Trojan

Trojan.Win32.DiskWriter.hdc information

Malware Removal

The Trojan.Win32.DiskWriter.hdc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.DiskWriter.hdc virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Likely installs a bootkit via raw harddisk modifications
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempted to write directly to a physical drive

How to determine Trojan.Win32.DiskWriter.hdc?


File Info:

name: 669C08186CB746BB315F.mlw
path: /opt/CAPEv2/storage/binaries/70e4901bf744afae8795f88f2434f3588d3f653385a3e0a21e08834891645cc3
crc32: 479092CA
md5: 669c08186cb746bb315f59d9ff69b836
sha1: f39df8dfb3ad09981e310560122fbd24233f05aa
sha256: 70e4901bf744afae8795f88f2434f3588d3f653385a3e0a21e08834891645cc3
sha512: d8b54d881846cf96270d63b963b8feb804714b1b538640fef8d4e77b0ad493f5041f1389d87e632496542d44f4b6f582e4363cd6322746199b23f0dd78ce11f9
ssdeep: 12288:xBqfvpusAK70vr9nvEv56gIR8pOzVAcu6c4dLpfvQ3:uIsA0sr9nue8M+cuLcLpnQ3
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T16CA4F1E535D48C5AE920463D458AC176333DBED08A42574766F03F3B3B33AD16EC26AA
sha3_384: 303e7dad9d1d752441527f86b0fca0753761f507b0b9074765bfd6c16668526bf4509ce212fd0b436ec34d2884f1e72c
ep_bytes: 53565755488d351ad4faff488dbedbcf
timestamp: 2021-11-28 14:04:20

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Command Processor
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
InternalName: cmd
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Cmd.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Trojan.Win32.DiskWriter.hdc also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
SangforTrojan.Win32.KillMBR.NEJ
K7AntiVirusTrojan ( 005769391 )
AlibabaTrojan:Win32/DiskWriter.9124b12a
K7GWTrojan ( 005769391 )
Cybereasonmalicious.fb3ad0
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/KillMBR.NEJ
TrendMicro-HouseCallTROJ_GEN.R002H0DKS21
AvastWin64:Trojan-gen
KasperskyTrojan.Win32.DiskWriter.hdc
BitDefenderTrojan.GenericKD.47511372
MicroWorld-eScanTrojan.GenericKD.47511372
Ad-AwareTrojan.GenericKD.47511372
EmsisoftTrojan.GenericKD.47511372 (B)
DrWebTrojan.KillMBR.24872
McAfee-GW-EditionBehavesLike.Win64.Fake.gc
FireEyeGeneric.mg.669c08186cb746bb
SophosMal/Generic-S
WebrootW32.Trojan.Dropper
AviraTR/KillMBR.kweyf
MAXmalware (ai score=88)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
APEXMalicious
GDataTrojan.GenericKD.47511372
AhnLab-V3Trojan/Win.DiskWriter.C4790461
McAfeeArtemis!669C08186CB7
YandexTrojan.GenAsa!ckMN52Bux90
IkarusTrojan.Win32.KillMBR
FortinetW32/KillMBR.NEJ!tr
AVGWin64:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.DiskWriter.hdc?

Trojan.Win32.DiskWriter.hdc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment