Trojan

Trojan.Win32.DiskWriter.hoh removal tips

Malware Removal

The Trojan.Win32.DiskWriter.hoh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.DiskWriter.hoh virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Likely installs a bootkit via raw harddisk modifications
  • Attempted to write directly to a physical drive
  • Deletes executed files from disk

How to determine Trojan.Win32.DiskWriter.hoh?


File Info:

name: 8FA69A429E924FE4D7E6.mlw
path: /opt/CAPEv2/storage/binaries/a114404917981d923a181d5c57412310fdaec704dd74c3f6b7fd1f18736f7456
crc32: C61A4048
md5: 8fa69a429e924fe4d7e6a5388fd146f0
sha1: fe61e06839276fe243ae64060aa2d34eb38f702e
sha256: a114404917981d923a181d5c57412310fdaec704dd74c3f6b7fd1f18736f7456
sha512: 7be64f5bb50fa9e3a860b49b84ac2748277828d2af63967e16862463b61c85aa130b7d4ce75229ba0ce0a12e11b7b8a345a590b2a08aeb78842aa313f0f6329b
ssdeep: 3072:lq6+ouCpk2mpcWJ0r+QNTBfsEAvukTRSEyflwkOcoPs0o:lldk1cWQRNTBUEZkTRSECNOco8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145E3BF44B3E742F7EAF1497100A6752FA73666284724E8DBC34C3C925943AD0AA7D3F9
sha3_384: 1e5ef0ded659d330a5459d3727f52183d568f906221667c388ccfbc47988df38ece6ea45461ae1eebc4cbee86ab61ae9
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan.Win32.DiskWriter.hoh also known as:

BkavW32.AIDetect.malware2
CylanceUnsafe
ZillyaTool.Lazagne.Win32.102
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058e48e1 )
K7GWTrojan ( 0058e48e1 )
Cybereasonmalicious.839276
VirITTrojan.Win32.Genus.IHW
CyrenW32/Trojan.VFBA-8001
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/KillDisk.NCU
APEXMalicious
KasperskyTrojan.Win32.DiskWriter.hoh
AvastWin32:WormX-gen [Wrm]
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.8fa69a429e924fe4
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.847D3F
AviraTR/KillDisk.gtuzr
Antiy-AVLTrojan/Generic.ASMalwS.50F5
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!8FA69A429E92
MalwarebytesMalware.AI.392946571
TrendMicro-HouseCallTROJ_GEN.R011H0CH322
RisingTrojan.Generic@AI.99 (RDML:OIRAlewM3bWGnTW6T5pilA)
IkarusTrojan.Win32
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KillDisk.NCU!tr
AVGWin32:WormX-gen [Wrm]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.DiskWriter.hoh?

Trojan.Win32.DiskWriter.hoh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment