マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.KillProc.46635

Added to the Dr.Web virus database: 2016-09-30

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Classes\.cmd] '' = 'exefile'
  • [<HKLM>\SOFTWARE\Classes\.bat] '' = 'exefile'
Creates the following files on removable media:
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг15000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг16500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг12100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг14300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг13600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг23200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг23100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг23000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг21900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг22300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг17900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг18900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг20100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг19400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг3400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг4900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг1900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг2000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг9200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг11400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг10700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6800.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг5900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг6300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8300.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8200.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8100.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7600.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7500.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7400.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7700.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг8000.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7900.exe
  • <Drive name for removable media>:\СЕГч°жРЬГЁЙХПг7800.exe
Malicious functions:
Executes the following:
  • '<SYSTEM32>\rundll32.exe' fldrclnr.dll,Wizard_RunDLL
  • '%WINDIR%\explorer.exe'
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\Explorer.EXE
Modifies file system:
Creates the following files:
  • C:\СЕГч°жРЬГЁЙХПг15500.exe
  • C:\СЕГч°жРЬГЁЙХПг15400.exe
  • C:\СЕГч°жРЬГЁЙХПг15300.exe
  • C:\СЕГч°жРЬГЁЙХПг15600.exe
  • C:\СЕГч°жРЬГЁЙХПг15900.exe
  • C:\СЕГч°жРЬГЁЙХПг15800.exe
  • C:\СЕГч°жРЬГЁЙХПг15700.exe
  • C:\СЕГч°жРЬГЁЙХПг14800.exe
  • C:\СЕГч°жРЬГЁЙХПг14700.exe
  • C:\СЕГч°жРЬГЁЙХПг14600.exe
  • C:\СЕГч°жРЬГЁЙХПг14900.exe
  • C:\СЕГч°жРЬГЁЙХПг15200.exe
  • C:\СЕГч°жРЬГЁЙХПг15100.exe
  • C:\СЕГч°жРЬГЁЙХПг15000.exe
  • C:\СЕГч°жРЬГЁЙХПг16000.exe
  • C:\СЕГч°жРЬГЁЙХПг17000.exe
  • C:\СЕГч°жРЬГЁЙХПг16900.exe
  • C:\СЕГч°жРЬГЁЙХПг16800.exe
  • C:\СЕГч°жРЬГЁЙХПг17100.exe
  • C:\СЕГч°жРЬГЁЙХПг17400.exe
  • C:\СЕГч°жРЬГЁЙХПг17300.exe
  • C:\СЕГч°жРЬГЁЙХПг17200.exe
  • C:\СЕГч°жРЬГЁЙХПг16300.exe
  • C:\СЕГч°жРЬГЁЙХПг16200.exe
  • C:\СЕГч°жРЬГЁЙХПг16100.exe
  • C:\СЕГч°жРЬГЁЙХПг16400.exe
  • C:\СЕГч°жРЬГЁЙХПг16700.exe
  • C:\СЕГч°жРЬГЁЙХПг16600.exe
  • C:\СЕГч°жРЬГЁЙХПг16500.exe
  • C:\СЕГч°жРЬГЁЙХПг12600.exe
  • C:\СЕГч°жРЬГЁЙХПг12500.exe
  • C:\СЕГч°жРЬГЁЙХПг12400.exe
  • C:\СЕГч°жРЬГЁЙХПг12700.exe
  • C:\СЕГч°жРЬГЁЙХПг13000.exe
  • C:\СЕГч°жРЬГЁЙХПг12900.exe
  • C:\СЕГч°жРЬГЁЙХПг12800.exe
  • C:\СЕГч°жРЬГЁЙХПг11900.exe
  • C:\СЕГч°жРЬГЁЙХПг11800.exe
  • C:\СЕГч°жРЬГЁЙХПг11700.exe
  • C:\СЕГч°жРЬГЁЙХПг12000.exe
  • C:\СЕГч°жРЬГЁЙХПг12300.exe
  • C:\СЕГч°жРЬГЁЙХПг12200.exe
  • C:\СЕГч°жРЬГЁЙХПг12100.exe
  • C:\СЕГч°жРЬГЁЙХПг13100.exe
  • C:\СЕГч°жРЬГЁЙХПг14100.exe
  • C:\СЕГч°жРЬГЁЙХПг14000.exe
  • C:\СЕГч°жРЬГЁЙХПг13900.exe
  • C:\СЕГч°жРЬГЁЙХПг14200.exe
  • C:\СЕГч°жРЬГЁЙХПг14500.exe
  • C:\СЕГч°жРЬГЁЙХПг14400.exe
  • C:\СЕГч°жРЬГЁЙХПг14300.exe
  • C:\СЕГч°жРЬГЁЙХПг13400.exe
  • C:\СЕГч°жРЬГЁЙХПг13300.exe
  • C:\СЕГч°жРЬГЁЙХПг13200.exe
  • C:\СЕГч°жРЬГЁЙХПг13500.exe
  • C:\СЕГч°жРЬГЁЙХПг13800.exe
  • C:\СЕГч°жРЬГЁЙХПг13700.exe
  • C:\СЕГч°жРЬГЁЙХПг13600.exe
  • C:\СЕГч°жРЬГЁЙХПг21300.exe
  • C:\СЕГч°жРЬГЁЙХПг21200.exe
  • C:\СЕГч°жРЬГЁЙХПг21100.exe
  • C:\СЕГч°жРЬГЁЙХПг21400.exe
  • C:\СЕГч°жРЬГЁЙХПг21700.exe
  • C:\СЕГч°жРЬГЁЙХПг21600.exe
  • C:\СЕГч°жРЬГЁЙХПг21500.exe
  • C:\СЕГч°жРЬГЁЙХПг20600.exe
  • C:\СЕГч°жРЬГЁЙХПг20500.exe
  • C:\СЕГч°жРЬГЁЙХПг20400.exe
  • C:\СЕГч°жРЬГЁЙХПг20700.exe
  • C:\СЕГч°жРЬГЁЙХПг21000.exe
  • C:\СЕГч°жРЬГЁЙХПг20900.exe
  • C:\СЕГч°жРЬГЁЙХПг20800.exe
  • C:\СЕГч°жРЬГЁЙХПг21800.exe
  • C:\СЕГч°жРЬГЁЙХПг22800.exe
  • C:\СЕГч°жРЬГЁЙХПг22700.exe
  • C:\СЕГч°жРЬГЁЙХПг22600.exe
  • C:\СЕГч°жРЬГЁЙХПг22900.exe
  • C:\СЕГч°жРЬГЁЙХПг23200.exe
  • C:\СЕГч°жРЬГЁЙХПг23100.exe
  • C:\СЕГч°жРЬГЁЙХПг23000.exe
  • C:\СЕГч°жРЬГЁЙХПг22100.exe
  • C:\СЕГч°жРЬГЁЙХПг22000.exe
  • C:\СЕГч°жРЬГЁЙХПг21900.exe
  • C:\СЕГч°жРЬГЁЙХПг22200.exe
  • C:\СЕГч°жРЬГЁЙХПг22500.exe
  • C:\СЕГч°жРЬГЁЙХПг22400.exe
  • C:\СЕГч°жРЬГЁЙХПг22300.exe
  • C:\СЕГч°жРЬГЁЙХПг18400.exe
  • C:\СЕГч°жРЬГЁЙХПг18300.exe
  • C:\СЕГч°жРЬГЁЙХПг18200.exe
  • C:\СЕГч°жРЬГЁЙХПг18500.exe
  • C:\СЕГч°жРЬГЁЙХПг18800.exe
  • C:\СЕГч°жРЬГЁЙХПг18700.exe
  • C:\СЕГч°жРЬГЁЙХПг18600.exe
  • C:\СЕГч°жРЬГЁЙХПг17700.exe
  • C:\СЕГч°жРЬГЁЙХПг17600.exe
  • C:\СЕГч°жРЬГЁЙХПг17500.exe
  • C:\СЕГч°жРЬГЁЙХПг17800.exe
  • C:\СЕГч°жРЬГЁЙХПг18100.exe
  • C:\СЕГч°жРЬГЁЙХПг18000.exe
  • C:\СЕГч°жРЬГЁЙХПг17900.exe
  • C:\СЕГч°жРЬГЁЙХПг18900.exe
  • C:\СЕГч°жРЬГЁЙХПг19900.exe
  • C:\СЕГч°жРЬГЁЙХПг19800.exe
  • C:\СЕГч°жРЬГЁЙХПг19700.exe
  • C:\СЕГч°жРЬГЁЙХПг20000.exe
  • C:\СЕГч°жРЬГЁЙХПг20300.exe
  • C:\СЕГч°жРЬГЁЙХПг20200.exe
  • C:\СЕГч°жРЬГЁЙХПг20100.exe
  • C:\СЕГч°жРЬГЁЙХПг19200.exe
  • C:\СЕГч°жРЬГЁЙХПг19100.exe
  • C:\СЕГч°жРЬГЁЙХПг19000.exe
  • C:\СЕГч°жРЬГЁЙХПг19300.exe
  • C:\СЕГч°жРЬГЁЙХПг19600.exe
  • C:\СЕГч°жРЬГЁЙХПг19500.exe
  • C:\СЕГч°жРЬГЁЙХПг19400.exe
  • C:\СЕГч°жРЬГЁЙХПг3900.exe
  • C:\СЕГч°жРЬГЁЙХПг3800.exe
  • C:\СЕГч°жРЬГЁЙХПг3700.exe
  • C:\СЕГч°жРЬГЁЙХПг4000.exe
  • C:\СЕГч°жРЬГЁЙХПг4300.exe
  • C:\СЕГч°жРЬГЁЙХПг4200.exe
  • C:\СЕГч°жРЬГЁЙХПг4100.exe
  • C:\СЕГч°жРЬГЁЙХПг3200.exe
  • C:\СЕГч°жРЬГЁЙХПг3100.exe
  • C:\СЕГч°жРЬГЁЙХПг3000.exe
  • C:\СЕГч°жРЬГЁЙХПг3300.exe
  • C:\СЕГч°жРЬГЁЙХПг3600.exe
  • C:\СЕГч°жРЬГЁЙХПг3500.exe
  • C:\СЕГч°жРЬГЁЙХПг3400.exe
  • C:\СЕГч°жРЬГЁЙХПг4400.exe
  • C:\СЕГч°жРЬГЁЙХПг5400.exe
  • C:\СЕГч°жРЬГЁЙХПг5300.exe
  • C:\СЕГч°жРЬГЁЙХПг5200.exe
  • C:\СЕГч°жРЬГЁЙХПг5500.exe
  • C:\СЕГч°жРЬГЁЙХПг5800.exe
  • C:\СЕГч°жРЬГЁЙХПг5700.exe
  • C:\СЕГч°жРЬГЁЙХПг5600.exe
  • C:\СЕГч°жРЬГЁЙХПг4700.exe
  • C:\СЕГч°жРЬГЁЙХПг4600.exe
  • C:\СЕГч°жРЬГЁЙХПг4500.exe
  • C:\СЕГч°жРЬГЁЙХПг4800.exe
  • C:\СЕГч°жРЬГЁЙХПг5100.exe
  • C:\СЕГч°жРЬГЁЙХПг5000.exe
  • C:\СЕГч°жРЬГЁЙХПг4900.exe
  • C:\СЕГч°жРЬГЁЙХПг1000.exe
  • C:\СЕГч°жРЬГЁЙХПг900.exe
  • C:\СЕГч°жРЬГЁЙХПг800.exe
  • C:\СЕГч°жРЬГЁЙХПг1100.exe
  • C:\СЕГч°жРЬГЁЙХПг1400.exe
  • C:\СЕГч°жРЬГЁЙХПг1300.exe
  • C:\СЕГч°жРЬГЁЙХПг1200.exe
  • C:\СЕГч°жРЬГЁЙХПг300.exe
  • C:\СЕГч°жРЬГЁЙХПг200.exe
  • C:\СЕГч°жРЬГЁЙХПг100.exe
  • C:\СЕГч°жРЬГЁЙХПг400.exe
  • C:\СЕГч°жРЬГЁЙХПг700.exe
  • C:\СЕГч°жРЬГЁЙХПг600.exe
  • C:\СЕГч°жРЬГЁЙХПг500.exe
  • C:\СЕГч°жРЬГЁЙХПг1500.exe
  • C:\СЕГч°жРЬГЁЙХПг2500.exe
  • C:\СЕГч°жРЬГЁЙХПг2400.exe
  • C:\СЕГч°жРЬГЁЙХПг2300.exe
  • C:\СЕГч°жРЬГЁЙХПг2600.exe
  • C:\СЕГч°жРЬГЁЙХПг2900.exe
  • C:\СЕГч°жРЬГЁЙХПг2800.exe
  • C:\СЕГч°жРЬГЁЙХПг2700.exe
  • C:\СЕГч°жРЬГЁЙХПг1800.exe
  • C:\СЕГч°жРЬГЁЙХПг1700.exe
  • C:\СЕГч°жРЬГЁЙХПг1600.exe
  • C:\СЕГч°жРЬГЁЙХПг1900.exe
  • C:\СЕГч°жРЬГЁЙХПг2200.exe
  • C:\СЕГч°жРЬГЁЙХПг2100.exe
  • C:\СЕГч°жРЬГЁЙХПг2000.exe
  • C:\СЕГч°жРЬГЁЙХПг9700.exe
  • C:\СЕГч°жРЬГЁЙХПг9600.exe
  • C:\СЕГч°жРЬГЁЙХПг9500.exe
  • C:\СЕГч°жРЬГЁЙХПг9800.exe
  • C:\СЕГч°жРЬГЁЙХПг10100.exe
  • C:\СЕГч°жРЬГЁЙХПг10000.exe
  • C:\СЕГч°жРЬГЁЙХПг9900.exe
  • C:\СЕГч°жРЬГЁЙХПг9000.exe
  • C:\СЕГч°жРЬГЁЙХПг8900.exe
  • C:\СЕГч°жРЬГЁЙХПг8800.exe
  • C:\СЕГч°жРЬГЁЙХПг9100.exe
  • C:\СЕГч°жРЬГЁЙХПг9400.exe
  • C:\СЕГч°жРЬГЁЙХПг9300.exe
  • C:\СЕГч°жРЬГЁЙХПг9200.exe
  • C:\СЕГч°жРЬГЁЙХПг10200.exe
  • C:\СЕГч°жРЬГЁЙХПг11200.exe
  • C:\СЕГч°жРЬГЁЙХПг11100.exe
  • C:\СЕГч°жРЬГЁЙХПг11000.exe
  • C:\СЕГч°жРЬГЁЙХПг11300.exe
  • C:\СЕГч°жРЬГЁЙХПг11600.exe
  • C:\СЕГч°жРЬГЁЙХПг11500.exe
  • C:\СЕГч°жРЬГЁЙХПг11400.exe
  • C:\СЕГч°жРЬГЁЙХПг10500.exe
  • C:\СЕГч°жРЬГЁЙХПг10400.exe
  • C:\СЕГч°жРЬГЁЙХПг10300.exe
  • C:\СЕГч°жРЬГЁЙХПг10600.exe
  • C:\СЕГч°жРЬГЁЙХПг10900.exe
  • C:\СЕГч°жРЬГЁЙХПг10800.exe
  • C:\СЕГч°жРЬГЁЙХПг10700.exe
  • C:\СЕГч°жРЬГЁЙХПг6800.exe
  • C:\СЕГч°жРЬГЁЙХПг6700.exe
  • C:\СЕГч°жРЬГЁЙХПг6600.exe
  • C:\СЕГч°жРЬГЁЙХПг6900.exe
  • C:\СЕГч°жРЬГЁЙХПг7200.exe
  • C:\СЕГч°жРЬГЁЙХПг7100.exe
  • C:\СЕГч°жРЬГЁЙХПг7000.exe
  • C:\СЕГч°жРЬГЁЙХПг6100.exe
  • C:\СЕГч°жРЬГЁЙХПг6000.exe
  • C:\СЕГч°жРЬГЁЙХПг5900.exe
  • C:\СЕГч°жРЬГЁЙХПг6200.exe
  • C:\СЕГч°жРЬГЁЙХПг6500.exe
  • C:\СЕГч°жРЬГЁЙХПг6400.exe
  • C:\СЕГч°жРЬГЁЙХПг6300.exe
  • C:\СЕГч°жРЬГЁЙХПг7300.exe
  • C:\СЕГч°жРЬГЁЙХПг8300.exe
  • C:\СЕГч°жРЬГЁЙХПг8200.exe
  • C:\СЕГч°жРЬГЁЙХПг8100.exe
  • C:\СЕГч°жРЬГЁЙХПг8400.exe
  • C:\СЕГч°жРЬГЁЙХПг8700.exe
  • C:\СЕГч°жРЬГЁЙХПг8600.exe
  • C:\СЕГч°жРЬГЁЙХПг8500.exe
  • C:\СЕГч°жРЬГЁЙХПг7600.exe
  • C:\СЕГч°жРЬГЁЙХПг7500.exe
  • C:\СЕГч°жРЬГЁЙХПг7400.exe
  • C:\СЕГч°жРЬГЁЙХПг7700.exe
  • C:\СЕГч°жРЬГЁЙХПг8000.exe
  • C:\СЕГч°жРЬГЁЙХПг7900.exe
  • C:\СЕГч°жРЬГЁЙХПг7800.exe
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: ''
  • ClassName: 'OleMainThreadWndClass' WindowName: ''
  • ClassName: 'CSCHiddenWindow' WindowName: ''
  • ClassName: 'SystemTray_Main' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: '' WindowName: 'explorer.exe'
  • ClassName: 'BaseBar' WindowName: 'ChanApp'
  • ClassName: 'Proxy Desktop' WindowName: ''

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android