Trojan

Trojan.Diskwriter removal

Malware Removal

The Trojan.Diskwriter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Diskwriter virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Diskwriter?


File Info:

crc32: F2258B7F
md5: 29f12053cf30b35bb5384c9d113a03e1
name: 29F12053CF30B35BB5384C9D113A03E1.mlw
sha1: 02c566dba531f93233856525d791a869df6e2664
sha256: 690f4308ef3f7b402b6d76305d2a9faab5b5264ffbacf5550ab183ee5663bd6e
sha512: 581b689482687ffa54a96487431cff48b767b65a1b20d5c7c6fa392814c366a4195633cc22c248de2130121eda657f8f16117bfa451512f04d2bf27de65eea59
ssdeep: 24576:/PQaF2aBL0x27y2ewlrxpYhWkIoyLcvzJ:/oaF7NuxwNQIZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1997-2019 Winamp SA
Assembly Version: 5.8.0.3660
InternalName: slkc.exe
FileVersion: 5.8.0.3660
CompanyName: Nullsoft, Inc.
LegalTrademarks: Nullsoft and Winamp are trademarks of Winamp SA
Comments: Winamp
ProductName: Winamp
ProductVersion: 5.8.0.3660
FileDescription: Winamp
OriginalFilename: slkc.exe

Trojan.Diskwriter also known as:

LionicTrojan.Win32.HiddenTears.4!c
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.8096
ALYacTrojan.Diskwriter.gen
CylanceUnsafe
ZillyaTrojan.DiskWriter.Win32.681
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/DiskWriter.5d5d819b
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.DiskWriter.gen
BitDefenderGen:Heur.Ransom.HiddenTears.1
NANO-AntivirusTrojan.Win32.DiskWriter.hhycbt
MicroWorld-eScanGen:Heur.Ransom.HiddenTears.1
TencentWin32.Trojan.Dropper.Huzp
Ad-AwareGen:Heur.Ransom.HiddenTears.1
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Heur.Ransom.HiddenTears.1
EmsisoftGen:Heur.Ransom.HiddenTears.1 (B)
AviraTR/Dropper.Gen7
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Ransom.HiddenTears.1
GDataGen:Heur.Ransom.HiddenTears.1
McAfeeArtemis!29F12053CF30
MAXmalware (ai score=88)
PandaTrj/GdSda.A
YandexTrojan.DiskWriter!6dElSzMi9qk
MaxSecureTrojan.Malware.73750418.susgen
FortinetMSIL/DiskWriter!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Diskwriter?

Trojan.Diskwriter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment