Thursday, November 6, 2008

Ribdew Trojan

Removing Ribdew
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Ribdew Also known as:

[Kaspersky]AdWare.Win32.Webdir.b;
[Other]Win32/Ribdew.E,Adware.WebDir,Win32/Ribdew.F

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\IECodecPlg.dll
[%WINDOWS%]\VirtualDNS.dll
[%WINDOWS%]\VirtualDNS.dll.bak
[%WINDOWS%]\IECodecPlg.dll
[%WINDOWS%]\VirtualDNS.dll
[%WINDOWS%]\VirtualDNS.dll.bak

How to detect Ribdew:

Files:
[%WINDOWS%]\IECodecPlg.dll
[%WINDOWS%]\VirtualDNS.dll
[%WINDOWS%]\VirtualDNS.dll.bak
[%WINDOWS%]\IECodecPlg.dll
[%WINDOWS%]\VirtualDNS.dll
[%WINDOWS%]\VirtualDNS.dll.bak

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}
HKEY_CLASSES_ROOT\CLSID\{CA13D72F-2DAC-4D99-B08D-C5EA1C920E89}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{86C510E9-97EF-4749-914F-0280247BE3A6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA13D72F-2DAC-4D99-B08D-C5EA1C920E89}
HKEY_CLASSES_ROOT\clsid\{86c510e9-97ef-4749-914f-0280247be3a6}
HKEY_CLASSES_ROOT\clsid\{ca13d72f-2dac-4d99-b08d-c5ea1c920e89}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{86c510e9-97ef-4749-914f-0280247be3a6}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ca13d72f-2dac-4d99-b08d-c5ea1c920e89}

Removing Ribdew:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:

No comments: