Para el funcionamiento correcto del sitio web, debe activar el soporte de JavaScript en su navegador.
Trojan.KillProc2.25485
Added to the Dr.Web virus database:
2025-07-10
Virus description added:
2025-07-11
Technical Information
Malicious functions
Terminates or attempts to terminate
the following system processes:
%WINDIR%\explorer.exe
<SYSTEM32>\taskhost.exe
<SYSTEM32>\dwm.exe
the following user processes:
Modifies file system
Creates the following files
%WINDIR%y1s2fctrp3
%CommonProgramFiles%\microsoft shared\asian horse epyxwn 40+ (gina).mpeg.exe
%ProgramFiles%\dvd maker\shared\xxx vjq39c1gwy (g6u8n4r,36mho73).mpg.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\asian h93bklf sgu4m7oc latex .avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\8r3baiec bd1l5ir beast bq4kno .mpg.exe
%ProgramFiles%\microsoft office\office14\groove\xml files\space templates\gay xxx girls boobs sweet .rar.exe
%ProgramFiles%\microsoft office\templates\jxaglwti 8ok6yf lpcu5ai3 uncut .zip.exe
%ProgramFiles%\windows journal\templates\gzn4ud7e porn gay nom72kl .mpeg.exe
%ProgramFiles%\windows sidebar\shared gadgets\z9z7rwe ddqayq 7vepaqjm .rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\viaz50 8ok6yf apv53deiq9fw girly (dxocjwba).rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\7nd83wovj vjq39c1gwy eigt45 (sonja).mpeg.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\wep6b08 uncut .rar.exe
%CommonProgramFiles(x86)%\microsoft shared\asian nom72kl yzw1afy sgu4m7oc gsva2xn (hyo87il).mpeg.exe
%ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\yzw1afy [milf] .rar.exe
%ProgramFiles(x86)%\windows sidebar\shared gadgets\horse nude vjq39c1gwy fw58kpr41ob1w .avi.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\sperm sgu4m7oc ash (sonja,sonja).zip.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\xakmpl nom72kl ejn547rbxhd1 (haj1oyikd,2hbt8wr).avi.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mzwpstr8n cum hot (!) .mpg.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\viaz50 mzwpstr8n girls (jade).zip.exe
%ALLUSERSPROFILE%\templates\z9z7rwe nom72kl ihthd33 nmibe2 (karin).avi.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\bd1l5ir ihthd33 sm .zip.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\black lpcu5ai3 horse hot (!) gh5b6gd7wrv (sonja).mpeg.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mnho9y54 [free] 8bgkvshe1 (jade,rdl1tfkz).mpg.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\ikdyfwhy horse bd1l5ir epyxwn cock mg9fvb2xk9 .mpg.exe
%ALLUSERSPROFILE%\templates\beast sgu4m7oc 8bgkvshe1 .mpg.exe
C:\users\default\appdata\local\microsoft\windows\<INETFILES>\ikdyfwhy 8ok6yf uncut (jade,dehod0).rar.exe
C:\users\default\appdata\local\temp\mnho9y54 xakmpl nom72kl nmibe2 (sonja).mpg.exe
C:\users\default\appdata\local\<INETFILES>\porn l9hwcs7vvnphd9 lady .avi.exe
C:\users\default\appdata\roaming\microsoft\windows\templates\7b6fhxi nude xakmpl uncut glans .rar.exe
C:\users\default\templates\lpcu5ai3 7nd83wovj sgu4m7oc .mpeg.exe
%LOCALAPPDATA%\microsoft\windows\<INETFILES>\7b6fhxi xakmpl [free] jxqgtp .rar.exe
%TEMP%\w6csjja14n1 lpcu5ai3 apv53deiq9fw hole .mpg.exe
%LOCALAPPDATA%\<INETFILES>\bd1l5ir apv53deiq9fw kfp2yqq 40+ (y8oxsqa,jenna).rar.exe
%LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\porn [bangbus] boots (hyo87il,hyo87il).mpeg.exe
%LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\nom72kl mzwpstr8n [milf] (haj1oyikd,gina).rar.exe
%LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\wpjwijv bd1l5ir sgu4m7oc .zip.exe
%APPDATA%\microsoft\templates\eq7k2xcxt xakmpl sgu4m7oc boots .avi.exe
%APPDATA%\microsoft\windows\templates\f1i7cm nom72kl apv53deiq9fw fw58kpr41ob1w .zip.exe
%APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\viaz50 8ok6yf [bangbus] .avi.exe
%HOMEPATH%\templates\z9z7rwe sperm [bangbus] feet (c4w8hqa,2hbt8wr).rar.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\nom72kl cum 7vepaqjm kfp2yqq eigt45 (sarah,c4w8hqa).mpg.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\eq7k2xcxt gay apv53deiq9fw glans boots .avi.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\jxaglwti porn 8ok6yf big hole (rdl1tfkz).mpg.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\black lpcu5ai3 wep6b08 [milf] girly .rar.exe
%WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\w6csjja14n1 mnho9y54 nom72kl lzxyhb7k .mpg.exe
%WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\asian tsomq34 sgu4m7oc gsva2xn .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\w6csjja14n1 girls 50+ .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\beast apv53deiq9fw feet gsva2xn .mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\mnho9y54 girls boobs .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\zc8giv9 horse nom72kl hairy (2hbt8wr).zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\upfgetx xakmpl 7vepaqjm feet fishy (dxocjwba).avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\8ok6yf nude sgu4m7oc kfp2yqq 6tl9zg0uqa .zip.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\sperm sgu4m7oc balls .mpg.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\nom72kl hot (!) fw58kpr41ob1w .mpeg.exe
%WINDIR%\assembly\temp\mnho9y54 beast epyxwn zn3tvn .mpg.exe
%WINDIR%\assembly\tmp\asian lpcu5ai3 7vepaqjm mg9fvb2xk9 .avi.exe
%WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\7b6fhxi nom72kl beast 7vepaqjm (y8oxsqa).zip.exe
%WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\eq7k2xcxt horse [milf] ash .mpeg.exe
%WINDIR%\pla\templates\ikdyfwhy xxx beast uncut hole hairy .zip.exe
%WINDIR%\security\templates\ikdyfwhy tsomq34 7nd83wovj nom72kl titts (dxocjwba).avi.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\asian yzw1afy ihthd33 rv0y8n .mpeg.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\temp\f1i7cm lpcu5ai3 [bangbus] titts 40+ .zip.exe
%WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\asian nom72kl horse girls titts gsva2xn (rdl1tfkz).zip.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\7b6fhxi mnho9y54 bq4kno .mpeg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\temp\cum bq4kno kfp2yqq gh5b6gd7wrv .avi.exe
%WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\h93bklf xakmpl uncut 40+ .avi.exe
%WINDIR%\syswow64\config\systemprofile\4h1e2a346 beast [free] (hyo87il,sonja).mpeg.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\beast hot (!) .zip.exe
%WINDIR%\syswow64\fxstmp\viaz50 cum hot (!) .rar.exe
%WINDIR%\syswow64\ime\shared\s2fkave mnho9y54 [milf] 50+ .mpg.exe
%WINDIR%\syswow64\config\systemprofile\f1i7cm 8ok6yf beast nom72kl .zip.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\nom72kl hot (!) sm (y8oxsqa).mpeg.exe
%WINDIR%\syswow64\fxstmp\gzn4ud7e bd1l5ir yzw1afy ihthd33 cock .mpeg.exe
%WINDIR%\syswow64\ime\shared\8r3baiec lpcu5ai3 ddqayq hot (!) glans .zip.exe
%WINDIR%\temp\lpcu5ai3 hot (!) zn3tvn .rar.exe
%WINDIR%\winsxs\installtemp\s2fkave xakmpl lpcu5ai3 l9hwcs7vvnphd9 779mipj (jade).mpeg.exe
<Current directory>\sqjaed7r1vnw
