Для корректной работы нашего сайта необходимо включить поддержку JavaScript в вашем браузере.
Trojan.Siggen32.45871
Добавлен в вирусную базу Dr.Web:
2026-05-29
Описание добавлено:
2026-05-31
Technical Information
Malicious functions
To complicate detection of its presence in the operating system,
adds antivirus exclusion:
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath 'C:\Users'"
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'"
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '<SYSTEM32>'"
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionProcess 'Dism.exe'"
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionProcess 'where.exe'"
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionPath %ALLUSERSPROFILE%
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionPath C:\Users
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionPath <SYSTEM32>
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionProcess Dism.exe
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionProcess where.exe
Injects code into
the following system processes:
Patches code
in dll
dism.exe process, IPHLPAPI.DLL module
Modifies file system
Creates the following files
Deletes following files that it created itself
%ProgramFiles%\printerdoctor\souths.msi
%TEMP%\is-3sy4ilq3a7.tmp\_isetup\is-tjjru7m7u0.tmp\ada.zip
%TEMP%\is-3sy4ilq3a7.tmp\_isetup\_is7z.dll
%TEMP%\is-3sy4ilq3a7.tmp\_isetup\_isdecmp.dll
%TEMP%\is-sliml89jtj.tmp\<File name>.tmp
Moves the following files
from %TEMP%\is-3sy4ilq3a7.tmp\_isetup\is-tjjru7m7u0.tmp\is-tuch8mvqsg.tmp to %TEMP%\is-3sy4ilq3a7.tmp\_isetup\is-tjjru7m7u0.tmp\ada.zip
from %ProgramFiles%\printerdoctor\is-9wbpj8pclo.tmp to %ProgramFiles%\printerdoctor\unins000.exe
from %ProgramFiles%\printerdoctor\is-zpmjgoi6tu.tmp to %ProgramFiles%\printerdoctor\souths.msi
from %ProgramFiles%\printerdoctor\is-vr3v7moqh8.tmp to %ProgramFiles%\printerdoctor\7.html
from %ProgramFiles%\printerdoctor\7_files\is-vucaiz18jd.tmp to %ProgramFiles%\printerdoctor\7_files\3b24b51bf11404089c4d66acd0c612539c77e7e7
from %ProgramFiles%\printerdoctor\7_files\is-aoiymcd51x.tmp to %ProgramFiles%\printerdoctor\7_files\3ce5793e0e2ab9e3dbc03c1cb23d538c8b86f1b7
from %ProgramFiles%\printerdoctor\7_files\is-ep5j55tkal.tmp to %ProgramFiles%\printerdoctor\7_files\5419.5fab78b2.css
from %ProgramFiles%\printerdoctor\7_files\is-acbsaodq9w.tmp to %ProgramFiles%\printerdoctor\7_files\60bfd4ad01d8d9142d88c3c0b73cea36bf327ea7
from %ProgramFiles%\printerdoctor\7_files\is-ofgq60oucb.tmp to %ProgramFiles%\printerdoctor\7_files\ab676161000051742113c21548ddabe305961c28
from %ProgramFiles%\printerdoctor\7_files\is-jcv7mjzttk.tmp to %ProgramFiles%\printerdoctor\7_files\ab6761610000517421a213a4fe1a6f9b45d3f7f9
from %ProgramFiles%\printerdoctor\7_files\is-d44p6opabv.tmp to %ProgramFiles%\printerdoctor\7_files\ab6761610000517469287c3f1b150bbead642499
from %ProgramFiles%\printerdoctor\7_files\is-j6sfbeaotm.tmp to %ProgramFiles%\printerdoctor\7_files\ab6761610000517487b0c6a4811964bd1b7d701f
from %ProgramFiles%\printerdoctor\7_files\is-qv89v3weaz.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616100005174ae81417d966e209b735b1160
from %ProgramFiles%\printerdoctor\7_files\is-xn05vz2bbq.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616100005174db59e1c017a93648b119f0cc
from %ProgramFiles%\printerdoctor\7_files\is-4iwjejgsrq.tmp to %ProgramFiles%\printerdoctor\7_files\ab6761610000f178d8139dde094f1b2609aeec15
from %ProgramFiles%\printerdoctor\7_files\is-sf1hhceg1z.tmp to %ProgramFiles%\printerdoctor\7_files\ab6761610000f178eaca358712b3fe4ed9814640
from %ProgramFiles%\printerdoctor\7_files\is-vee1eapxg9.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02039b95b846d039d78a2ca6a1
from %ProgramFiles%\printerdoctor\7_files\is-ucjvwwb33v.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e0204f7d57adcdf0c2f2decf4c4
from %ProgramFiles%\printerdoctor\7_files\is-y059huqf3i.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02055b322b3efb78f1082bc799
from %ProgramFiles%\printerdoctor\7_files\is-pwdikmtr2v.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e020cb65bb81eebf25f36de2999
from %ProgramFiles%\printerdoctor\7_files\is-skc60s0q7l.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02105086205323b81177c709d4
from %ProgramFiles%\printerdoctor\7_files\is-2xolwhk09n.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e021ddafc3aa34ad883ff27418f
from %ProgramFiles%\printerdoctor\7_files\is-j768ixgyzm.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02214f0bd9dc1ed0c65ae81760
from %ProgramFiles%\printerdoctor\7_files\is-8m6ejq1jjz.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e0223cc0f0a925845a3de4aca38
from %ProgramFiles%\printerdoctor\7_files\is-attn8d77j4.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e022c1f1f4512c99b738110035a
from %ProgramFiles%\printerdoctor\7_files\is-vfwn9dcpzv.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e022c90628cf534a426e3687b47
from %ProgramFiles%\printerdoctor\7_files\is-7iovucrilc.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e0231eb25ed004dd2e9b6f35d4f
from %ProgramFiles%\printerdoctor\7_files\is-d48aap3tar.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02374f450ee0a6c2036ee01b89
from %ProgramFiles%\printerdoctor\7_files\is-6ji0p1ytkj.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e023b67e4695d120ebfe9ca359a
from %ProgramFiles%\printerdoctor\7_files\is-a4zef6zb7i.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e024117e531f63855d072059d6e
from %ProgramFiles%\printerdoctor\7_files\is-s0za67qrfa.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e025c3742c1e50f5f272c92ae59
from %ProgramFiles%\printerdoctor\7_files\is-tslg41vrbt.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e0265af8f4075f3a6b96866e611
from %ProgramFiles%\printerdoctor\7_files\is-hntrewi3lg.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02685b70d40ae9fffdcc242a0a
from %ProgramFiles%\printerdoctor\7_files\is-c8y1f9n2hj.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e026a4175046856b90a9b5d67a1
from %ProgramFiles%\printerdoctor\7_files\is-fa7idqiw4n.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02897077217561a52898209cc5
from %ProgramFiles%\printerdoctor\7_files\is-bymg761usw.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e028a2ce3f148f57584269c3782
from %ProgramFiles%\printerdoctor\7_files\is-fvk31923c1.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02907f0d0884466966d6546767
from %ProgramFiles%\printerdoctor\7_files\is-gql72poc7s.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e029435ca4eaef0847e80d04b02
from %ProgramFiles%\printerdoctor\7_files\is-9vft724xa6.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e029564dd0f283e0a16440063c7
from %ProgramFiles%\printerdoctor\7_files\is-4mmm5ddllh.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02979637dbe8b71de7c13ab5cf
from %ProgramFiles%\printerdoctor\7_files\is-f7efc3wrl4.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02992d0e6aeb59f587a1e81ac8
from %ProgramFiles%\printerdoctor\7_files\is-61hao9ajsl.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e0299e49fe1e935d3d724627211
from %ProgramFiles%\printerdoctor\7_files\is-dngxmlmmpx.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e029e6f77c2aa67cab83fb412be
from %ProgramFiles%\printerdoctor\7_files\is-6yb8iushq3.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e029e8e0df48ff95de8d014f0b1
from %ProgramFiles%\printerdoctor\7_files\is-99yqr59s5u.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e029fefaca04a80b8b221954573
from %ProgramFiles%\printerdoctor\7_files\is-8tagjudlpr.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02ae0e62cc351978ad5203fcfa
from %ProgramFiles%\printerdoctor\7_files\is-98fen9kw38.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02b7fe0714ccb2ad8c61303911
from %ProgramFiles%\printerdoctor\7_files\is-is5a52aghn.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02c02ced489483042f820ad4b0
from %ProgramFiles%\printerdoctor\7_files\is-vxmnjpsps5.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02c093f4dd308ad9c41e20eee8
from %ProgramFiles%\printerdoctor\7_files\is-2zdb3rmuc2.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02c8da7970ca45b99fb2c51777
from %ProgramFiles%\printerdoctor\7_files\is-d2w3oh57ra.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02cf491ef0ed4e0d587b571724
from %ProgramFiles%\printerdoctor\7_files\is-fx30oht1e0.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02dd64809bbf416dde80e80f99
from %ProgramFiles%\printerdoctor\7_files\is-pb50e6tjeu.tmp to %ProgramFiles%\printerdoctor\7_files\ab67616d00001e02e2829416e5011fb749cc3fde
from %ProgramFiles%\printerdoctor\7_files\is-o4eyx6vnsm.tmp to %ProgramFiles%\printerdoctor\7_files\adsct
from %ProgramFiles%\printerdoctor\7_files\is-jj0sh6utoa.tmp to %ProgramFiles%\printerdoctor\7_files\adsct(1)
from %ProgramFiles%\printerdoctor\7_files\is-vvluiy8x91.tmp to %ProgramFiles%\printerdoctor\7_files\anchor.html
from %ProgramFiles%\printerdoctor\7_files\is-hr2lxuhx8j.tmp to %ProgramFiles%\printerdoctor\7_files\c2c1b3612f38b206411173c168b912d306b5c196
from %ProgramFiles%\printerdoctor\7_files\is-r31dj37u5s.tmp to %ProgramFiles%\printerdoctor\7_files\cast_framework.js
from %ProgramFiles%\printerdoctor\7_files\is-9zcuioeo1x.tmp to %ProgramFiles%\printerdoctor\7_files\cast_sender(1).js
from %ProgramFiles%\printerdoctor\7_files\is-33ner5rjpt.tmp to %ProgramFiles%\printerdoctor\7_files\cast_sender.js
from %ProgramFiles%\printerdoctor\7_files\is-66u6fkpbgm.tmp to %ProgramFiles%\printerdoctor\7_files\dwp-feedback-bar.2f1f7eb4.css
from %ProgramFiles%\printerdoctor\7_files\is-fabr1zkx99.tmp to %ProgramFiles%\printerdoctor\7_files\dwp-now-playing-bar.88eac62f.css
from %ProgramFiles%\printerdoctor\7_files\is-j3awo4fcwh.tmp to %ProgramFiles%\printerdoctor\7_files\dwp-panel-section.db8179d5.css
from %ProgramFiles%\printerdoctor\7_files\is-14dfrrpmk3.tmp to %ProgramFiles%\printerdoctor\7_files\dwp-top-bar.2d1e7227.css
from %ProgramFiles%\printerdoctor\7_files\is-ic8beyi6hl.tmp to %ProgramFiles%\printerdoctor\7_files\dwp-video-player.a92a1bf1.css
from %ProgramFiles%\printerdoctor\7_files\is-2c8yazcjuk.tmp to %ProgramFiles%\printerdoctor\7_files\dwp-watch-feed-view-container.39b09463.css
from %ProgramFiles%\printerdoctor\7_files\is-2urkuz9dh3.tmp to %ProgramFiles%\printerdoctor\7_files\enterprise.js
from %ProgramFiles%\printerdoctor\7_files\is-c1fykny88m.tmp to %ProgramFiles%\printerdoctor\7_files\gtm.96d60fd6.js
from %ProgramFiles%\printerdoctor\7_files\is-p2p7no8d28.tmp to %ProgramFiles%\printerdoctor\7_files\heap_config.js
from %ProgramFiles%\printerdoctor\7_files\is-h6t6iiddaw.tmp to %ProgramFiles%\printerdoctor\7_files\listening-stats-modal.8c1b8d24.css
from %ProgramFiles%\printerdoctor\7_files\is-ptzrow59if.tmp to %ProgramFiles%\printerdoctor\7_files\otsdkstub.js
from %ProgramFiles%\printerdoctor\7_files\is-z2fkts96pm.tmp to %ProgramFiles%\printerdoctor\7_files\ot_company_logo.png
from %ProgramFiles%\printerdoctor\7_files\is-48c4op1wkf.tmp to %ProgramFiles%\printerdoctor\7_files\powered_by_logo.svg
from %ProgramFiles%\printerdoctor\7_files\is-sk6ddbzv75.tmp to %ProgramFiles%\printerdoctor\7_files\retargeting-pixels.02346b5d.js
from %ProgramFiles%\printerdoctor\7_files\is-qjah73aq4g.tmp to %ProgramFiles%\printerdoctor\7_files\saved_resource(1).html
from %ProgramFiles%\printerdoctor\7_files\is-yh8hrsax23.tmp to %ProgramFiles%\printerdoctor\7_files\saved_resource(2).html
from %ProgramFiles%\printerdoctor\7_files\is-bo37rm4s84.tmp to %ProgramFiles%\printerdoctor\7_files\saved_resource.html
from %ProgramFiles%\printerdoctor\7_files\is-l2g4z5h7sa.tmp to %ProgramFiles%\printerdoctor\7_files\sync.min.js
from %ProgramFiles%\printerdoctor\7_files\is-d6upsac270.tmp to %ProgramFiles%\printerdoctor\7_files\uwt.js
from %ProgramFiles%\printerdoctor\7_files\is-loqu970i1s.tmp to %ProgramFiles%\printerdoctor\7_files\xpui-root-dialogs.24c65f8c.css
from %ProgramFiles%\printerdoctor\7_files\is-7qpjc5aca5.tmp to %ProgramFiles%\printerdoctor\7_files\xpui-routes-track-v2.3643c9d7.css
from %ProgramFiles%\printerdoctor\7_files\is-8qo3jvn2oh.tmp to %ProgramFiles%\printerdoctor\7_files\xpui-routes-your-library-x.d077bf4b.css
from %ProgramFiles%\printerdoctor\is-5wc139pu4i.tmp to %ProgramFiles%\printerdoctor\shadow@2x.png
Network activity
Connects to
'do#####.##.ap-east-1.amazonaws.com':443
'ba##u.com':443
TCP
HTTP GET requests
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?78##############
Other
'do#####.##.ap-east-1.amazonaws.com':443
'ba##u.com':443
UDP
DNS ASK do#####.##.ap-east-1.amazonaws.com
DNS ASK ba##u.com
DNS ASK hk.##7imx.net
Miscellaneous
Creates and executes the following
'%TEMP%\is-sliml89jtj.tmp\<File name>.tmp' /SL5="$F01BA,3581697,1006592,<Full path to file>"
Executes the following
'%WINDIR%\syswow64\msiexec.exe' /i "%ProgramFiles%\PrinterDoctor\souths.msi" /qn
'<SYSTEM32>\dism.exe'
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath 'C:\Users'"' (with hidden window)
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'"' (with hidden window)
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '<SYSTEM32>'"' (with hidden window)
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionProcess 'Dism.exe'"' (with hidden window)
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionProcess 'where.exe'"' (with hidden window)
Рекомендации по лечению
Windows
macOS
Linux
Android
В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store .
Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light . Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
выключите устройство и включите его в обычном режиме.
Подробнее о Dr.Web для Android
Демо бесплатно на 14 дней
Выдаётся при установке
Поздравляем!
Обменяйте их на скидку до 50% на покупку Dr.Web.
Получить скидку
Скачайте Dr.Web для Android
Бесплатно на 3 месяца
Все компоненты защиты
Продление демо через AppGallery/Google Pay
Если Вы продолжите использование данного сайта, это означает, что Вы даете согласие на использование нами Cookie-файлов и иных технологий по сбору статистических сведений о посетителях. Подробнее
OK