Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Packed.79

Added to the Dr.Web virus database: 2018-05-09

Virus description added:

Technical Information

Malicious functions:
Launches processes:
  • tty
  • stty size
  • stty raw -echo
  • stty -raw echo
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/installkit /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/unpack.tcl -- /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/unpack.ini
  • xdg-desktop-menu install --novendor /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/364C48A9-4F05-489A-A981-F5F75455A2C8-NDK2.0_DM648_Ethernet_Driver_Patch.directory /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/NDK2.0_DM648_eth_drv_patch-uninstall.desktop
  • whoami
  • basename /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/364C48A9-4F05-489A-A981-F5F75455A2C8-NDK2.0_DM648_Ethernet_Driver_Patch.directory
  • cut -d . -f 1
  • sed s/:/ /g
  • mktemp /tmp/tmp.XXXXXXXXXX
  • cat /tmp/tmp.rfdhFS6Hb7
  • basename /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/NDK2.0_DM648_eth_drv_patch-uninstall.desktop
  • grep ^NDK2.0_DM648_eth_drv_patch-uninstall.desktop$ /tmp/tmp.rfdhFS6Hb7
  • rm -f /tmp/tmp.rfdhFS6Hb7
  • chmod 0644 /tmp/tmp.KRwrC8xAtO
  • mkdir -p /applications-merged
  • cp /tmp/tmp.KRwrC8xAtO /applications-merged/364C48A9-4F05-489A-A981-F5F75455A2C8-NDK2.menu
  • rm -f /tmp/tmp.KRwrC8xAtO
Performs operations with the file system:
Modifies file access rights:
  • /tmp/tclifvGI1
  • /tmp/tclt1R67e
  • /tmp/tcl1212392892684.tmp
  • /var/tmp/tcl1212392892684.tmp
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin/xdg-desktop-icon
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin/xdg-desktop-menu
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/installkit
  • /tmp/tclegwgmk
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib/hal
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib/hal/evmdm648
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648/ethss_dm648
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648/ethss_dm648/inc
  • /usr/local/NDK2.0_DM648_eth_drv_patch/uninstall
  • /tmp/tmp.KRwrC8xAtO
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837
Creates folders:
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin
  • /usr/local/NDK2.0_DM648_eth_drv_patch
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib/hal
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib/hal/evmdm648
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648/ethss_dm648
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648/ethss_dm648/inc
  • /applications-merged
  • /var/lib/installjammer
  • /var/lib/installjammer/364C48A9-4F05-489A-A981-F5F75455A2C8
Deletes folders:
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin
Creates or modifies files:
  • /tmp/tclifvGI1
  • /tmp/tclwYly97
  • /tmp/tclt1R67e
  • /tmp/tcl1212392892684.tmp
  • /var/tmp/tcl1212392892684.tmp
  • /tmp/tclz55dCs
  • /tmp/tclz55dCs (deleted)
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin/xdg-desktop-icon
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin/xdg-desktop-menu
  • /tmp/tcljFbtwH
  • /tmp/tcljFbtwH (deleted)
  • /tmp/tcljJZeHW
  • /tmp/tcljJZeHW (deleted)
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/installkit
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/unpack.ini
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/unpack.tcl
  • /tmp/tclCYBHOe
  • /tmp/tclegwgmk
  • /tmp/tcllcHWRE
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/run.log
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib/hal/evmdm648/hal_eth_dm648.lib
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/lib/hal/evmdm648/hal_eth_dm648e.lib
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648/ethss_dm648/ethdriver.c
  • /usr/local/NDK2.0_DM648_eth_drv_patch/packages/ti/ndk/src/hal/evmdm648/ethss_dm648/inc/nimu_eth.h
  • /usr/local/NDK2.0_DM648_eth_drv_patch/NDK2.0_DM648_ethernet_driver_patch.txt
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/.done
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/uninstall.tcl
  • /usr/local/NDK2.0_DM648_eth_drv_patch/uninstall
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/NDK2.0_DM648_eth_drv_patch-uninstall.desktop
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/364C48A9-4F05-489A-A981-F5F75455A2C8-NDK2.0_DM648_Ethernet_Driver_Patch.directory
  • /tmp/tclOx23ZR
  • /tmp/tmp.rfdhFS6Hb7
  • /tmp/tmp.KRwrC8xAtO
  • /applications-merged/364C48A9-4F05-489A-A981-F5F75455A2C8-NDK2.menu
  • /tmp/tclOx23ZR (deleted)
  • /tmp/tcloptohC
  • /tmp/tcloptohC (deleted)
  • /tmp/tclsa7V9m
  • /tmp/tclsa7V9m (deleted)
  • /var/lib/installjammer/364C48A9-4F05-489A-A981-F5F75455A2C8/C3B2EF0B-4CC5-7E82-CC5B-0A3FB8E17DA3.ver
  • /var/lib/installjammer/364C48A9-4F05-489A-A981-F5F75455A2C8/C3B2EF0B-4CC5-7E82-CC5B-0A3FB8E17DA3.log
  • /var/lib/installjammer/364C48A9-4F05-489A-A981-F5F75455A2C8/C3B2EF0B-4CC5-7E82-CC5B-0A3FB8E17DA3.info
Deletes files:
  • /tmp/tclifvGI1
  • /tmp/tclwYly97
  • /tmp/tclt1R67e
  • /tmp/tcl1212392892684.tmp
  • /var/tmp/tcl1212392892684.tmp
  • /tmp/tclz55dCs
  • /tmp/tcljFbtwH
  • /tmp/tcljJZeHW
  • /tmp/tclCYBHOe
  • /tmp/tclegwgmk
  • /tmp/tcllcHWRE
  • /usr/local/NDK2.0_DM648_eth_drv_patch/uninstall
  • /tmp/tclOx23ZR
  • /tmp/tmp.rfdhFS6Hb7
  • /tmp/tmp.KRwrC8xAtO
  • /tmp/tcloptohC
  • /tmp/tclsa7V9m
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/364C48A9-4F05-489A-A981-F5F75455A2C8-NDK2.0_DM648_Ethernet_Driver_Patch.directory
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/uninstall.tcl
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin/xdg-desktop-icon
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/bin/xdg-desktop-menu
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/NDK2.0_DM648_eth_drv_patch-uninstall.desktop
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/run.log
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/installkit
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/.done
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/unpack.tcl
  • /tmp/ijtmp_41E11356-6797-09EB-77B9-B25EF02DC837/unpack.ini

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number