Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.KillProc2.24648

Added to the Dr.Web virus database: 2025-06-17

Virus description added:

Technical Information

Malicious functions
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\explorer.exe
  • <SYSTEM32>\taskhost.exe
  • <SYSTEM32>\dwm.exe
the following user processes:
  • iexplore.exe
  • firefox.exe
Modifies file system
Creates the following files
  • %WINDIR%prea12ybq3
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\5i8wmj9 [milf] titts 1wyga12mzc .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\peud38v obd4vccp8 5i8wmj9 [bangbus] .mpeg.exe
  • %ALLUSERSPROFILE%\templates\k1tlhzdf 3ikjnm4y .zip.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\tf1tq013 vegpvr sperm 3z6oda glans agl9tsu (karin).mpeg.exe
  • C:\users\default\appdata\local\temp\tf1tq013 2yuliau sperm w5t8cu4 boots .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\k1tlhzdf a1swtsdhkhbf titts ash .avi.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\dk4amn0 vyfkljc16kq yo6djypsz qfb04d7ux8iegf glans .mpeg.exe
  • C:\users\default\appdata\local\<INETFILES>\beast 3z6oda (karin).rar.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\dk4amn0 cum sperm [milf] fishy .rar.exe
  • %TEMP%\k1tlhzdf w5t8cu4 hole wifey .avi.exe
  • %LOCALAPPDATA%\<INETFILES>\horse cew2xnf4xc .rar.exe
  • %LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\peud38v abj24u k1tlhzdf qfb04d7ux8iegf feet hairy (jade).avi.exe
  • %LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\dxzg91nv3 horse mvakgcwi f9kdqlk (jade).rar.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\dk4amn0 porn w5t8cu4 uncut sweet .avi.exe
  • C:\users\default\templates\ktrosnb 2yuliau vg2zgnq [milf] .mpg.exe
  • %ALLUSERSPROFILE%\templates\yhfjge etorvhr mvakgcwi uncut (opgr3as).mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\w5t8cu4 girls sweet .mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\ 3ikjnm4y feet 1n4kl7830jqa .mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\vg2zgnq [milf] hole .mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\dk4amn0 nude yo6djypsz w5t8cu4 n3mhrd7 .rar.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\w5t8cu4 [free] cock (gyta81s3l,sarah).mpeg.exe
  • %ProgramFiles%\microsoft office\templates\dk4amn0 5p4dftc yo6djypsz hot (!) (4us7a95g).avi.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\0nmwz7s abj24u sperm [milf] vkwhqow (gina,4us7a95g).avi.exe
  • %ProgramFiles%\windows journal\templates\ f9kdqlk hole 0vzq1yfv (rhpa1v).mpg.exe
  • %ProgramFiles%\dvd maker\shared\horse 3ikjnm4y h41hy4cklkoue .zip.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\thw5cms3 vyfkljc16kq yo6djypsz 6hg4sl cock .avi.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\z7qips 5p4dftc yo6djypsz girls hole 8j1qjf (karin).rar.exe
  • %CommonProgramFiles(x86)%\microsoft shared\z7qips porn uncut (jade).rar.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\z7qips yton2v mvakgcwi girls cock fishy (karin).mpeg.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\k1tlhzdf [milf] .zip.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\gay snidyfph shoes .zip.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\mvakgcwi [free] cock .rar.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\thw5cms3 vyfkljc16kq f9kdqlk glans dvmdzwh8lo .zip.exe
  • %LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\5i8wmj9 w5t8cu4 .mpg.exe
  • %APPDATA%\microsoft\templates\dk4amn0 obd4vccp8 k1tlhzdf qfb04d7ux8iegf feet .avi.exe
  • %APPDATA%\microsoft\windows\templates\xxx 3ikjnm4y shoes (sonja,rhpa1v).avi.exe
  • %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\thw5cms3 horse horse big .avi.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\5i8wmj9 qfb04d7ux8iegf hole 40+ (liz).zip.exe
  • %WINDIR%\pla\templates\dxzg91nv3 etorvhr k1tlhzdf [free] cock (jenna,karin).avi.exe
  • %WINDIR%\security\templates\5i8wmj9 [free] ash .avi.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\dk4amn0 2yuliau yo6djypsz w5t8cu4 titts n3mhrd7 .rar.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\dxzg91nv3 cum gay qfb04d7ux8iegf balls .rar.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\black cum beast cew2xnf4xc .zip.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\ktrosnb 2yuliau vg2zgnq 3ikjnm4y cock n3mhrd7 .zip.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\0nmwz7s vegpvr xxx qfb04d7ux8iegf feet .zip.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\peud38v yton2v 5i8wmj9 qfb04d7ux8iegf cock .mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\z7qips 2yuliau vg2zgnq girls (rhpa1v).mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\0nmwz7s 2yuliau horse snidyfph feet 40+ .rar.exe
  • %WINDIR%\syswow64\fxstmp\black obd4vccp8 xxx w5t8cu4 .mpeg.exe
  • %WINDIR%\syswow64\ime\shared\vg2zgnq snidyfph feet .mpeg.exe
  • %WINDIR%\syswow64\config\systemprofile\black 5p4dftc mvakgcwi f9kdqlk agl9tsu .zip.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\ktrosnb 5p4dftc mvakgcwi big titts q4njwcdgux5bzomjnr (liz).rar.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\ktrosnb cum yo6djypsz [bangbus] 40+ .mpeg.exe
  • %WINDIR%\assembly\temp\yhfjge cum 3ikjnm4y feet 7k78h5f .mpg.exe
  • %WINDIR%\assembly\tmp\black yton2v yo6djypsz cew2xnf4xc rg7tdu4 (gyta81s3l,2b0ay6o).avi.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\5i8wmj9 [bangbus] (liz).mpg.exe
  • %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\ uncut glans fcksd0samk .mpeg.exe
  • %HOMEPATH%\templates\5i8wmj9 6hg4sl 1n4kl7830jqa (etc82zq,sarah).mpeg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\dxzg91nv3 vegpvr k1tlhzdf 6hg4sl glans upfukdp8 (8e6fxld).mpg.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\peud38v 2yuliau w5t8cu4 f9kdqlk (liz).zip.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\yhfjge nude k1tlhzdf snidyfph (opgr3as).avi.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\thw5cms3 etorvhr 5i8wmj9 3ikjnm4y .rar.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\ snidyfph glans dvmdzwh8lo (liz).zip.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\dxzg91nv3 nude yo6djypsz [bangbus] titts boots .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\thw5cms3 nude w5t8cu4 hot (!) titts 50+ .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\sperm qfb04d7ux8iegf .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\dk4amn0 2yuliau k1tlhzdf f9kdqlk 0vzq1yfv .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\yhfjge yton2v k1tlhzdf uncut girly (etc82zq,opgr3as).mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\dk4amn0 vyfkljc16kq qfb04d7ux8iegf titts agl9tsu .rar.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\z7qips yton2v w5t8cu4 feet .mpg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\peud38v vyfkljc16kq mvakgcwi [milf] feet fishy (2b0ay6o).mpeg.exe
  • %WINDIR%\syswow64\fxstmp\yhfjge 2yuliau vg2zgnq f9kdqlk glans vvano0phq .rar.exe
  • %CommonProgramFiles%\microsoft shared\yo6djypsz girls latex .mpg.exe
  • %WINDIR%\winsxs\installtemp\tf1tq013 vegpvr k1tlhzdf a1swtsdhkhbf hotel .mpg.exe
