What is attrib.exe?
attrib.exe is a legitimate file process. It is developed by Microsoft Corporation. This process is known as Attribute Utility and it belongs to Windows Operating System. You can locate the file in C:\Windows\Sytem32. The virus is created by malware authors and is named after attrib.exe file.
Affected Platform: Windows OS
How to check if your computer is infected with attrib.exe malware?
Keep an eye for the following symptoms to check if your PC is infected with attrib.exe malware:
- Unstable internet connection
- Browser redirects to unwanted websites
- PC performance slows down
- Browser is bombarded with hordes of popup ads
- System screen freezes repeatedly
If you find any of the above mentioned symptoms, take the following steps to be sure about the malware infection:
- Press CTRL+ALT+DEL keys to open Task Manager.
- Go to the process tab and right-click on the attrib.exe file and open its location.
If the file is located outside C:\Windows\Sytem32, then you should take measures to get rid of the malware.
How to remove attrib.exe malware from system with Comodo Cleaning Essentials?
Comodo Cleaning Essentials (CCE) incorporates antivirus software with unique features like auto-sandboxing to identify and obstruct every suspicious process running on an endpoint with a single click. To remove attrib.exe malware using CCE, follow the steps mentioned below:
Step 1: Download the CCE suite.
Step 2: To start the application, double-click on the CCE.exe file.
Step 3: It then probes the antivirus to initiate a full system scan to identify and remove any existing malicious files.
Step 4: If threats are found during the scanning, you will be prompted with an alert screen.
Step 5: Comodo Cleaning Essentials will remove attrib.exe malware from your computer including all other malwares!
No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
---|---|---|---|---|---|---|---|---|---|---|
1 | Microsoft Corporation | Executable | 77c26e51f21673f1 25964c1e3c03c593 1286c2bf |
d7cdeee6e342c256 20f594a4765dba29 |
Virus.Win32. Virut.CE |
No | 6.1.7600.1 6385 (win7_rtm. 090713-125 5) |
6.1.7600.1 6385 |
196.75.253.1/32 | N/A |
2 | Microsoft Corporation | Executable | 2ee5620ddf4e9fca e16224278151b85b ccca79ef |
187eba313338bb33 1f6095e861e2dd28 |
Virus.Win32. Virut.Ce |
No | 5.1.2600.5 512 (xpsp.0804 13-2111) |
5.1.2600.5 512 |
Italy | N/A |
3 | Microsoft Corporation | Executable | d4aad6d675bf7dbd 1b4c29beeea98e48 92dd693a |
3c31774f4e39ba28 3a9f7846eff3b571 |
Virus.Win32. Parite.gen |
No | 5.2.3790.0 (srv03_rtm .030324-20 48) |
5.2.3790.0 | China | N/A |
4 | Microsoft Corporation | Executable | 27e18fdf2be59585 9400a91a6d1d8716 8a1e3e9a |
596a496aede95f48 fdecacb99f5c6a5c |
Virus.Win32. Expiro.naf |
No | 6.1.7600.1 6385 (win7_rtm. 090713-125 5) |
6.1.7600.1 6385 |
Russian Federation | N/A |
No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
---|---|---|---|---|---|---|---|---|
1 | N/A | Executable | de379f6d39401563 5f718a9809ee6bd2 ada31ab4 |
a199faa190ff30c4 01ae6e3c0446c30a |
No | N/A | N/A | Internal Submission |
2 | Microsoft Corporation | Executable | 14918cd3450c2f85 6790277c5791ecb0 51c978ba |
cad43a7452b6a15c 2f49f955e51d0f49 |
No | 6.3.9600.1 6384 (winblue_r tm.130821- 1623) |
6.3.9600.1 6384 |
United States |
3 | N/A | Executable | ef4a8865683a8663 22fbc31c03ba48de eafdc140 |
4502bd6b8bbcaae5 0028d21c08ffe525 |
No | N/A | N/A | Internal Submission |
4 | N/A | Executable | 29038cdaffe14a5e 1b043185d24400b9 db0caf91 |
36a63e28159be864 a91e51a454469183 |
No | N/A | N/A | Internal Submission |