Home Malware Programs Trojans Trojan.Dididix

Trojan.Dididix

Posted: July 16, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 5
First Seen: July 16, 2012
Last Seen: May 28, 2022
OS(es) Affected: Windows

Trojan.Dididix is a Trojan that modifies the master boot record (MBR) of the infected computer. Once executed, Trojan.Dididix copies the certain file. Trojan.Dididix then writes a driver file and an encrypted .exe file into sectors after the end of the last partition on the disk drive of the affected PC. Trojan.Dididix saves the existent master boot record (MBR) and then overwrites it (Boot.Dididix). The modified MBR hooks the BIOS interrupt to load the driver file when Windows is started, and then loads and runs the saved MBR. The driver file then decrypts the encrypted .exe file and adds it as the certain file. Trojan.Dididix can also delete files.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%System%\winsys.exe (Backdoor.Trojan) File name: %System%\winsys.exe (Backdoor.Trojan)
Mime Type: unknown/Trojan)
Group: Malware file
%System%\drivers\beep.sys File name: %System%\drivers\beep.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%System%\drivers\beep.sys to %Windir%\Help\intel.chm. File name: %System%\drivers\beep.sys to %Windir%\Help\intel.chm.
Group: Malware file
Loading...