Pour le fonctionnement correct du site, vous devez activer JavaScript dans votre navigateur.
Trojan.Siggen33.58834
Added to the Dr.Web virus database:
2026-08-29
Virus description added:
2026-08-30
Technical Information
To ensure autorun and distribution
Modifies the following registry keys
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_31a3ca.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_a6c3f1.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_33a722.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_6f8c60.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_b0539f.exe"'
Creates or modifies the following files
<SYSTEM32>\tasks\5cd3252b3fe5b98309
%APPDATA%\microsoft\windows\start menu\programs\startup\5cd3252b3fe5b98309.lnk
Malicious functions
Patches code
in AMSI dll
ouugg.exe process, Amsi.dll module
msedge.exe process, Amsi.dll module
server.exe process, Amsi.dll module
msedge_5303139015514ef3a0de5c0a65419287.exe process, Amsi.dll module
msedge_9bc52c25a4794617a596d5add5d89960.exe process, Amsi.dll module
msedge_6438f4f7353e437d8253a2201f504154.exe process, Amsi.dll module
msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe process, Amsi.dll module
msedge_77b4aab92dd84e0697ea512fe440b416.exe process, Amsi.dll module
msedge_63371e751f7d404c83389a9bfcbfe648.exe process, Amsi.dll module
msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe process, Amsi.dll module
msedge_ca4184e4b46246e387fde527181943c8.exe process, Amsi.dll module
msedge_79d7ec298b494368be8752d6beb43f32.exe process, Amsi.dll module
server_31a3ca.exe process, Amsi.dll module
server_a6c3f1.exe process, Amsi.dll module
msedge_1c41a166634745f4803be93a4149b4a6.exe process, Amsi.dll module
msedge_d7580d40c0b64f558f95a39d5681ad72.exe process, Amsi.dll module
msedge_b65f05dff6de4f1395e77f2507b24805.exe process, Amsi.dll module
server_33a722.exe process, Amsi.dll module
msedge_c38729d762c44ef8bd1231b036b8a55b.exe process, Amsi.dll module
server_6f8c60.exe process, Amsi.dll module
msedge_7a65bac193d04b1182d5e05f79d98445.exe process, Amsi.dll module
msedge_e8798c10777a4763ab3d8a0280483bf6.exe process, Amsi.dll module
msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe process, Amsi.dll module
msedge_9e1697c9b03844129bd7947a26ac45f8.exe process, Amsi.dll module
server_b0539f.exe process, Amsi.dll module
msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe process, Amsi.dll module
msedge_77c1271028734b709e2d4b91c06f6e7b.exe process, Amsi.dll module
msedge_cc1c81f91d3d4e2eb43f6d802ea21463.exe process, Amsi.dll module
msedge_66ee14d019ab4e9ba18a7e64980f5188.exe process, Amsi.dll module
msedge_73229473f4bd42da9a99097177d4f10e.exe process, Amsi.dll module
server_91c6a0.exe process, Amsi.dll module
server_c2c7d8.exe process, Amsi.dll module
server_590971.exe process, Amsi.dll module
server_e2fd14.exe process, Amsi.dll module
server_0ca7e2.exe process, Amsi.dll module
server_5dcc28.exe process, Amsi.dll module
server_79ef40.exe process, Amsi.dll module
in NTDLL dll
ouugg.exe process, ntdll.dll module
msedge.exe process, ntdll.dll module
server.exe process, ntdll.dll module
msedge_5303139015514ef3a0de5c0a65419287.exe process, ntdll.dll module
msedge_9bc52c25a4794617a596d5add5d89960.exe process, ntdll.dll module
msedge_6438f4f7353e437d8253a2201f504154.exe process, ntdll.dll module
msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe process, ntdll.dll module
msedge_77b4aab92dd84e0697ea512fe440b416.exe process, ntdll.dll module
msedge_63371e751f7d404c83389a9bfcbfe648.exe process, ntdll.dll module
msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe process, ntdll.dll module
msedge_ca4184e4b46246e387fde527181943c8.exe process, ntdll.dll module
msedge_79d7ec298b494368be8752d6beb43f32.exe process, ntdll.dll module
server_31a3ca.exe process, ntdll.dll module
server_a6c3f1.exe process, ntdll.dll module
msedge_1c41a166634745f4803be93a4149b4a6.exe process, ntdll.dll module
msedge_d7580d40c0b64f558f95a39d5681ad72.exe process, ntdll.dll module
msedge_b65f05dff6de4f1395e77f2507b24805.exe process, ntdll.dll module
server_33a722.exe process, ntdll.dll module
msedge_c38729d762c44ef8bd1231b036b8a55b.exe process, ntdll.dll module
server_6f8c60.exe process, ntdll.dll module
msedge_7a65bac193d04b1182d5e05f79d98445.exe process, ntdll.dll module
msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe process, ntdll.dll module
msedge_e8798c10777a4763ab3d8a0280483bf6.exe process, ntdll.dll module
msedge_9e1697c9b03844129bd7947a26ac45f8.exe process, ntdll.dll module
server_b0539f.exe process, ntdll.dll module
msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe process, ntdll.dll module
msedge_77c1271028734b709e2d4b91c06f6e7b.exe process, ntdll.dll module
msedge_cc1c81f91d3d4e2eb43f6d802ea21463.exe process, ntdll.dll module
msedge_66ee14d019ab4e9ba18a7e64980f5188.exe process, ntdll.dll module
msedge_73229473f4bd42da9a99097177d4f10e.exe process, ntdll.dll module
server_91c6a0.exe process, ntdll.dll module
server_e2fd14.exe process, ntdll.dll module
server_c2c7d8.exe process, ntdll.dll module
server_590971.exe process, ntdll.dll module
server_0ca7e2.exe process, ntdll.dll module
server_5dcc28.exe process, ntdll.dll module
server_79ef40.exe process, ntdll.dll module
Modifies file system
Creates the following files
%LOCALAPPDATA%\microsoft\edge\application\msedge.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
%TEMP%\server.exe
%TEMP%\msedge_5303139015514ef3a0de5c0a65419287.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server.exe.log
%TEMP%\msedge_9bc52c25a4794617a596d5add5d89960.exe
%TEMP%\msedge_6438f4f7353e437d8253a2201f504154.exe
%TEMP%\msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe
%TEMP%\msedge_77b4aab92dd84e0697ea512fe440b416.exe
%TEMP%\msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe
%TEMP%\msedge_63371e751f7d404c83389a9bfcbfe648.exe
%TEMP%\msedge_ca4184e4b46246e387fde527181943c8.exe
%TEMP%\msedge_79d7ec298b494368be8752d6beb43f32.exe
%TEMP%\server_31a3ca.exe
%TEMP%\server_a6c3f1.exe
%TEMP%\msedge_d7580d40c0b64f558f95a39d5681ad72.exe
%TEMP%\msedge_1c41a166634745f4803be93a4149b4a6.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_31a3ca.exe.log
%TEMP%\msedge_b65f05dff6de4f1395e77f2507b24805.exe
%TEMP%\msedge_c38729d762c44ef8bd1231b036b8a55b.exe
%TEMP%\server_33a722.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_a6c3f1.exe.log
%TEMP%\5cd3252b\vault.dat
%TEMP%\server_6f8c60.exe
%TEMP%\msedge_7a65bac193d04b1182d5e05f79d98445.exe
%TEMP%\msedge_e8798c10777a4763ab3d8a0280483bf6.exe
%TEMP%\msedge_9e1697c9b03844129bd7947a26ac45f8.exe
%TEMP%\msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_33a722.exe.log
%TEMP%\server_b0539f.exe
%TEMP%\msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_6f8c60.exe.log
Sets the 'hidden' attribute to the following files
%LOCALAPPDATA%\microsoft\edge\application\msedge.exe
%TEMP%\server.exe
%APPDATA%\microsoft\windows\start menu\programs\startup\5cd3252b3fe5b98309.lnk
%TEMP%\server_31a3ca.exe
%TEMP%\server_a6c3f1.exe
%TEMP%\server_33a722.exe
%TEMP%\server_6f8c60.exe
%TEMP%\server_b0539f.exe
Deletes following files that it created itself
%LOCALAPPDATA%\microsoft\edge\application\msedge.exe
%TEMP%\server.exe
Substitutes the following files
Miscellaneous
Creates and executes the following
'%LOCALAPPDATA%\microsoft\edge\application\msedge.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server.exe' --edge-sub
'%TEMP%\server.exe'
'%TEMP%\msedge_5303139015514ef3a0de5c0a65419287.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_9bc52c25a4794617a596d5add5d89960.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_6438f4f7353e437d8253a2201f504154.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_77b4aab92dd84e0697ea512fe440b416.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_63371e751f7d404c83389a9bfcbfe648.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_ca4184e4b46246e387fde527181943c8.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_79d7ec298b494368be8752d6beb43f32.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_31a3ca.exe' --edge-sub
'%TEMP%\server_a6c3f1.exe' --edge-sub
'%TEMP%\server_31a3ca.exe'
'%TEMP%\msedge_d7580d40c0b64f558f95a39d5681ad72.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_1c41a166634745f4803be93a4149b4a6.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_a6c3f1.exe'
'%TEMP%\msedge_b65f05dff6de4f1395e77f2507b24805.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_c38729d762c44ef8bd1231b036b8a55b.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_33a722.exe' --edge-sub
'%TEMP%\server_6f8c60.exe' --edge-sub
'%TEMP%\server_33a722.exe'
'%TEMP%\msedge_7a65bac193d04b1182d5e05f79d98445.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_9e1697c9b03844129bd7947a26ac45f8.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_e8798c10777a4763ab3d8a0280483bf6.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_6f8c60.exe'
'%TEMP%\server_b0539f.exe' --edge-sub
'%TEMP%\msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_b0539f.exe'
Executes the following
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server.exe"; try{ $fObj=Set-WmiInstance -Namespace root\subscript...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_31a3ca.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_31a3ca.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_a6c3f1.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_a6c3f1.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_33a722.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_33a722.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_6f8c60.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_6f8c60.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_b0539f.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_b0539f.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_91c6a0.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_c2c7d8.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_590971.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_e2fd14.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_91c6a0.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_590971.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_c2c7d8.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_e2fd14.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_5dcc28.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_0ca7e2.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_79ef40.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_0ca7e2.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_5dcc28.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_79ef40.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
Recommandations pour le traitement
Windows
macOS
Linux
Android
Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space .
Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.
Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android . Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
Débranchez votre appareil et rebranchez-le.
En savoir plus sur Dr.Web pour Android
Téléchargez Dr.Web pour Android
Gratuit pour 3 mois
Tous les composants de protection
Renouvellement de la démo via AppGallery/Google Pay
Nous utilisons des cookies sur notre site web à des fins uniques d’analyse de la fréquentation et de récolte de données statistiques. En naviguant sur notre site, vous pouvez accepter ou refuser l’utilisation de ces fichiers cookies.
En savoir plus : Politique de confidentialité
Accepter
Refuser