Malware

Win32/KillDisk.NCU (file analysis)

Malware Removal

The Win32/KillDisk.NCU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/KillDisk.NCU virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine Win32/KillDisk.NCU?


File Info:

name: F97E2DB43B8DBBCA2932.mlw
path: /opt/CAPEv2/storage/binaries/fd5025a06e5432423157e1956c6f1c0e50dc8df45652ff6c75480b5eb3a693c4
crc32: 1FA8A345
md5: f97e2db43b8dbbca293276f377204557
sha1: 419e0e401a76f0401ae1180d78eeaf3c8fc22e8a
sha256: fd5025a06e5432423157e1956c6f1c0e50dc8df45652ff6c75480b5eb3a693c4
sha512: bc39d32511e0e6fdd228a03f0b9e02eb342bdb8a357ae6303fa129e0d517c3a40f068b5d30088fdde5b3abe047282f8da28117a168acb60c6b89ec8f1fb00601
ssdeep: 3072:tq6+ouCpk2mpcWJ0r+QNTBfJzicSeaM5eFSM2vIi:tldk1cWQRNTBhzeP92Ai
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBE3CF45F3D241F7EAE20A3100B6622EA73667245724ECDBC34C3D829553AD19A7D3FA
sha3_384: f542855dc76dff2736a6149c38ddbe52e4083674d844a85628ea7d48eb3d7264fa45d059c3e030577ce6dec64fd45f6a
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Win32/KillDisk.NCU also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Tiny.trFe
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeRDN/Generic.grp
MalwarebytesMalware.AI.392946571
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.48388488
K7GWTrojan ( 0058e48e1 )
K7AntiVirusTrojan ( 0058e0e81 )
VirITTrojan.Win32.Genus.IHW
CyrenW32/Trojan.VFBA-8001
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/KillDisk.NCU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.DiskWriter.hoh
AlibabaTrojan:Win32/DiskWriter.4a0bd5bb
MicroWorld-eScanTrojan.GenericKD.48388488
AvastWin32:WormX-gen [Wrm]
RisingTrojan.KillDisk!8.C4C (CLOUD)
Ad-AwareTrojan.GenericKD.48388488
SophosMal/Generic-S
ZillyaTool.Lazagne.Win32.102
TrendMicroTROJ_GEN.R002C0WBM22
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.f97e2db43b8dbbca
EmsisoftTrojan.GenericKD.48388488 (B)
IkarusTrojan.Win32.KillDisk
GDataWin32.Trojan.PSE.UUGKTH
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D2E25988
ZoneAlarmTrojan.Win32.DiskWriter.hoh
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.C4978320
ALYacTrojan.GenericKD.48388488
VBA32Trojan.DiskWriter
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0WBM22
TencentWin32.Trojan.Diskwriter.Eehi
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.140636643.susgen
FortinetW32/KillDisk.NCU!tr
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.01a76f
PandaTrj/Genetic.gen

How to remove Win32/KillDisk.NCU?

Win32/KillDisk.NCU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment