Trojan

Trojan.Win32.DiskWriter.ebe removal

Malware Removal

The Trojan.Win32.DiskWriter.ebe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.DiskWriter.ebe virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • CAPE detected the WobbyChipMBR malware family

How to determine Trojan.Win32.DiskWriter.ebe?


File Info:

name: 91D5EBCC8FB0FC79E7A4.mlw
path: /opt/CAPEv2/storage/binaries/22b403ae358e179d9a6689c2b971cf68cfc9442aad863012d5c46a4da58e074f
crc32: CF53036C
md5: 91d5ebcc8fb0fc79e7a444522e78f363
sha1: 0be03c0a0ef02ace96cbe75679224bed9ffa3603
sha256: 22b403ae358e179d9a6689c2b971cf68cfc9442aad863012d5c46a4da58e074f
sha512: d2c9f12471fb2740e6ec1f08b3b797fc9e67ffff1ec79c6a9d0725ac63285a406cd542a125506715d67b7735b0b4140836c393c0d86492268b9fad93318e4c69
ssdeep: 12288:oZ3owANYUg8IFAIBmG3xDBz+Dcm0kOz5Qt2kGc:omTSzAIBmeBEBlOTkGc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13394D001F6C14CF2D57219325A39A722AA7DB8201F648ADFB3EC596DDF711C19630BA3
sha3_384: 4dec532c0edea3edaa3ecd388c6737d64d624d2b8cd7854e9cd0d694434cc721d539350ac1c88189d17e7a370c16a68c
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2021-10-08 08:51:51

Version Info:

0: [No Data]

Trojan.Win32.DiskWriter.ebe also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Ransom.GenericKD.48171435
FireEyeGeneric.mg.91d5ebcc8fb0fc79
ALYacTrojan.Ransom.GenericKD.48171435
CylanceUnsafe
ZillyaTrojan.Bingoml.Win32.7603
SangforTrojan.Win32.DiskWriter.ebe
K7AntiVirusTrojan ( 0055f5981 )
AlibabaTrojan:Win32/DiskWriter.69914cb9
K7GWTrojan ( 0055f5981 )
Cybereasonmalicious.c8fb0f
BitDefenderThetaGen:NN.ZexaF.34182.AyZ@a8YCCFfO
CyrenW32/KillMBR.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/KillMBR.NDS
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.DiskWriter.ebe
BitDefenderTrojan.Ransom.GenericKD.48171435
NANO-AntivirusTrojan.Win32.KillMBR.hgafvn
AvastWin32:Trojan-gen
TencentWin32.Trojan.Diskwriter.Htvp
SophosMal/Generic-R
DrWebTrojan.Siggen9.27655
TrendMicroTROJ_GEN.R002C0DAT22
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftTrojan.Ransom.GenericKD.48171435 (B)
IkarusTrojan.Win32.KillMBR
AviraTR/KillMBR.zstmf
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Killmbr
ZoneAlarmTrojan.Win32.DiskWriter.ebe
GDataWin32.Malware.MBRInfector.A (2x)
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4943951
McAfeeRDN/Generic.dx
MAXmalware (ai score=84)
VBA32BScope.Trojan.Meterpreter
MalwarebytesRansom.KillMBR
TrendMicro-HouseCallTROJ_GEN.R002H0CAT22
RisingExploit.UAC!8.107CD (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KillMBR.NDS!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.DiskWriter.ebe?

Trojan.Win32.DiskWriter.ebe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment