We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Aliases: W32/Wiper.AWHZ-7137 (Command) BKDR_WIPALL.B (Trend Micro) W32/Wiper.MRHI-3910 (Avira) Win-Trojan/Destroyer.268579 (AhnLab)
Windows Defender detects and removes this threat.
This threat can install other malware on your PC, including Trojan:Win32/NukeSped.B!dha and Trojan:Win32/NukeSped.C!dha. It can show you a warning message that says your files will be made publically available if you don't follow the malicious hacker's commands.
We have seen this threat used in targeted attacks against specific enterprises.
Use the following free Microsoft software to detect and remove this threat:
You should also run a full scan. A full scan might find hidden malware.
This threat makes changes to your Master Boot Record (MBR). To repair the MBR you might need to run the Bootrec.exe tool using Windows installation media.
You can read more about the Bootrec.exe tool in the Use Bootrec.exe in the Windows RE article.
Before you begin:
You will need to use Windows installation media to run the Bootrec.exe tool. If you don’t have Windows installation
media, you might have to create it.
To run the Bootrec.exe tool in Windows 8.1:
To run the Bootrec.exe tool in Windows 7:
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.
If you’re using Windows XP, see our Windows XP end of support page