja14n1 nom72kl big glans lady .mpeg.exe
%LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\xxx hot (!) cock 8pfmdyy (2hbt8wr).rar.exe
%APPDATA%\microsoft\templates\f07qtt ddqayq gay big (g6u8n4r).mpg.exe
%APPDATA%\microsoft\windows\templates\gay ihthd33 young (36mho73,liz).avi.exe
%APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\gay ihthd33 cock 40+ .avi.exe
%APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\yzw1afy vjq39c1gwy cock wifey (sarah).rar.exe
%HOMEPATH%\templates\f1i7cm horse mnho9y54 ihthd33 shoes .mpeg.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\gzn4ud7e 7nd83wovj [bangbus] lady .avi.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\f1i7cm bd1l5ir mnho9y54 nom72kl (jade).zip.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\upfgetx porn gay nom72kl feet .mpeg.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\tsomq34 apv53deiq9fw 8pfmdyy (sonja,jade).zip.exe
%WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\fac71w2 nude horse uncut latex .zip.exe
%WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\fac71w2 h93bklf yzw1afy apv53deiq9fw latex .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\upfgetx bd1l5ir sgu4m7oc (2hbt8wr).zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\xxx vjq39c1gwy feet hairy .mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\horse big glans .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\horse girls titts .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\f07qtt horse 7vepaqjm girly .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\sperm apv53deiq9fw 40+ .rar.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\gay sgu4m7oc nmibe2 .zip.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\gzn4ud7e bd1l5ir xxx hot (!) (karin).mpeg.exe
%WINDIR%\assembly\temp\gzn4ud7e 8ok6yf xxx [bangbus] hole 8bgkvshe1 (2hbt8wr).avi.exe
%WINDIR%\assembly\tmp\8r3baiec w6csjja14n1 nom72kl epyxwn titts sm .mpeg.exe
%WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\z9z7rwe xakmpl nom72kl ihthd33 (liz).rar.exe
%WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\fac71w2 nude gay epyxwn (dxocjwba).avi.exe
%WINDIR%\pla\templates\8r3baiec xakmpl horse [bangbus] (jade).mpg.exe
%WINDIR%\security\templates\gzn4ud7e ddqayq beast bq4kno .rar.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\black horse mzwpstr8n 7vepaqjm qq6w54yfhtqrbwcslg .mpeg.exe
%WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\asian mzwpstr8n big .rar.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\beast big ash .mpg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\temp\xxx [bangbus] shoes .avi.exe
%WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\ hot (!) titts .rar.exe
%WINDIR%\syswow64\config\systemprofile\gzn4ud7e w6csjja14n1 lpcu5ai3 ihthd33 .zip.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\black 8ok6yf mzwpstr8n uncut feet .avi.exe
%WINDIR%\syswow64\fxstmp\xakmpl mzwpstr8n 7vepaqjm cock 50+ .mpg.exe
%WINDIR%\syswow64\ime\shared\horse sgu4m7oc sgoibhh .rar.exe
%WINDIR%\syswow64\config\systemprofile\fac71w2 8ok6yf [milf] (dxocjwba).avi.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\fac71w2 nude xxx big (c4w8hqa).zip.exe
%WINDIR%\syswow64\fxstmp\yzw1afy ihthd33 .mpeg.exe
%WINDIR%\syswow64\ime\shared\8r3baiec ddqayq gay [bangbus] cock boots (sarah).mpeg.exe
%WINDIR%\temp\mzwpstr8n uncut .avi.exe
Miscellaneous
Searches for the following windows
ClassName: 'Progman' WindowName: ''
ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
Recommandations pour le traitement
Windows
macOS
Linux
Android
Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space .
Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.
Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android . Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
Débranchez votre appareil et rebranchez-le.
En savoir plus sur Dr.Web pour Android
Téléchargez Dr.Web pour Android
Gratuit pour 3 mois
Tous les composants de protection
Renouvellement de la démo via AppGallery/Google Pay
Nous utilisons des cookies sur notre site web à des fins uniques d’analyse de la fréquentation et de récolte de données statistiques. En naviguant sur notre site, vous pouvez accepter ou refuser l’utilisation de ces fichiers cookies.
En savoir plus : Politique de confidentialité
Accepter
Refuser