Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Trojan.KillProc2.30003

Added to the Dr.Web virus database: 2025-07-17

Virus description added:

Technical Information

Malicious functions
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\explorer.exe
  • <SYSTEM32>\taskhost.exe
  • <SYSTEM32>\dwm.exe
the following user processes:
  • iexplore.exe
  • firefox.exe
Modifies file system
Creates the following files
  • %WINDIR%y1s2fctrp3
  • %CommonProgramFiles%\microsoft shared\mnho9y54 [milf] .avi.exe
  • %ProgramFiles%\dvd maker\shared\wep6b08 cum big titts ol6p1tua (36mho73).mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\0287zh nude apv53deiq9fw .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\porn big .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\z9z7rwe gay big girly .mpg.exe
  • %ProgramFiles%\microsoft office\templates\mnho9y54 l9hwcs7vvnphd9 gh5b6gd7wrv (jenna,c4w8hqa).mpg.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\black sperm girls .mpg.exe
  • %ProgramFiles%\windows journal\templates\black apv53deiq9fw .mpg.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\xakmpl ddqayq sgu4m7oc feet fishy .zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\mnho9y54 wep6b08 epyxwn cock gh5b6gd7wrv .mpeg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\f07qtt horse w6csjja14n1 [bangbus] titts ash (dxocjwba,2hbt8wr).mpg.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\gzn4ud7e gay porn hot (!) hole nmibe2 .zip.exe
  • %CommonProgramFiles(x86)%\microsoft shared\wpjwijv 8ok6yf uncut .mpg.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\gay nom72kl bq4kno (c4w8hqa).mpg.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\asian 7nd83wovj xakmpl 7vepaqjm hole wifey .zip.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\w6csjja14n1 [free] titts (jade,36mho73).avi.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\bd1l5ir horse uncut titts mg9fvb2xk9 (dehod0).mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\h93bklf gay [bangbus] 8bgkvshe1 .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\black w6csjja14n1 h93bklf l9hwcs7vvnphd9 ash fishy .rar.exe
  • %ALLUSERSPROFILE%\templates\tsomq34 cum l9hwcs7vvnphd9 (g6u8n4r,rdl1tfkz).mpg.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\wpjwijv porn tsomq34 [milf] .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\ddqayq epyxwn feet ol6p1tua .mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\f07qtt nude cum big boots .avi.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\w6csjja14n1 nude epyxwn js80j73 .rar.exe
  • %ALLUSERSPROFILE%\templates\7b6fhxi sperm sperm ihthd33 legs nrb42wq (jenna,jenna).mpg.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\wpjwijv lpcu5ai3 vjq39c1gwy .mpeg.exe
  • C:\users\default\appdata\local\temp\ 8ok6yf uncut .avi.exe
  • C:\users\default\appdata\local\<INETFILES>\gay nude 7vepaqjm feet qq6w54yfhtqrbwcslg .rar.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\z1qxwcd horse 7vepaqjm ol6p1tua .zip.exe
  • C:\users\default\templates\z9z7rwe 7nd83wovj [bangbus] 8bgkvshe1 .mpg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\horse epyxwn js80j73 .mpg.exe
  • %TEMP%\fac71w2 w6csjja14n1 l9hwcs7vvnphd9 (dehod0,2hbt8wr).mpeg.exe
  • %LOCALAPPDATA%\<INETFILES>\jxaglwti xxx 8ok6yf uncut gsva2xn (y8oxsqa,y8oxsqa).mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\viaz50 w6csjja14n1 [milf] hole fishy (36mho73,jenna).mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\4h1e2a346 gay mnho9y54 7vepaqjm shoes .zip.exe
  • %LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\bd1l5ir nom72kl apv53deiq9fw gh5b6gd7wrv (haj1oyikd,karin).rar.exe
  • %APPDATA%\microsoft\templates\0287zh mnho9y54 [milf] .mpg.exe
  • %APPDATA%\microsoft\windows\templates\ gay nom72kl young .avi.exe
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\z9z7rwe w6csjja14n1 cum sgu4m7oc .rar.exe
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\ikdyfwhy tsomq34 beast uncut (jenna).mpeg.exe
  • %HOMEPATH%\templates\s2fkave mzwpstr8n vjq39c1gwy .rar.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\upfgetx lpcu5ai3 lpcu5ai3 [free] titts .mpeg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\z9z7rwe bd1l5ir lpcu5ai3 nom72kl .mpg.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\viaz50 h93bklf beast vjq39c1gwy 8pfmdyy (rdl1tfkz).rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\eq7k2xcxt 8ok6yf uncut ash .rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\zc8giv9 wep6b08 uncut .mpeg.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\eq7k2xcxt w6csjja14n1 w6csjja14n1 ihthd33 gsva2xn (2hbt8wr).mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\horse big 779mipj .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\8r3baiec ddqayq xxx hot (!) nmibe2 .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\f07qtt wep6b08 girls legs .avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\viaz50 lpcu5ai3 beast girls .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\porn tsomq34 hot (!) gsva2xn .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\ikdyfwhy porn gay girls .mpg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\z9z7rwe yzw1afy horse uncut .rar.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\wep6b08 hot (!) (karin,dehod0).zip.exe
  • %WINDIR%\assembly\temp\gzn4ud7e horse lpcu5ai3 uncut .rar.exe
  • %WINDIR%\assembly\tmp\w6csjja14n1 apv53deiq9fw sgoibhh .mpg.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\7nd83wovj gay [free] boobs 40+ .zip.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\beast epyxwn .mpeg.exe
  • %WINDIR%\pla\templates\f1i7cm tsomq34 big feet qx2j1b5 .mpeg.exe
  • %WINDIR%\security\templates\porn hot (!) balls (2hbt8wr,karin).mpeg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\ddqayq sperm sgu4m7oc kfp2yqq sm (y8oxsqa).zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\w6csjja14n1 porn apv53deiq9fw js80j73 .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\gzn4ud7e xxx tsomq34 big rv0y8n .mpg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\z1qxwcd 8ok6yf ddqayq bq4kno glans .mpeg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\z1qxwcd beast nude big boobs .rar.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\lpcu5ai3 cum sgu4m7oc fw58kpr41ob1w (sonja,36mho73).zip.exe
  • %WINDIR%\syswow64\config\systemprofile\gzn4ud7e mzwpstr8n l9hwcs7vvnphd9 .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\xakmpl mnho9y54 vjq39c1gwy .mpg.exe
  • %WINDIR%\syswow64\fxstmp\horse w6csjja14n1 bq4kno .zip.exe
  • %WINDIR%\syswow64\ime\shared\z9z7rwe horse girls sgoibhh .mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\8r3baiec tsomq34 [milf] (hyo87il).mpg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\wpjwijv 8ok6yf uncut gh5b6gd7wrv (sonja,sarah).mpeg.exe
  • %WINDIR%\syswow64\fxstmp\wpjwijv 7nd83wovj 8ok6yf big feet 40+ .rar.exe
  • %WINDIR%\syswow64\ime\shared\horse hot (!) hole 779mipj .avi.exe
  • %WINDIR%\temp\fac71w2 xxx gay sgu4m7oc nrb42wq .zip.exe
  • %WINDIR%\winsxs\installtemp\wpjwijv horse bq4kno sgoibhh .zip.exe
  • <Current directory>\sqjaed7r1vnw
  • %CommonProgramFiles%\microsoft shared\wpjwijv mnho9y54 [milf] feet (gina).mpeg.exe
  • %ProgramFiles%\dvd maker\shared\7nd83wovj 7vepaqjm eigt45 (karin).mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\yzw1afy xakmpl apv53deiq9fw qq6w54yfhtqrbwcslg .zip.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\horse tsomq34 [milf] fw58kpr41ob1w .avi.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\xxx mnho9y54 [milf] .mpeg.exe
  • %ProgramFiles%\microsoft office\templates\eq7k2xcxt bd1l5ir porn [milf] ash mg9fvb2xk9 .mpg.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\8r3baiec yzw1afy uncut cock .avi.exe
  • %ProgramFiles%\windows journal\templates\lpcu5ai3 epyxwn qq6w54yfhtqrbwcslg .rar.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\beast [free] (sonja,2hbt8wr).rar.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\z9z7rwe tsomq34 bq4kno qq6w54yfhtqrbwcslg .zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\wpjwijv w6csjja14n1 bd1l5ir bq4kno ejn547rbxhd1 .zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\nom72kl 8ok6yf hot (!) cock .rar.exe
  • %CommonProgramFiles(x86)%\microsoft shared\zc8giv9 8ok6yf 7vepaqjm .mpg.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\f1i7cm 7vepaqjm young .rar.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\black mzwpstr8n xakmpl uncut b37oavmx289 (sonja).avi.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\viaz50 w6csjja14n1 w6csjja14n1 big fishy .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\tsomq34 7vepaqjm boots .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\h93bklf [bangbus] shoes .mpg.exe
  • %ALLUSERSPROFILE%\templates\8r3baiec mzwpstr8n hot (!) .rar.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\f07qtt ddqayq [bangbus] mg9fvb2xk9 (dehod0,2hbt8wr).mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\beast hot (!) boobs ash (jade).avi.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\7nd83wovj lpcu5ai3 big qq6w54yfhtqrbwcslg .avi.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\ 7vepaqjm hole hotel (karin,hyo87il).zip.exe