  • %WINDIR%\temp\tf1tq013 5p4dftc 5i8wmj9 w5t8cu4 .mpg.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\xf0m998 yo6djypsz etorvhr snidyfph q4njwcdgux5bzomjnr .rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\tf1tq013 horse uncut hairy (gina).rar.exe
  • %ALLUSERSPROFILE%\templates\porn snidyfph .mpg.exe
  • C:\users\default\appdata\local\microsoft\windows\<INETFILES>\xf0m998 5i8wmj9 cew2xnf4xc fatfulz .avi.exe
  • C:\users\default\appdata\local\<INETFILES>\horse w5t8cu4 uncut cock 50+ .avi.exe
  • %ALLUSERSPROFILE%\templates\qppc8g gay girls ash .mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\cvj3ofi w5t8cu4 sperm 6hg4sl dvmdzwh8lo .mpg.exe
  • C:\users\default\appdata\roaming\microsoft\windows\templates\cvj3ofi cum 3ikjnm4y cock 8j1qjf .avi.exe
  • %TEMP%\black yo6djypsz 5i8wmj9 [free] shoes .zip.exe
  • %LOCALAPPDATA%\<INETFILES>\tf1tq013 w5t8cu4 big (sarah,0wlc1ae).rar.exe
  • %LOCALAPPDATA%low\mozilla\temp-{12c7f776-de07-4d8a-a6eb-93019fcb4f66}\thw5cms3 mvakgcwi obd4vccp8 f9kdqlk hole .mpg.exe
  • %LOCALAPPDATA%low\mozilla\temp-{28060726-42ae-4e49-b300-93149d394ff5}\z7qips 2yuliau f9kdqlk rg7tdu4 (2b0ay6o).rar.exe
  • %LOCALAPPDATA%low\mozilla\temp-{bc1f1f78-2666-4310-aef7-f6fd5ba4bc43}\peud38v mvakgcwi 6hg4sl feet (karin).avi.exe
  • C:\users\default\templates\p2yoszc mvakgcwi xxx a1swtsdhkhbf sm .mpeg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\qjsuuj51 2yuliau [bangbus] (sarah).rar.exe
  • %ALLUSERSPROFILE%\microsoft\windows\templates\qppc8g vg2zgnq yton2v [free] ash wifey .avi.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\xxx f9kdqlk ash hotel .avi.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\temp\black mvakgcwi girls e05pe26 yipsl1etyvv .mpeg.exe
  • %ProgramFiles%\dvd maker\shared\qppc8g etorvhr yton2v [bangbus] (ct00vwxo,sonja).mpeg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\gay vg2zgnq 3z6oda 7k78h5f .mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\yhfjge 5p4dftc 3z6oda ash .mpg.exe
  • %ProgramFiles%\microsoft office\office14\groove\xml files\space templates\asian sperm horse w5t8cu4 hole .rar.exe
  • %ProgramFiles%\microsoft office\templates\black 5i8wmj9 f9kdqlk cock 1wyga12mzc (etc82zq).mpeg.exe
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\xf0m998 vg2zgnq k1tlhzdf qfb04d7ux8iegf oltmowd .mpg.exe
  • %CommonProgramFiles%\microsoft shared\yton2v 2yuliau qfb04d7ux8iegf .rar.exe
  • %ProgramFiles%\windows journal\templates\qjsuuj51 vg2zgnq abj24u uncut feet .zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\2yuliau 5i8wmj9 big (sonja,ct00vwxo).zip.exe
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\vegpvr 2yuliau [bangbus] feet sweet .avi.exe
  • %CommonProgramFiles(x86)%\microsoft shared\mvakgcwi vg2zgnq 6hg4sl .avi.exe
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\ktrosnb sperm big yipsl1etyvv .avi.exe
  • %ProgramFiles(x86)%\windows sidebar\shared gadgets\xxx cew2xnf4xc jbu8c1 fcksd0samk .mpeg.exe
  • %ALLUSERSPROFILE%\microsoft\rac\temp\xxx a1swtsdhkhbf .rar.exe
  • %ProgramFiles%\windows sidebar\shared gadgets\qppc8g 5i8wmj9 cum w5t8cu4 vvano0phq .mpg.exe
  • %APPDATA%\microsoft\templates\qjsuuj51 sperm 5p4dftc 6hg4sl .rar.exe
  • %APPDATA%\microsoft\windows\templates\yo6djypsz 3z6oda n3mhrd7 .rar.exe
  • %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\temporary\etorvhr k1tlhzdf 6hg4sl 50+ .zip.exe
  • %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\temporary\vegpvr obd4vccp8 cew2xnf4xc wifey (jade).rar.exe
  • %WINDIR%\pla\templates\beast nude f9kdqlk legs (sandy).mpg.exe
  • %WINDIR%\security\templates\dxzg91nv3 horse w5t8cu4 snidyfph (jade,jenna).avi.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\<INETFILES>\2yuliau hot (!) feet wkdgiqz (sonja,rhpa1v).mpeg.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\local\temp\mvakgcwi snidyfph fcksd0samk .zip.exe
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templates\yhfjge nude w5t8cu4 snidyfph .avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\microsoft\windows\<INETFILES>\peud38v horse big boobs vkwhqow .zip.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\local\temp\peud38v mvakgcwi yton2v 3z6oda .avi.exe
  • %WINDIR%\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templates\4m7060 gay qfb04d7ux8iegf hotel (gina).avi.exe
  • %WINDIR%\syswow64\config\systemprofile\qjsuuj51 abj24u vg2zgnq girls e05pe26 .zip.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\cy0hhk4jm sperm uncut .mpeg.exe
  • %WINDIR%\syswow64\fxstmp\tl1xg0d yton2v w5t8cu4 vnm7bo .rar.exe
  • %WINDIR%\syswow64\ime\shared\asian gay uncut ash dvmdzwh8lo .rar.exe
  • %WINDIR%\syswow64\config\systemprofile\qjsuuj51 obd4vccp8 w5t8cu4 [bangbus] cock yipsl1etyvv (yeadrcq,0wlc1ae).zip.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\dk4amn0 abj24u cew2xnf4xc jbu8c1 upfukdp8 .rar.exe
  • %WINDIR%\syswow64\fxstmp\yhfjge horse cew2xnf4xc .mpeg.exe
  • %WINDIR%\microsoft.net\framework64\v4.0.30319\temporary asp.net files\dk4amn0 horse cum hot (!) 40+ (0wlc1ae,opgr3as).mpeg.exe
  • %WINDIR%\assembly\tmp\tl1xg0d 2yuliau 5p4dftc 6hg4sl .mpeg.exe
  • %WINDIR%\microsoft.net\framework\v4.0.30319\temporary asp.net files\mvakgcwi horse snidyfph hotel .zip.exe
  • %WINDIR%\assembly\temp\etorvhr big .mpg.exe
  • %HOMEPATH%\templates\cum hot (!) legs .zip.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\cvj3ofi 2yuliau beast cew2xnf4xc glans .zip.exe
  • %WINDIR%\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\vg2zgnq cum girls .mpg.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\ktrosnb 2yuliau snidyfph agl9tsu .mpeg.exe
  • %WINDIR%\assembly\gac_64\microsoft.grouppolicy.admtmpleditor.resources\abj24u uncut ash .mpg.exe
  • %WINDIR%\assembly\gac_64\microsoft.sharepoint.businessdata.administration.client\tl1xg0d yton2v horse 3z6oda agl9tsu .mpeg.exe
  • %WINDIR%\assembly\gac_msil\microsoft.sharepoint.businessdata.administration.client.intl\cy0hhk4jm vyfkljc16kq vg2zgnq 6hg4sl upfukdp8 .mpg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\dxzg91nv3 xxx a1swtsdhkhbf .mpeg.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_32\temp\zap9e41.tmp\p2yoszc nude yton2v cew2xnf4xc balls .avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\9saw1az3 xxx girls .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zap6b8e.tmp\asian 5i8wmj9 abj24u f9kdqlk latex .zip.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape291.tmp\peud38v mvakgcwi 6hg4sl boobs fcksd0samk (gyta81s3l,liz).avi.exe
  • %WINDIR%\assembly\nativeimages_v2.0.50727_64\temp\zape56e.tmp\4m7060 nude horse snidyfph 50+ .mpg.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_32\temp\vg2zgnq uncut .zip.exe
  • %WINDIR%\assembly\nativeimages_v4.0.30319_64\temp\5i8wmj9 yton2v w5t8cu4 dvmdzwh8lo (etc82zq).zip.exe
  • %WINDIR%\syswow64\ime\shared\qjsuuj51 k1tlhzdf cum uncut .mpg.exe
  • %WINDIR%\winsxs\installtemp\4m7060 yo6djypsz cew2xnf4xc titts (sonja,karin).rar.exe
Miscellaneous
Searches for the following windows
  • ClassName: 'Progman' WindowName: ''
  • ClassName: 'Proxy Desktop' WindowName: ''
Restarts the analyzed sample
Executes the following
  • '%WINDIR%\explorer.exe'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android