Pour le fonctionnement correct du site, vous devez activer JavaScript dans votre navigateur.
Trojan.KillProc2.28119
Added to the Dr.Web virus database:
2025-07-16
Virus description added:
2025-07-18
Technical Information
Malicious functions
Terminates or attempts to terminate
the following system processes:
%WINDIR%\explorer.exe
<SYSTEM32>\taskhost.exe
<SYSTEM32>\dwm.exe
the following user processes:
Modifies file system
Creates the following files
%WINDIR%y1s2fctrp3
%CommonProgramFiles%\microsoft shared\0287zh ddqayq bd1l5ir epyxwn (jenna).zip.exe
%ProgramFiles%\dvd maker\shared\bd1l5ir tsomq34 nom72kl b37oavmx289 (karin).mpeg.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\horse mnho9y54 bq4kno 40+ .avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\wpjwijv nom72kl gay sgu4m7oc legs .rar.exe
%ProgramFiles%\microsoft office\office14\groove\xml files\space templates\s2fkave porn bq4kno .mpeg.exe
%ProgramFiles%\microsoft office\templates\7nd83wovj yzw1afy [milf] ol6p1tua (sonja,dxocjwba).rar.exe
%ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\ikdyfwhy tsomq34 vjq39c1gwy 8pfmdyy (sonja,sonja).mpeg.exe
%ProgramFiles%\windows journal\templates\8r3baiec w6csjja14n1 epyxwn balls .mpg.exe
%ProgramFiles%\windows sidebar\shared gadgets\horse yzw1afy apv53deiq9fw boobs mg9fvb2xk9 .zip.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\zc8giv9 xakmpl porn [free] ash .rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\sperm lpcu5ai3 [bangbus] ash .zip.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\ikdyfwhy sperm wep6b08 [bangbus] .zip.exe
%CommonProgramFiles(x86)%\microsoft shared\xxx beast big b37oavmx289 (sonja,dxocjwba).mpg.exe
%ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\mnho9y54 tsomq34 sgu4m7oc (dehod0).rar.exe
%ProgramFiles(x86)%\windows sidebar\shared gadgets\s2fkave xxx ddqayq apv53deiq9fw zmc8ujp .rar.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\wpjwijv lpcu5ai3 big nrb42wq .zip.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\sperm sperm l9hwcs7vvnphd9 779mipj .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\fac71w2 mzwpstr8n apv53deiq9fw 6tl9zg0uqa (hyo87il,jenna).mpeg.exe
%ALLUSERSPROFILE%\templates\viaz50 w6csjja14n1 h93bklf apv53deiq9fw .rar.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\7nd83wovj uncut wifey .avi.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\z1qxwcd tsomq34 nom72kl hole .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\porn ihthd33 b37oavmx289 .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\jxaglwti tsomq34 l9hwcs7vvnphd9 legs .zip.exe
%ALLUSERSPROFILE%\templates\nom72kl yzw1afy 7vepaqjm ash .avi.exe
C:\users\default\appdata\local\microsoft\windows\<INETFILES>\gzn4ud7e wep6b08 w6csjja14n1 [bangbus] ol6p1tua .zip.exe
C:\users\default\appdata\local\temp\bd1l5ir horse ihthd33 fw58kpr41ob1w .rar.exe
C:\users\default\appdata\local\<INETFILES>\nom72kl gay epyxwn rv0y8n .zip.exe
C:\users\default\appdata\roaming\microsoft\windows\templates\viaz50 xxx sgu4m7oc .rar.exe
C:\users\default\templates\8r3baiec w6csjja14n1 gay l9hwcs7vvnphd9 legs zn3tvn .zip.exe
%LOCALAPPDATA%\microsoft\windows\<INETFILES>\xakmpl [bangbus] qq6w54yfhtqrbwcslg .mpeg.exe
%TEMP%\tsomq34 uncut sgoibhh .zip.exe
%LOCALAPPDATA%\<INETFILES>\4h1e2a346 lpcu5ai3 [free] hole ejn547rbxhd1 .mpg.exe
%LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\asian horse uncut (liz,gina).rar.exe
%LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\7nd83wovj ihthd33 (sandy).avi.exe
%LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\eq7k2xcxt 7nd83wovj hot (!) lzxyhb7k .mpg.exe
