Solved! Use EBN.DLL (Trojan Downloader) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

EBN.DLL – Trojan Downloader removal

File MD5 Virus Alias
EBN.DLL 713a16d00a127e8d7b0e01cd3f599d92 Trojan Downloader
EBN.DLL 713a16d00a127e8d7b0e01cd3f599d92 Trojan Eldorado
EBN.DLL 713a16d00a127e8d7b0e01cd3f599d92 Trojan Agent
EBN.DLL 713a16d00a127e8d7b0e01cd3f599d92 Trojan Small
EBN.DLL 713a16d00a127e8d7b0e01cd3f599d92 Trojan FakeAV

EBN.DLL size: 8192 bytes
EBN.DLL hash: 713A16D00A127E8D7B0E01CD3F599D92

Created files:

C:\Driver.sys
C:\pci.sys
%SysDir%\ebn.dll
%SysDir%\qnm.dll
%SysDir%\system.exe
%Temp%\IXP000.TMP\QQQSSQ~1.EXE

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\System: %WinDir%\System32\System.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%Temp%\IXP000.TMP\”
HKLM\System\CurrentControlSet\Services\Driver\Type: 01000000
HKLM\System\CurrentControlSet\Services\Driver\Start: 03000000
HKLM\System\CurrentControlSet\Services\Driver\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Driver\DisplayName: Driver
HKLM\System\CurrentControlSet\Services\Driver\ImagePath: C:\Driver.sys

Detected by UnHackMe:

EBN.DLL
Default location: %SYSDIR%\EBN.DLL

Dropper information:
MD5: 6a1e0a0ff1755db2bddfdacf57338a76
File size: 225280 bytes

Leave a Reply