Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.KillProc2.27678

Added to the Dr.Web virus database: 2025-07-16

Virus description added:

Technical Information

Malicious functions
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\explorer.exe
  • <SYSTEM32>\taskhost.exe
  • <SYSTEM32>\dwm.exe
the following user processes:
  • iexplore.exe
  • firefox.exe
Modifies file system
Creates the following files
  • %WINDIR%y1s2fctrp3
  • %CommonProgramFiles%\microsoft shared\8r3baiec bd1l5ir horse nom72kl titts gsva2xn .zip.exe
  • %ProgramFiles%\dvd maker\shared\mnho9y54 [bangbus] lzxyhb7k .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\tsomq34 nom72kl feet .zip.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\z9z7rwe 7nd83wovj xxx bq4kno qx2j1b5 (hyo87il,karin).mpeg.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\upfgetx wep6b08 sgu4m7oc .avi.exe
  • %ProgramFiles%\microsoft office\templates\z9z7rwe 8ok6yf lpcu5ai3 7vepaqjm zmc8ujp .avi.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\z9z7rwe nude yzw1afy 7vepaqjm cock gh5b6gd7wrv .mpg.exe
  • %ProgramFiles%\windows journal\templates\yzw1afy apv53deiq9fw latex .zip.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\gay big (2hbt8wr).zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\xxx apv53deiq9fw shoes (sonja,y8oxsqa).mpeg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\gay [bangbus] .rar.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\beast uncut (g6u8n4r).zip.exe
  • %CommonProgramFiles(x86)%\microsoft shared\8r3baiec porn sperm [milf] .zip.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\black 8ok6yf sperm [bangbus] feet 6tl9zg0uqa .mpg.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\beast big hole .zip.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\z9z7rwe h93bklf tsomq34 vjq39c1gwy hole 779mipj (dxocjwba).avi.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\s2fkave w6csjja14n1 nom72kl l9hwcs7vvnphd9 (y8oxsqa).avi.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\8r3baiec wep6b08 mzwpstr8n big .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\tsomq34 bq4kno .mpg.exe
  • %ALLUSERSPROFILE%\templates\s2fkave xakmpl gay uncut lady .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\upfgetx w6csjja14n1 sgu4m7oc boots .rar.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\black horse mnho9y54 big .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\s2fkave 7nd83wovj beast apv53deiq9fw gsva2xn (jenna,liz).mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\xxx uncut cock zmc8ujp (dxocjwba).rar.exe
  • %ALLUSERSPROFILE%\templates\gzn4ud7e nude tsomq34 l9hwcs7vvnphd9 .mpg.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\horse [bangbus] boots .avi.exe
  • C:\users\default\appdata\local\temp\ apv53deiq9fw hole ol6p1tua (liz).zip.exe
  • C:\users\default\appdata\local\<INETFILES>\8r3baiec w6csjja14n1 xxx big ejn547rbxhd1 .mpg.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\black 8ok6yf horse [bangbus] (2hbt8wr).zip.exe
  • C:\users\default\templates\nom72kl hot (!) glans qx2j1b5 (2hbt8wr).mpeg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\f07qtt wep6b08 gay [bangbus] feet zn3tvn .avi.exe
  • %TEMP%\yzw1afy ihthd33 ae2sd7u4xh .mpeg.exe
  • %LOCALAPPDATA%\<INETFILES>\z9z7rwe 7nd83wovj horse l9hwcs7vvnphd9 (c4w8hqa).zip.exe
  • %LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\s2fkave 8ok6yf gay [free] titts .zip.exe
  • %LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\tsomq34 [milf] qx2j1b5 .mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\tsomq34 sgu4m7oc glans .mpeg.exe
  • %APPDATA%\microsoft\templates\8r3baiec porn mzwpstr8n [bangbus] gsva2xn .mpg.exe
  • %APPDATA%\microsoft\windows\templates\yzw1afy ihthd33 40+ .mpg.exe
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\eq7k2xcxt ddqayq nom72kl epyxwn feet 8pfmdyy .rar.exe
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\upfgetx nude horse [milf] hotel .rar.exe
  • %HOMEPATH%\templates\s2fkave horse horse vjq39c1gwy gh5b6gd7wrv .mpg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\black horse beast bq4kno .mpeg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\xxx [free] (y8oxsqa).zip.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\f1i7cm cum lpcu5ai3 nom72kl (jade).rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\z9z7rwe bd1l5ir nom72kl 7vepaqjm 40+ .zip.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\gzn4ud7e xakmpl sperm hot (!) .rar.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\black w6csjja14n1 lpcu5ai3 big 8pfmdyy (dehod0,c4w8hqa).rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\horse sperm ihthd33 (c4w8hqa).mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\8r3baiec nude beast nom72kl .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\mnho9y54 girls feet .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\nom72kl [milf] cock fishy (2hbt8wr).avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\f07qtt w6csjja14n1 horse big 779mipj .rar.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\sperm uncut .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\z9z7rwe h93bklf sperm big cock .mpeg.exe
  • %WINDIR%\assembly\temp\8r3baiec 7nd83wovj tsomq34 vjq39c1gwy (2hbt8wr).zip.exe
  • %WINDIR%\assembly\tmp\gay [free] feet .mpeg.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\ apv53deiq9fw (cy4xpd).avi.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\8r3baiec h93bklf vjq39c1gwy .mpeg.exe
  • %WINDIR%\pla\templates\8r3baiec ddqayq sperm [bangbus] feet fw58kpr41ob1w .avi.exe
  • %WINDIR%\security\templates\tsomq34 epyxwn shoes .mpg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\s2fkave horse beast [free] wifey .mpeg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\beast apv53deiq9fw (jade).rar.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\z9z7rwe cum horse uncut .zip.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\z9z7rwe nude yzw1afy bq4kno titts .avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\ epyxwn feet .avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\upfgetx 7nd83wovj mnho9y54 nom72kl feet ol6p1tua .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\mnho9y54 l9hwcs7vvnphd9 js80j73 .zip.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\s2fkave nude gay l9hwcs7vvnphd9 cock zmc8ujp .zip.exe
  • %WINDIR%\syswow64\fxstmp\z1qxwcd sperm apv53deiq9fw 8pfmdyy (rdl1tfkz,jade).mpg.exe
  • %WINDIR%\syswow64\ime\shared\sperm girls 8pfmdyy .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\upfgetx bd1l5ir mzwpstr8n [bangbus] gh5b6gd7wrv .mpeg.exe
  • %WINDIR%\syswow64\fxstmp\f1i7cm 8ok6yf xxx [bangbus] sweet .mpeg.exe
  • %WINDIR%\syswow64\ime\shared\nom72kl [milf] .mpg.exe
  • %WINDIR%\temp\horse big ash .mpeg.exe
  • %WINDIR%\winsxs\installtemp\z9z7rwe 8ok6yf horse uncut young (rdl1tfkz,liz).mpeg.exe
  • <Current directory>\sqjaed7r1vnw
  • %CommonProgramFiles%\microsoft shared\gzn4ud7e 8ok6yf gay [bangbus] sgoibhh .mpeg.exe
  • %ProgramFiles%\dvd maker\shared\mnho9y54 apv53deiq9fw fw58kpr41ob1w .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\nom72kl hot (!) .mpeg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\upfgetx 8ok6yf nom72kl vjq39c1gwy .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\tsomq34 hot (!) wifey .mpg.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\f07qtt porn beast 7vepaqjm (y8oxsqa).mpeg.exe
  • %ProgramFiles%\windows journal\templates\mzwpstr8n [free] young .zip.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\nom72kl [free] cock .avi.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\s2fkave cum nom72kl epyxwn glans .mpg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\yzw1afy bq4kno feet sweet .mpeg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\beast epyxwn hole .zip.exe
  • %CommonProgramFiles(x86)%\microsoft shared\8r3baiec h93bklf gay bq4kno js80j73 .zip.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\eq7k2xcxt porn gay [free] cock 779mipj (y8oxsqa).mpg.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\fac71w2 h93bklf hot (!) .zip.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\f1i7cm porn xxx vjq39c1gwy boots .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\s2fkave cum mnho9y54 girls (2hbt8wr).rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\eq7k2xcxt horse horse ihthd33 nrb42wq .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\yzw1afy uncut ash .mpg.exe
  • %ALLUSERSPROFILE%\templates\upfgetx horse mzwpstr8n hot (!) (g6u8n4r).avi.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\8r3baiec bd1l5ir lpcu5ai3 hot (!) titts nrb42wq (cy4xpd).avi.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\horse vjq39c1gwy (cy4xpd).mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\xxx [bangbus] .rar.exe
  • %ALLUSERSPROFILE%\templates\mnho9y54 bq4kno 40+ .mpeg.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\beast ihthd33 feet qq6w54yfhtqrbwcslg (dxocjwba).avi.exe
  • C:\users\default\appdata\local\<INETFILES>\s2fkave cum lpcu5ai3 [milf] girly .zip.exe
  • C:\users\default\templates\0287zh mnho9y54 big titts rv0y8n .mpg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\fac71w2 xakmpl beast uncut .rar.exe
  • %TEMP%\f1i7cm porn mnho9y54 [free] cock ejn547rbxhd1 (sarah).avi.exe
  • %LOCALAPPDATA%\<INETFILES>\ uncut glans 40+ .mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\tsomq34 uncut .mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\upfgetx xakmpl mnho9y54 vjq39c1gwy ol6p1tua .mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\yzw1afy apv53deiq9fw .zip.exe
  • %APPDATA%\microsoft\templates\gay sgu4m7oc titts js80j73 (2hbt8wr).mpeg.exe
  • %APPDATA%\microsoft\windows\templates\mzwpstr8n uncut hole young (liz).mpeg.exe
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\black porn bq4kno rv0y8n .zip.exe
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\s2fkave wep6b08 tsomq34 l9hwcs7vvnphd9 hole .mpeg.exe
  • %HOMEPATH%\templates\horse [free] hole (sonja,2hbt8wr).mpg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\yzw1afy [free] glans ol6p1tua (jade).rar.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\s2fkave w6csjja14n1 horse nom72kl eigt45 .avi.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\8r3baiec horse xxx ihthd33 40+ .mpeg.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\z9z7rwe h93bklf yzw1afy [free] titts sweet (jade).mpg.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\8r3baiec 7nd83wovj gay nom72kl lzxyhb7k .mpeg.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\s2fkave wep6b08 mzwpstr8n l9hwcs7vvnphd9 50+ .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\fac71w2 xakmpl ihthd33 hole .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\8r3baiec wep6b08 tsomq34 nom72kl glans b37oavmx289 (y8oxsqa).mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\horse vjq39c1gwy (c4w8hqa).mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\upfgetx w6csjja14n1 nom72kl big titts .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\ big hole ol6p1tua .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\z9z7rwe ddqayq mnho9y54 [free] glans fishy (jade).mpeg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\upfgetx cum mzwpstr8n ihthd33 (2hbt8wr).avi.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\f1i7cm horse tsomq34 hot (!) glans mg9fvb2xk9 .zip.exe
  • %WINDIR%\assembly\temp\f1i7cm h93bklf beast vjq39c1gwy feet sweet .avi.exe
  • %WINDIR%\assembly\tmp\gzn4ud7e bd1l5ir lpcu5ai3 sgu4m7oc ol6p1tua .mpg.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\z9z7rwe ddqayq sperm uncut .mpg.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\z9z7rwe xakmpl 7vepaqjm titts hotel (2hbt8wr).mpeg.exe
  • %WINDIR%\pla\templates\z9z7rwe 8ok6yf sperm girls ejn547rbxhd1 .mpg.exe
  • %WINDIR%\security\templates\beast girls feet .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\nom72kl uncut gsva2xn .mpg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\s2fkave bd1l5ir yzw1afy l9hwcs7vvnphd9 mg9fvb2xk9 .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\8r3baiec horse beast l9hwcs7vvnphd9 fishy .rar.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\f1i7cm nude nom72kl epyxwn .mpg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\tsomq34 [milf] (y8oxsqa).mpg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\mnho9y54 uncut titts qx2j1b5 .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\xxx big cock .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\nom72kl girls .avi.exe
  • %WINDIR%\syswow64\fxstmp\mnho9y54 hot (!) cock gh5b6gd7wrv .zip.exe
  • %WINDIR%\syswow64\ime\shared\xxx bq4kno glans gsva2xn (2hbt8wr).zip.exe
  • %WINDIR%\syswow64\config\systemprofile\8r3baiec ddqayq tsomq34 7vepaqjm rv0y8n (sonja,cy4xpd).rar.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\sperm [bangbus] .rar.exe
  • %WINDIR%\syswow64\fxstmp\yzw1afy vjq39c1gwy sweet .mpeg.exe
  • %WINDIR%\syswow64\ime\shared\s2fkave cum mzwpstr8n sgu4m7oc glans .mpeg.exe
  • %WINDIR%\temp\mzwpstr8n l9hwcs7vvnphd9 50+ (sandy,liz).avi.exe
  • %WINDIR%\winsxs\installtemp\gzn4ud7e xakmpl girls .rar.exe
  • %CommonProgramFiles%\microsoft shared\ big titts lady .mpeg.exe
  • %CommonProgramFiles%\microsoft shared\upfgetx nude horse nom72kl gh5b6gd7wrv .avi.exe
  • %ProgramFiles%\dvd maker\shared\gay vjq39c1gwy .rar.exe
  • %ProgramFiles%\dvd maker\shared\nom72kl 7vepaqjm hole ejn547rbxhd1 .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\gzn4ud7e ddqayq mzwpstr8n [free] cock 6tl9zg0uqa .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\8r3baiec porn gay uncut .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\xxx hot (!) sgoibhh (sandy,c4w8hqa).mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\black ddqayq mnho9y54 big 40+ .zip.exe
  • %ProgramFiles%\microsoft office\templates\s2fkave nude tsomq34 uncut zmc8ujp .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\mzwpstr8n hot (!) 779mipj (sonja,cy4xpd).avi.exe
  • %ProgramFiles%\microsoft office\templates\f07qtt bd1l5ir xxx uncut cock .avi.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\8r3baiec wep6b08 sperm big glans .avi.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\f1i7cm nude beast vjq39c1gwy 40+ .rar.exe
  • %ProgramFiles%\windows journal\templates\gay sgu4m7oc zmc8ujp .mpeg.exe
Miscellaneous
Searches for the following windows
  • ClassName: 'Progman' WindowName: ''
  • ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
  • '%WINDIR%\explorer.exe'

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android