  • %ALLUSERSPROFILE%\templates\w6csjja14n1 bq4kno qx2j1b5 .mpeg.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\horse xxx hot (!) (jenna,2hbt8wr).mpeg.exe
  • C:\users\default\appdata\local\temp\eq7k2xcxt 8ok6yf w6csjja14n1 uncut b37oavmx289 .mpeg.exe
  • C:\users\default\appdata\local\<INETFILES>\7b6fhxi lpcu5ai3 8ok6yf sgu4m7oc kfp2yqq boots .zip.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\tsomq34 nom72kl cock (dehod0,liz).mpg.exe
  • C:\users\default\templates\horse vjq39c1gwy wifey .mpg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\nom72kl 7nd83wovj [milf] 8bgkvshe1 .mpg.exe
  • %TEMP%\7b6fhxi sperm [milf] nmibe2 .avi.exe
  • %LOCALAPPDATA%\<INETFILES>\yzw1afy h93bklf [milf] .mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{070abd97-84e1-4f5f-9c02-f1d76dd9fce4}\4h1e2a346 7nd83wovj uncut zn3tvn .mpeg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{1fae114c-c2b0-4da1-b23a-8e5ad0c3d722}\8r3baiec beast xxx uncut girly .mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{3571406e-c08c-4c74-b145-8857b365f6e7}\7b6fhxi wep6b08 epyxwn cock rv0y8n (jade).mpeg.exe
  • %APPDATA%\microsoft\templates\sperm yzw1afy big young .avi.exe
  • %APPDATA%\microsoft\windows\templates\8ok6yf mzwpstr8n ihthd33 .avi.exe
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\temporary\ddqayq vjq39c1gwy titts (c4w8hqa,jenna).rar.exe
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\temporary\asian cum mzwpstr8n bq4kno .zip.exe
  • %HOMEPATH%\templates\cum bd1l5ir epyxwn js80j73 .mpeg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\7b6fhxi xxx [milf] .mpg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\nude horse l9hwcs7vvnphd9 hotel (gina).zip.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\f07qtt nom72kl 7nd83wovj [bangbus] titts nmibe2 .mpg.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\yzw1afy sperm bq4kno (haj1oyikd).rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\tsomq34 wep6b08 l9hwcs7vvnphd9 latex .avi.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\8ok6yf apv53deiq9fw fishy (karin).avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\wpjwijv 8ok6yf xxx 7vepaqjm girly .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\f07qtt beast hot (!) shoes .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\beast h93bklf bq4kno .avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\horse w6csjja14n1 big (gina,hyo87il).avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\asian horse epyxwn fishy .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\jxaglwti horse [free] .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\bd1l5ir l9hwcs7vvnphd9 .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\mzwpstr8n girls (jenna,c4w8hqa).mpg.exe
  • %WINDIR%\assembly\temp\beast mzwpstr8n [milf] (rdl1tfkz,jenna).rar.exe
  • %WINDIR%\assembly\tmp\s2fkave nom72kl [free] .mpeg.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\ ddqayq ihthd33 ash (hyo87il).avi.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\0287zh mnho9y54 bd1l5ir vjq39c1gwy ash .mpg.exe
  • %WINDIR%\pla\templates\eq7k2xcxt gay epyxwn qq6w54yfhtqrbwcslg .mpeg.exe
  • %WINDIR%\security\templates\black mzwpstr8n uncut 50+ .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\sperm vjq39c1gwy .mpeg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\f07qtt gay beast bq4kno .mpeg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\upfgetx lpcu5ai3 mnho9y54 l9hwcs7vvnphd9 (sarah).mpg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\xakmpl ddqayq apv53deiq9fw 8bgkvshe1 .avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\black 7nd83wovj uncut hole lady .mpeg.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\zc8giv9 tsomq34 gay epyxwn latex (rdl1tfkz).zip.exe
  • %WINDIR%\syswow64\config\systemprofile\8r3baiec w6csjja14n1 nude apv53deiq9fw .rar.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\z9z7rwe yzw1afy beast [free] lady .mpeg.exe
  • %WINDIR%\syswow64\fxstmp\jxaglwti big zmc8ujp (rdl1tfkz).mpg.exe
  • %WINDIR%\syswow64\ime\shared\horse uncut sgoibhh .mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\horse epyxwn titts 6tl9zg0uqa .mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\gzn4ud7e xxx epyxwn ash latex (haj1oyikd).mpeg.exe
  • %WINDIR%\syswow64\fxstmp\fac71w2 ddqayq hot (!) .avi.exe
  • %WINDIR%\syswow64\ime\shared\asian horse vjq39c1gwy glans 8pfmdyy .avi.exe
  • %WINDIR%\winsxs\installtemp\w6csjja14n1 [bangbus] ae2sd7u4xh .zip.exe
Miscellaneous
Searches for the following windows
  • ClassName: 'Progman' WindowName: ''
  • ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
  • '%WINDIR%\explorer.exe'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android