JavaScript support is required for our site to be fully operational in your browser.
Trojan.Siggen33.58834
Added to the Dr.Web virus database:
2026-08-29
Virus description added:
2026-08-30
Technical Information
To ensure autorun and distribution
Modifies the following registry keys
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_31a3ca.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_a6c3f1.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_33a722.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_6f8c60.exe"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '5cd3252b3fe5b98309' = '"%TEMP%\Server_b0539f.exe"'
Creates or modifies the following files
<SYSTEM32>\tasks\5cd3252b3fe5b98309
%APPDATA%\microsoft\windows\start menu\programs\startup\5cd3252b3fe5b98309.lnk
Malicious functions
Patches code
in AMSI dll
ouugg.exe process, Amsi.dll module
msedge.exe process, Amsi.dll module
server.exe process, Amsi.dll module
msedge_5303139015514ef3a0de5c0a65419287.exe process, Amsi.dll module
msedge_9bc52c25a4794617a596d5add5d89960.exe process, Amsi.dll module
msedge_6438f4f7353e437d8253a2201f504154.exe process, Amsi.dll module
msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe process, Amsi.dll module
msedge_77b4aab92dd84e0697ea512fe440b416.exe process, Amsi.dll module
msedge_63371e751f7d404c83389a9bfcbfe648.exe process, Amsi.dll module
msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe process, Amsi.dll module
msedge_ca4184e4b46246e387fde527181943c8.exe process, Amsi.dll module
msedge_79d7ec298b494368be8752d6beb43f32.exe process, Amsi.dll module
server_31a3ca.exe process, Amsi.dll module
server_a6c3f1.exe process, Amsi.dll module
msedge_1c41a166634745f4803be93a4149b4a6.exe process, Amsi.dll module
msedge_d7580d40c0b64f558f95a39d5681ad72.exe process, Amsi.dll module
msedge_b65f05dff6de4f1395e77f2507b24805.exe process, Amsi.dll module
server_33a722.exe process, Amsi.dll module
msedge_c38729d762c44ef8bd1231b036b8a55b.exe process, Amsi.dll module
server_6f8c60.exe process, Amsi.dll module
msedge_7a65bac193d04b1182d5e05f79d98445.exe process, Amsi.dll module
msedge_e8798c10777a4763ab3d8a0280483bf6.exe process, Amsi.dll module
msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe process, Amsi.dll module
msedge_9e1697c9b03844129bd7947a26ac45f8.exe process, Amsi.dll module
server_b0539f.exe process, Amsi.dll module
msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe process, Amsi.dll module
msedge_77c1271028734b709e2d4b91c06f6e7b.exe process, Amsi.dll module
msedge_cc1c81f91d3d4e2eb43f6d802ea21463.exe process, Amsi.dll module
msedge_66ee14d019ab4e9ba18a7e64980f5188.exe process, Amsi.dll module
msedge_73229473f4bd42da9a99097177d4f10e.exe process, Amsi.dll module
server_91c6a0.exe process, Amsi.dll module
server_c2c7d8.exe process, Amsi.dll module
server_590971.exe process, Amsi.dll module
server_e2fd14.exe process, Amsi.dll module
server_0ca7e2.exe process, Amsi.dll module
server_5dcc28.exe process, Amsi.dll module
server_79ef40.exe process, Amsi.dll module
in NTDLL dll
ouugg.exe process, ntdll.dll module
msedge.exe process, ntdll.dll module
server.exe process, ntdll.dll module
msedge_5303139015514ef3a0de5c0a65419287.exe process, ntdll.dll module
msedge_9bc52c25a4794617a596d5add5d89960.exe process, ntdll.dll module
msedge_6438f4f7353e437d8253a2201f504154.exe process, ntdll.dll module
msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe process, ntdll.dll module
msedge_77b4aab92dd84e0697ea512fe440b416.exe process, ntdll.dll module
msedge_63371e751f7d404c83389a9bfcbfe648.exe process, ntdll.dll module
msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe process, ntdll.dll module
msedge_ca4184e4b46246e387fde527181943c8.exe process, ntdll.dll module
msedge_79d7ec298b494368be8752d6beb43f32.exe process, ntdll.dll module
server_31a3ca.exe process, ntdll.dll module
server_a6c3f1.exe process, ntdll.dll module
msedge_1c41a166634745f4803be93a4149b4a6.exe process, ntdll.dll module
msedge_d7580d40c0b64f558f95a39d5681ad72.exe process, ntdll.dll module
msedge_b65f05dff6de4f1395e77f2507b24805.exe process, ntdll.dll module
server_33a722.exe process, ntdll.dll module
msedge_c38729d762c44ef8bd1231b036b8a55b.exe process, ntdll.dll module
server_6f8c60.exe process, ntdll.dll module
msedge_7a65bac193d04b1182d5e05f79d98445.exe process, ntdll.dll module
msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe process, ntdll.dll module
msedge_e8798c10777a4763ab3d8a0280483bf6.exe process, ntdll.dll module
msedge_9e1697c9b03844129bd7947a26ac45f8.exe process, ntdll.dll module
server_b0539f.exe process, ntdll.dll module
msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe process, ntdll.dll module
msedge_77c1271028734b709e2d4b91c06f6e7b.exe process, ntdll.dll module
msedge_cc1c81f91d3d4e2eb43f6d802ea21463.exe process, ntdll.dll module
msedge_66ee14d019ab4e9ba18a7e64980f5188.exe process, ntdll.dll module
msedge_73229473f4bd42da9a99097177d4f10e.exe process, ntdll.dll module
server_91c6a0.exe process, ntdll.dll module
server_e2fd14.exe process, ntdll.dll module
server_c2c7d8.exe process, ntdll.dll module
server_590971.exe process, ntdll.dll module
server_0ca7e2.exe process, ntdll.dll module
server_5dcc28.exe process, ntdll.dll module
server_79ef40.exe process, ntdll.dll module
Modifies file system
Creates the following files
%LOCALAPPDATA%\microsoft\edge\application\msedge.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
%TEMP%\server.exe
%TEMP%\msedge_5303139015514ef3a0de5c0a65419287.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server.exe.log
%TEMP%\msedge_9bc52c25a4794617a596d5add5d89960.exe
%TEMP%\msedge_6438f4f7353e437d8253a2201f504154.exe
%TEMP%\msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe
%TEMP%\msedge_77b4aab92dd84e0697ea512fe440b416.exe
%TEMP%\msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe
%TEMP%\msedge_63371e751f7d404c83389a9bfcbfe648.exe
%TEMP%\msedge_ca4184e4b46246e387fde527181943c8.exe
%TEMP%\msedge_79d7ec298b494368be8752d6beb43f32.exe
%TEMP%\server_31a3ca.exe
%TEMP%\server_a6c3f1.exe
%TEMP%\msedge_d7580d40c0b64f558f95a39d5681ad72.exe
%TEMP%\msedge_1c41a166634745f4803be93a4149b4a6.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_31a3ca.exe.log
%TEMP%\msedge_b65f05dff6de4f1395e77f2507b24805.exe
%TEMP%\msedge_c38729d762c44ef8bd1231b036b8a55b.exe
%TEMP%\server_33a722.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_a6c3f1.exe.log
%TEMP%\5cd3252b\vault.dat
%TEMP%\server_6f8c60.exe
%TEMP%\msedge_7a65bac193d04b1182d5e05f79d98445.exe
%TEMP%\msedge_e8798c10777a4763ab3d8a0280483bf6.exe
%TEMP%\msedge_9e1697c9b03844129bd7947a26ac45f8.exe
%TEMP%\msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_33a722.exe.log
%TEMP%\server_b0539f.exe
%TEMP%\msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe
%LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\server_6f8c60.exe.log
Sets the 'hidden' attribute to the following files
%LOCALAPPDATA%\microsoft\edge\application\msedge.exe
%TEMP%\server.exe
%APPDATA%\microsoft\windows\start menu\programs\startup\5cd3252b3fe5b98309.lnk
%TEMP%\server_31a3ca.exe
%TEMP%\server_a6c3f1.exe
%TEMP%\server_33a722.exe
%TEMP%\server_6f8c60.exe
%TEMP%\server_b0539f.exe
Deletes following files that it created itself
%LOCALAPPDATA%\microsoft\edge\application\msedge.exe
%TEMP%\server.exe
Substitutes the following files
Miscellaneous
Creates and executes the following
'%LOCALAPPDATA%\microsoft\edge\application\msedge.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server.exe' --edge-sub
'%TEMP%\server.exe'
'%TEMP%\msedge_5303139015514ef3a0de5c0a65419287.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_9bc52c25a4794617a596d5add5d89960.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_6438f4f7353e437d8253a2201f504154.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_3fbc7b62b9b34ce1bb079e70d5862b85.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_77b4aab92dd84e0697ea512fe440b416.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_5eb8f8d511b94af284ab6ded7d8861f2.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_63371e751f7d404c83389a9bfcbfe648.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_ca4184e4b46246e387fde527181943c8.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_79d7ec298b494368be8752d6beb43f32.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_31a3ca.exe' --edge-sub
'%TEMP%\server_a6c3f1.exe' --edge-sub
'%TEMP%\server_31a3ca.exe'
'%TEMP%\msedge_d7580d40c0b64f558f95a39d5681ad72.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_1c41a166634745f4803be93a4149b4a6.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_a6c3f1.exe'
'%TEMP%\msedge_b65f05dff6de4f1395e77f2507b24805.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_c38729d762c44ef8bd1231b036b8a55b.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_33a722.exe' --edge-sub
'%TEMP%\server_6f8c60.exe' --edge-sub
'%TEMP%\server_33a722.exe'
'%TEMP%\msedge_7a65bac193d04b1182d5e05f79d98445.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_9e1697c9b03844129bd7947a26ac45f8.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_e8798c10777a4763ab3d8a0280483bf6.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\msedge_3fa5ee81df4e42acb12d7ba1b028c731.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_6f8c60.exe'
'%TEMP%\server_b0539f.exe' --edge-sub
'%TEMP%\msedge_3012536f7f8040c6b23ae7cfa5b272b1.exe' --type=utility --utility-sub-type=network.mojom.NetworkService /prefetch:8 --no-sandbox --edge-sub
'%TEMP%\server_b0539f.exe'
Executes the following
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server.exe"; try{ $fObj=Set-WmiInstance -Namespace root\subscript...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_31a3ca.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_31a3ca.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_a6c3f1.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_a6c3f1.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_33a722.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_33a722.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_6f8c60.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_6f8c60.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_b0539f.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_b0539f.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_91c6a0.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_c2c7d8.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_590971.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_e2fd14.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_91c6a0.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_590971.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_c2c7d8.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_e2fd14.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_5dcc28.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_0ca7e2.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\schtasks.exe' /create /tn "5cd3252b3fe5b98309" /tr "'%TEMP%\Server_79ef40.exe'" /sc onlogon /rl highest /f
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_0ca7e2.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_5dcc28.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "$f='WinMgr_5cd325'; $c="C:\\Users\\user\\AppData\\Local\\Temp\\Server_79ef40.exe"; try{ $fObj=Set-WmiInstance -Namespace root\su...
Curing recommendations
Windows
macOS
Linux
Android
If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space .
If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.
If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
Switch off your device and turn it on as normal.
Find out more about Dr.Web for Android
欢迎下载 Dr.Web for Android
免费3个月
可使用所有保护组件
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息
OK