Sets the 'hidden' attribute to the following files
%WINDIR%\1637425641\winenhw.exe
<Drive name for removable media>:\.lnk
<Drive name for removable media>:\autorun.inf
Network activity
TCP
HTTP GET requests
http://19#.#2.161.69/1.exe
http://19#.#2.161.69/2.exe
http://19#.#2.161.69/3.exe
http://19#.#2.161.69/4.exe
http://19#.#2.161.69/5.exe
http://19#.#2.161.69/6.exe
http://19#.#2.161.69/7.exe
Miscellaneous
Creates and executes the following
'%WINDIR%\1637425641\winenhw.exe'
'%TEMP%\3320729512.exe'
'%TEMP%\3939516910.exe'
'%TEMP%\3539940747.exe'
'%TEMP%\1447132115.exe'
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\glidescope_review_rev_010.docx", "<Drive name for removable media>:\\_\glidescope_review_rev_010.docx"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\thlps_keeper_mayer_1965.docx", "<Drive name for removable media>:\\_\thlps_keeper_mayer_1965.docx"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\weeklysheet1215.doc", "<Drive name for removable media>:\\_\weeklysheet1215.doc"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\fi51.doc", "<Drive name for removable media>:\\_\fi51.doc"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\ovp25012015.doc", "<Drive name for removable media>:\\_\ovp25012015.doc"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\february_catalogue__2015.doc", "<Drive name for removable media>:\\_\february_catalogue__2015.doc"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\TestCertificate.cer", "<Drive name for removable media>:\\_\TestCertificate.cer"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\testEE.cer", "<Drive name for removable media>:\\_\testEE.cer"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso.cer", "<Drive name for removable media>:\\_\contoso.cer"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKSamplePrivDeveloper.cer", "<Drive name for removable media>:\\_\SDKSamplePrivDeveloper.cer"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKFailsafeEmulator.cer", "<Drive name for removable media>:\\_\SDKFailsafeEmulator.cer"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contosoroot.cer", "<Drive name for removable media>:\\_\contosoroot.cer"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_192.bmp", "<Drive name for removable media>:\\_\dashBorder_192.bmp"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\coffee.bmp", "<Drive name for removable media>:\\_\coffee.bmp"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\default.bmp", "<Drive name for removable media>:\\_\default.bmp"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_96.bmp", "<Drive name for removable media>:\\_\dashBorder_96.bmp"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\archer.avi", "<Drive name for removable media>:\\_\archer.avi"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\000814251_video_01.avi", "<Drive name for removable media>:\\_\000814251_video_01.avi"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso_1.cer", "<Drive name for removable media>:\\_\contoso_1.cer"' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\holycrosschurchinstructions.docx", "<Drive name for removable media>:\\_\holycrosschurchinstructions.docx"' (with hidden window)
Executes the following
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\000814251_video_01.avi", "<Drive name for removable media>:\\_\000814251_video_01.avi"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\thlps_keeper_mayer_1965.docx", "<Drive name for removable media>:\\_\thlps_keeper_mayer_1965.docx"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\weeklysheet1215.doc", "<Drive name for removable media>:\\_\weeklysheet1215.doc"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\fi51.doc", "<Drive name for removable media>:\\_\fi51.doc"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\ovp25012015.doc", "<Drive name for removable media>:\\_\ovp25012015.doc"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\february_catalogue__2015.doc", "<Drive name for removable media>:\\_\february_catalogue__2015.doc"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\TestCertificate.cer", "<Drive name for removable media>:\\_\TestCertificate.cer"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso.cer", "<Drive name for removable media>:\\_\contoso.cer"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\testEE.cer", "<Drive name for removable media>:\\_\testEE.cer"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKFailsafeEmulator.cer", "<Drive name for removable media>:\\_\SDKFailsafeEmulator.cer"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contoso_1.cer", "<Drive name for removable media>:\\_\contoso_1.cer"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\SDKSamplePrivDeveloper.cer", "<Drive name for removable media>:\\_\SDKSamplePrivDeveloper.cer"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\contosoroot.cer", "<Drive name for removable media>:\\_\contosoroot.cer"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_192.bmp", "<Drive name for removable media>:\\_\dashBorder_192.bmp"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\coffee.bmp", "<Drive name for removable media>:\\_\coffee.bmp"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\default.bmp", "<Drive name for removable media>:\\_\default.bmp"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\dashBorder_96.bmp", "<Drive name for removable media>:\\_\dashBorder_96.bmp"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\archer.avi", "<Drive name for removable media>:\\_\archer.avi"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\glidescope_review_rev_010.docx", "<Drive name for removable media>:\\_\glidescope_review_rev_010.docx"
'%WINDIR%\syswow64\cmd.exe' /c move /y "<Drive name for removable media>:\\holycrosschurchinstructions.docx", "<Drive name for removable media>:\\_\holycrosschurchinstructions.docx"
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more