%APPDATA%\microsoft\templates\f1i7cm mzwpstr8n [bangbus] kfp2yqq .rar.exe
%APPDATA%\microsoft\windows\templates\f1i7cm bd1l5ir w6csjja14n1 girls ash .avi.exe
%APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\black horse vjq39c1gwy .avi.exe
%APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\tsomq34 yzw1afy girls glans .mpg.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\jxaglwti mzwpstr8n ddqayq [bangbus] ol6p1tua (2hbt8wr,y8oxsqa).zip.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\viaz50 beast horse apv53deiq9fw .mpg.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\8r3baiec ddqayq uncut kfp2yqq mg9fvb2xk9 .avi.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\wpjwijv big legs 8pfmdyy .rar.exe
%WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\viaz50 bd1l5ir horse l9hwcs7vvnphd9 .avi.exe
%WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\mnho9y54 lpcu5ai3 hot (!) hairy .zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\h93bklf [bangbus] latex (2hbt8wr,karin).avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\horse ddqayq girls wifey (liz,y8oxsqa).zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\z1qxwcd beast sgu4m7oc lzxyhb7k .zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\mnho9y54 bq4kno .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\horse hot (!) boobs 779mipj (liz,jade).rar.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\z9z7rwe mzwpstr8n uncut .mpeg.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\f07qtt 7nd83wovj hot (!) fishy (hyo87il,jenna).mpeg.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\7nd83wovj horse 7vepaqjm .mpg.exe
%WINDIR%\assembly\temp\ddqayq uncut sm .avi.exe
%WINDIR%\assembly\tmp\8ok6yf epyxwn 779mipj (jade).mpg.exe
%WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\s2fkave cum [milf] boobs (dehod0,2hbt8wr).rar.exe
%WINDIR%\pla\templates\s2fkave 8ok6yf [bangbus] cock zn3tvn (dehod0,sonja).mpeg.exe
%WINDIR%\security\templates\zc8giv9 cum uncut hole eigt45 .mpg.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\8r3baiec 8ok6yf nude girls 8pfmdyy (sonja).rar.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\temp\4h1e2a346 sperm xakmpl uncut sweet .rar.exe
%WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\upfgetx cum apv53deiq9fw cock boots .avi.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\4h1e2a346 h93bklf gay [bangbus] boobs (hyo87il,haj1oyikd).mpeg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\temp\0287zh mnho9y54 girls (gina,g6u8n4r).mpg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\cum girls (jenna).zip.exe
%WINDIR%\syswow64\config\systemprofile\tsomq34 porn uncut .mpeg.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\gay sgu4m7oc .mpg.exe
%WINDIR%\syswow64\fxstmp\wpjwijv horse cum 7vepaqjm nmibe2 (liz).mpg.exe
%WINDIR%\syswow64\ime\shared\0287zh ihthd33 jxqgtp .avi.exe
%WINDIR%\syswow64\config\systemprofile\horse nom72kl hot (!) .mpg.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\nom72kl wep6b08 epyxwn (2hbt8wr).avi.exe
%WINDIR%\syswow64\fxstmp\eq7k2xcxt horse sperm hot (!) titts .mpg.exe
%WINDIR%\syswow64\ime\shared\xakmpl big b37oavmx289 .rar.exe
%WINDIR%\temp\8r3baiec ddqayq mzwpstr8n [milf] hole (y8oxsqa,hyo87il).mpeg.exe
%WINDIR%\winsxs\installtemp\yzw1afy nom72kl 7vepaqjm shoes (c4w8hqa,c4w8hqa).mpeg.exe
<Current directory>\sqjaed7r1vnw
%CommonProgramFiles%\microsoft shared\eq7k2xcxt porn beast epyxwn qq6w54yfhtqrbwcslg .mpg.exe
%ProgramFiles%\dvd maker\shared\tsomq34 [milf] 40+ .avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\eq7k2xcxt h93bklf lpcu5ai3 [free] glans boots .mpg.exe
%ProgramFiles%\microsoft office\office14\groove\xml files\space templates\eq7k2xcxt h93bklf vjq39c1gwy hole (sonja,g6u8n4r).mpg.exe
%ProgramFiles%\microsoft office\templates\8r3baiec h93bklf sperm sgu4m7oc (y8oxsqa).avi.exe
%ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\z9z7rwe ddqayq sperm hot (!) lady .mpg.exe
%ProgramFiles%\windows journal\templates\gzn4ud7e bd1l5ir nom72kl [milf] ol6p1tua .zip.exe
%ProgramFiles%\windows sidebar\shared gadgets\black h93bklf lpcu5ai3 hot (!) .zip.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\ vjq39c1gwy .zip.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\gay epyxwn .mpg.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\8r3baiec cum beast uncut ae2sd7u4xh (jenna,2hbt8wr).zip.exe
%CommonProgramFiles(x86)%\microsoft shared\8r3baiec porn gay apv53deiq9fw cock ash .rar.exe
%ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\xxx bq4kno js80j73 .mpg.exe
%ProgramFiles(x86)%\windows sidebar\shared gadgets\horse sgu4m7oc zn3tvn (gina,y8oxsqa).zip.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\upfgetx bd1l5ir horse ihthd33 titts ol6p1tua (cy4xpd).mpeg.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\beast [milf] feet mg9fvb2xk9 .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\beast [free] hole (rdl1tfkz,2hbt8wr).rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\ uncut cock .rar.exe
%ALLUSERSPROFILE%\templates\sperm bq4kno mg9fvb2xk9 .avi.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\horse nom72kl sgoibhh .rar.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\fac71w2 h93bklf epyxwn gsva2xn .mpg.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\lpcu5ai3 7vepaqjm hole (sonja,c4w8hqa).mpeg.exe
%ALLUSERSPROFILE%\templates\f07qtt nude mnho9y54 nom72kl .zip.exe
C:\users\default\appdata\local\microsoft\windows\<INETFILES>\tsomq34 sgu4m7oc .zip.exe
C:\users\default\appdata\local\<INETFILES>\s2fkave cum [free] glans .avi.exe
C:\users\default\appdata\roaming\microsoft\windows\templates\8r3baiec cum mzwpstr8n [bangbus] .mpeg.exe
C:\users\default\templates\f1i7cm 7nd83wovj yzw1afy hot (!) .rar.exe
%LOCALAPPDATA%\microsoft\windows\<INETFILES>\sperm nom72kl cock .mpeg.exe
%TEMP%\f07qtt cum tsomq34 apv53deiq9fw sgoibhh .zip.exe
%LOCALAPPDATA%\<INETFILES>\fac71w2 xakmpl xxx [bangbus] (cy4xpd).rar.exe
%LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\nom72kl nom72kl nmibe2 .rar.exe
%LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\horse nom72kl girly .mpg.exe
%LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\eq7k2xcxt ddqayq [bangbus] glans .rar.exe
%APPDATA%\microsoft\templates\xxx l9hwcs7vvnphd9 feet qq6w54yfhtqrbwcslg .avi.exe
%APPDATA%\microsoft\windows\templates\tsomq34 apv53deiq9fw ejn547rbxhd1 .avi.exe
%APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\gay hot (!) .avi.exe
%APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\mzwpstr8n epyxwn feet hairy (cy4xpd).mpg.exe
%HOMEPATH%\templates\sperm ihthd33 glans .zip.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\sperm [bangbus] hole wifey .avi.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\fac71w2 bd1l5ir gay apv53deiq9fw girly .rar.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\f07qtt nude mzwpstr8n vjq39c1gwy .rar.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\z9z7rwe xakmpl lpcu5ai3 nom72kl glans 8bgkvshe1 .rar.exe
%WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\z9z7rwe porn mzwpstr8n big feet girly .mpeg.exe
%WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\ [bangbus] (g6u8n4r).mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\gzn4ud7e cum big titts .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\upfgetx nude sperm l9hwcs7vvnphd9 (liz).avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\upfgetx h93bklf ihthd33 feet .zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\lpcu5ai3 ihthd33 sgoibhh .zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\eq7k2xcxt ddqayq yzw1afy big (y8oxsqa).mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\eq7k2xcxt horse nom72kl sgu4m7oc feet .zip.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\gzn4ud7e bd1l5ir uncut titts boots (g6u8n4r).rar.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\gzn4ud7e ddqayq horse uncut rv0y8n .rar.exe
%WINDIR%\assembly\temp\s2fkave cum mnho9y54 uncut wifey .avi.exe
%WINDIR%\assembly\tmp\f07qtt porn lpcu5ai3 big hole .rar.exe
%WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\gzn4ud7e xakmpl lpcu5ai3 l9hwcs7vvnphd9 8pfmdyy (36mho73,dxocjwba).zip.exe
%WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\gzn4ud7e h93bklf tsomq34 uncut js80j73 .mpg.exe
%WINDIR%\pla\templates\xxx bq4kno glans mg9fvb2xk9 .mpeg.exe
%WINDIR%\security\templates\s2fkave 7nd83wovj tsomq34 girls hole (haj1oyikd,c4w8hqa).mpeg.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\s2fkave cum [bangbus] .zip.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\temp\f1i7cm nude beast 7vepaqjm mg9fvb2xk9 .mpeg.exe
%WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\xxx big fw58kpr41ob1w .mpeg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\gzn4ud7e w6csjja14n1 mnho9y54 [milf] b37oavmx289 .rar.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\temp\yzw1afy uncut titts (dehod0,liz).zip.exe
%WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\upfgetx wep6b08 yzw1afy ihthd33 cock (gina,2hbt8wr).avi.exe
%WINDIR%\syswow64\config\systemprofile\eq7k2xcxt ddqayq lpcu5ai3 apv53deiq9fw titts fw58kpr41ob1w .avi.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\lpcu5ai3 ihthd33 hole (sandy,c4w8hqa).zip.exe
%WINDIR%\syswow64\fxstmp\ddqayq mzwpstr8n hot (!) shoes (sonja,sarah).avi.exe
%WINDIR%\syswow64\ime\shared\lpcu5ai3 nom72kl titts .mpeg.exe
%WINDIR%\syswow64\config\systemprofile\black xakmpl gay [milf] feet sm .zip.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\s2fkave w6csjja14n1 yzw1afy apv53deiq9fw glans (36mho73,2hbt8wr).zip.exe
%WINDIR%\syswow64\fxstmp\s2fkave 7nd83wovj gay epyxwn nrb42wq .avi.exe
%WINDIR%\syswow64\ime\shared\f1i7cm porn lpcu5ai3 nom72kl cock .rar.exe
%WINDIR%\temp\eq7k2xcxt horse sperm uncut (karin).mpeg.exe
%WINDIR%\winsxs\installtemp\gzn4ud7e bd1l5ir horse [free] feet ash .zip.exe
Miscellaneous
Searches for the following windows
ClassName: 'Progman' WindowName: ''
ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
Recommandations pour le traitement
Windows
macOS
Linux
Android
Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space .
Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.
Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android . Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
Débranchez votre appareil et rebranchez-le.
En savoir plus sur Dr.Web pour Android
Téléchargez Dr.Web pour Android
Gratuit pour 3 mois
Tous les composants de protection
Renouvellement de la démo via AppGallery/Google Pay
Nous utilisons des cookies sur notre site web à des fins uniques d’analyse de la fréquentation et de récolte de données statistiques. En naviguant sur notre site, vous pouvez accepter ou refuser l’utilisation de ces fichiers cookies.
En savoir plus : Politique de confidentialité
Accepter
Refuser