Remove Backdoor.Revird

Posted on: November 15th, 2009


Discovered: November 14, 2009
Updated:

November 14, 2009 2:34:17 AM

Type:

Trojan

Systems Affected:

Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000

Recommended Action:
In order to Remove Backdoor.Revird you need to Download the ‘No Adware’ remover software. Based on our testing this was the best peforming remover of Backdoor.Revird .. Read our full No Adware Review

No Adware Review

Technical Details:

Once executed, the Trojan creates the following files:

* %System%\nwwwks.dll
* %System%\rdisk.dll
* %System%\skeys.dll
* %System%\SvcHost.DLL.exe
* %System%\SvcHost.DLL.log

It then creates the following folder:
%SystemDrive%\drivers\own\

The Trojan registers the file %System%\nwwwsk.dll as a new service with the following characteristics, so that it runs every time Windows starts:
Service Name: Gateway Service For Netware
Display Name: Gateway Service for Netware
Startup Type: Automatic

It creates the service by adding entries to the following registry subkey:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWC
workstation

The Trojan opens a back door on the compromised computer allowing a
remote attacker to perform some of the following actions:

* Download, upload, delete and execute files
* List, stop, and start processes and services.

It gathers the following information on the compromised computer:

* Available Network Resources
* Computer Name
* Drives connected and type of drive.
* Free Space on each drive
* Operating System and Version
* Processor Type
* System Memory
* System uptime
* User Name.

The Trojan copies all files with the following extensions to the %SystemDrive%\drivers\own\ folder and sends them to a predetermined
remote location:

* .doc
* .pdf
* .ppt
* .rar
* .zip

Action Steps:
FREE SCAN: NoAdware can Remove Backdoor.Revird . Click the link below for your free download & scan your PC now.

Please click here for manual removal instructions.