'<SYSTEM32>\attrib.exe' <Drive name for removable media>:\autorun.inf -s -r
'<SYSTEM32>\attrib.exe' <Drive name for removable media>:\autorun.inf +s +h +r
'<SYSTEM32>\attrib.exe' <Drive name for removable media>:\adtime.exe +s +h +r
'<SYSTEM32>\attrib.exe' c:\autorun.inf +s +h +r
'<SYSTEM32>\attrib.exe' <Drive name for removable media>:\adtime.exe -s -r
Modifies file system :
Creates the following files:
C:\programdata\runupdate.cmd
C:\programdata\updated
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\system[1].exe
C:\programdata\system.exe
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\command[1]
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\system[1].exe
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\command[1]
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\system[1].exe
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\command[1]
C:\programdata\autorun.inf
C:\programdata\sys2.cmd
C:\programdata\adtime.exe
C:\autorun.inf
C:\programdata\06-27-2013
C:\programdata\sys.cmd
C:\adtime.exe
Sets the 'hidden' attribute to the following files:
<Drive name for removable media>:\adtime.exe
<Drive name for removable media>:\autorun.inf
C:\adtime.exe
C:\autorun.inf
Deletes the following files:
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\system[1].exe
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\command[1]
%TEMP%\~DF3F5B.tmp
%TEMP%\~DFBFA0.tmp
%TEMP%\~DFE9C1.tmp
%TEMP%\~DF76D5.tmp
%TEMP%\~DF4C7E.tmp
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\system[1].exe
%HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\command[1]
Network activity:
Connects to:
'localhost':1041
'fu####s.allalla.com':80
'localhost':1037
'fu####s.allalla.com':21
TCP:
HTTP GET requests:
fu####s.allalla.com/system.exe
fu####s.allalla.com/command
UDP:
DNS ASK fu####s.allalla.com
Descargue Dr.Web para Android
Gratis por 3 meses
Todos los componentes de protección
Renovación de la demo a través de AppGallery/Google Pay
Si Vd. continúa usando este sitio web, esto significa que Vd. acepta el uso de archivos Cookie y otras tecnologías para que recabemos las estadísticas sobre los visitantes. Más información