disk2vhd.exe

  • File Path: C:\SysinternalsSuite\disk2vhd.exe
  • Description: Disk to VHD converter

Hashes

Type Hash
MD5 D26F2930892B309B36C7819CD49A021D
SHA1 7A067F51A21A6765FF88B53B40064FA2D49F8A64
SHA256 9A69F747771FB29E3B3F20E6E802FF82280D653DD1CCCD2B55B945D237F5652E
SHA384 E3598D861E5D7E2EE5CD59978CCAE4CA41984AADA4FD2C81CC8667CA39DE423A22E59F8BC932684C34C13F022AC8A069
SHA512 69843F7698CA16FFE79B365EBDE2BF1152306F17D725CC9965BC5A1F77C04F16AE8382A278DB45826493D5FB42D06150BAC1B414ADE2D3B26F93A24BD4984F48
SSDEEP 24576:7eM9zGzweY/OAxuOnd8Pbn304LVVZPlEqpdAi14lKjyYAJ9Jxj/W0Xx84x:9zEwTTxuEQTPLZysfAlxjvx
IMP 267962DCB688834B5DD6FD9F808AF1F3
PESHA1 D90229277B60A77D2C7A1184B07958B6A04CB7BF
PE256 D81709E54B37B6FF4FA8176CD82D9F104274BD962E97443B771E9CD1C836DC17

Runtime Data

Child Processes:

disk2vhd-tmp.exe

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\propsys.dll.mui File
(RW-) C:\Windows File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627 File
(RW-) C:\xCyclopedia File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\BaseNamedObjects\windows_shell_global_counters Section
\Sessions\1\BaseNamedObjects\UrlZonesSM_user Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section

Loaded Modules:

Path
C:\SysinternalsSuite\disk2vhd.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 33000000B011AF0A8BD03B9FDD0001000000B0
  • Thumbprint: 108E2BA23632620C427C570B6D9DB51AC31387FE
  • Issuer: CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: Disk2vhd
  • Product Name: Disk2vhd
  • Company Name: Sysinternals - www.sysinternals.com
  • File Version: 2.01
  • Product Version: 2.01
  • Language: English (United States)
  • Legal Copyright: Copyright 2009-2014 Mark Russinovich
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/66
  • VirusTotal Link: https://www.virustotal.com/gui/file/9a69f747771fb29e3b3f20e6e802ff82280d653dd1cccd2b55b945d237f5652e/detection/

Possible Misuse

The following table contains possible examples of disk2vhd.exe being misused. While disk2vhd.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_false_sysinternalsuite.yml - '\disk2vhd.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.