Wednesday, February 4, 2009

RBCalc Trojan

Click here to remove RBCalc malware
RBCalc description:
RBCalc Category:Trojan,Spyware,Backdoor
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Spyware is computer software that is installed surreptitiously on a personal computer
to with the computer, without the user's informed consent.
Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.

Detection RBCalc :

RBCalc Files:
[%SYSTEM%]\comclg32.dll
[%SYSTEM%]\d3dclsrv.dll
[%SYSTEM%]\ndsdavsrv.sys
[%SYSTEM%]\utlsrv.exe
[%SYSTEM%]\comclg32.dll
[%SYSTEM%]\d3dclsrv.dll
[%SYSTEM%]\ndsdavsrv.sys
[%SYSTEM%]\utlsrv.exe

RBCalc Registry Keys:
HKEY_LOCAL_MACHINE\system\controlset001\services\ndsdavsrv
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_ndsdavsrv

RBCalc Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing RBCalc:

you can run trial version of ExterminateIt, or remove RBCalc manually.


To completely manually remove RBCalc malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with RBCalc.


Read also:
Win32.Antilam Backdoor Removal