%CommonProgramFiles%\microsoft shared\8r3baiec xakmpl mnho9y54 uncut shoes .mpg.exe
%ProgramFiles%\dvd maker\shared\f1i7cm xakmpl xxx bq4kno fishy (sonja,liz).avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\f1i7cm 7nd83wovj nom72kl vjq39c1gwy (jade).avi.exe
%ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\z9z7rwe 7nd83wovj tsomq34 epyxwn (cy4xpd).zip.exe
%ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\xxx girls boots .mpg.exe
%ProgramFiles%\windows journal\templates\horse [bangbus] .avi.exe
%ProgramFiles%\windows sidebar\shared gadgets\8r3baiec horse beast apv53deiq9fw feet lzxyhb7k (cy4xpd).rar.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\xxx l9hwcs7vvnphd9 cock 8bgkvshe1 (g6u8n4r).avi.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\f1i7cm horse yzw1afy l9hwcs7vvnphd9 (c4w8hqa).zip.exe
%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\sperm l9hwcs7vvnphd9 feet b37oavmx289 .zip.exe
%CommonProgramFiles(x86)%\microsoft shared\sperm [bangbus] hole .rar.exe
%ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\black 8ok6yf horse girls (jade).avi.exe
%ProgramFiles(x86)%\windows sidebar\shared gadgets\f07qtt bd1l5ir sgu4m7oc .zip.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\sperm [milf] hole js80j73 .zip.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\8r3baiec 8ok6yf gay ihthd33 lady .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\mnho9y54 uncut feet 8pfmdyy (dxocjwba).rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\eq7k2xcxt 8ok6yf yzw1afy nom72kl nrb42wq (jenna,dxocjwba).avi.exe
%ALLUSERSPROFILE%\templates\fac71w2 8ok6yf tsomq34 hot (!) hole .mpg.exe
%ALLUSERSPROFILE%\microsoft\rac\temp\mzwpstr8n 7vepaqjm glans js80j73 (liz).rar.exe
%ALLUSERSPROFILE%\microsoft\search\data\temp\mzwpstr8n vjq39c1gwy glans .zip.exe
%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\xxx 7vepaqjm hole .rar.exe
%ALLUSERSPROFILE%\microsoft\windows\templates\beast nom72kl titts 8pfmdyy .avi.exe
C:\users\default\appdata\local\microsoft\windows\<INETFILES>\upfgetx h93bklf mzwpstr8n [milf] feet .rar.exe
C:\users\default\appdata\local\temp\gzn4ud7e 7nd83wovj horse ihthd33 .mpeg.exe
C:\users\default\appdata\local\<INETFILES>\upfgetx horse yzw1afy bq4kno feet (haj1oyikd,y8oxsqa).mpeg.exe
C:\users\default\appdata\roaming\microsoft\windows\templates\upfgetx 8ok6yf xxx uncut titts .zip.exe
C:\users\default\templates\f1i7cm nude sperm ihthd33 hole ol6p1tua .rar.exe
%LOCALAPPDATA%\microsoft\windows\<INETFILES>\f1i7cm horse yzw1afy [bangbus] hairy .zip.exe
%TEMP%\xxx 7vepaqjm (y8oxsqa).mpeg.exe
%LOCALAPPDATA%\<INETFILES>\horse [free] lzxyhb7k .mpg.exe
%LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\gzn4ud7e cum gay ihthd33 feet .avi.exe
%LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\8r3baiec w6csjja14n1 nom72kl big glans lady .mpeg.exe
%LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\xxx hot (!) cock 8pfmdyy (2hbt8wr).rar.exe
%APPDATA%\microsoft\templates\f07qtt ddqayq gay big (g6u8n4r).mpg.exe
%APPDATA%\microsoft\windows\templates\gay ihthd33 young (36mho73,liz).avi.exe
%APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\gay ihthd33 cock 40+ .avi.exe
%APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\yzw1afy vjq39c1gwy cock wifey (sarah).rar.exe
%HOMEPATH%\templates\f1i7cm horse mnho9y54 ihthd33 shoes .mpeg.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\gzn4ud7e 7nd83wovj [bangbus] lady .avi.exe
%WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\f1i7cm bd1l5ir mnho9y54 nom72kl (jade).zip.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\upfgetx porn gay nom72kl feet .mpeg.exe
%WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\tsomq34 apv53deiq9fw 8pfmdyy (sonja,jade).zip.exe
%WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\fac71w2 nude horse uncut latex .zip.exe
%WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\fac71w2 h93bklf yzw1afy apv53deiq9fw latex .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\upfgetx bd1l5ir sgu4m7oc (2hbt8wr).zip.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\xxx vjq39c1gwy feet hairy .mpeg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\horse big glans .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\horse girls titts .avi.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\f07qtt horse 7vepaqjm girly .mpg.exe
%WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\sperm apv53deiq9fw 40+ .rar.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\gay sgu4m7oc nmibe2 .zip.exe
%WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\gzn4ud7e bd1l5ir xxx hot (!) (karin).mpeg.exe
%WINDIR%\assembly\temp\gzn4ud7e 8ok6yf xxx [bangbus] hole 8bgkvshe1 (2hbt8wr).avi.exe
%WINDIR%\assembly\tmp\8r3baiec w6csjja14n1 nom72kl epyxwn titts sm .mpeg.exe
%WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\z9z7rwe xakmpl nom72kl ihthd33 (liz).rar.exe
%WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\fac71w2 nude gay epyxwn (dxocjwba).avi.exe
%WINDIR%\pla\templates\8r3baiec xakmpl horse [bangbus] (jade).mpg.exe
%WINDIR%\security\templates\gzn4ud7e ddqayq beast bq4kno .rar.exe
%WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\black horse mzwpstr8n 7vepaqjm qq6w54yfhtqrbwcslg .mpeg.exe
%WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\asian mzwpstr8n big .rar.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\beast big ash .mpg.exe
%WINDIR%\serviceprofiles\networkservice\appdata\local\temp\xxx [bangbus] shoes .avi.exe
%WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\ hot (!) titts .rar.exe
%WINDIR%\syswow64\config\systemprofile\gzn4ud7e w6csjja14n1 lpcu5ai3 ihthd33 .zip.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\black 8ok6yf mzwpstr8n uncut feet .avi.exe
%WINDIR%\syswow64\fxstmp\xakmpl mzwpstr8n 7vepaqjm cock 50+ .mpg.exe
%WINDIR%\syswow64\ime\shared\horse sgu4m7oc sgoibhh .rar.exe
%WINDIR%\syswow64\config\systemprofile\fac71w2 8ok6yf [milf] (dxocjwba).avi.exe
%WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\fac71w2 nude xxx big (c4w8hqa).zip.exe
%WINDIR%\syswow64\fxstmp\yzw1afy ihthd33 .mpeg.exe
%WINDIR%\syswow64\ime\shared\8r3baiec ddqayq gay [bangbus] cock boots (sarah).mpeg.exe
%WINDIR%\temp\mzwpstr8n uncut .avi.exe
Miscellaneous
Searches for the following windows
ClassName: 'Progman' WindowName: ''
ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
Curing recommendations
Windows
macOS
Linux
Android
If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space .
If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.
If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
Switch off your device and turn it on as normal.
Find out more about Dr.Web for Android
Descargue Dr.Web para Android
Gratis por 3 meses
Todos los componentes de protección
Renovación de la demo a través de AppGallery/Google Pay
Si Vd. continúa usando este sitio web, esto significa que Vd. acepta el uso de archivos Cookie y otras tecnologías para que recabemos las estadísticas sobre los visitantes. Más información
OK