Adware.RBlast Trojan

Virus description: Adware.RBlast
Category:Trojan,Adware,Hijacker,Downloader
Another names:

[Kaspersky]TrojanDownloader.Win32.Delf.j,TrojanDownloader.Win32.IstBar.ak,TrojanDownloader.Win32.IstBar.ar,TrojanDownloader.Win32.IstBar.g,TrojanDropper.Win32.RunMe;
[Eset]Win32/TrojanDownloader.IstBar.AR trojan,Win32/TrojanDownloader.IstBar.G trojan;
[McAfee]Adware-RBlast;
[Panda]Spyware/ISTbar,Trj/W32.Delf;
[Computer Associates]Win32/IstBar.g!Downloader;
[Other]Win32/Rbot.DPG,W32/Rbot-AOK,Trojan.Dropper,Backdoor.Win32.Rbot.xn,Backdoor.Win32.IRCBot.bl

Adware.RBlast Detection :

Files:
[%PROGRAM_FILES%]\rb32\rb32.exe
[%PROGRAM_FILES%]\rb32\rb32.exe

Folders:
[%PROGRAM_FILES%]\fwn toolbar
[%PROGRAM_FILES%]\rapidblaster
[%PROGRAM_FILES%]\belmontsoft

Registry Keys:
HKEY_LOCAL_MACHINE\software\classes\appid\{f72cbc6d-6cbe-4570-ad54-4a51bff58036}
HKEY_LOCAL_MACHINE\software\classes\clsid\{01fc5803-8644-45d7-877b-5a3924d8ecc4}
HKEY_LOCAL_MACHINE\software\classes\clsid\{3d0bdab3-12f4-471c-8966-e35a2c6c7de7}
HKEY_LOCAL_MACHINE\software\classes\clsid\{3d156636-3f7e-46c9-9ac1-5e4d8202aa23}
HKEY_LOCAL_MACHINE\software\classes\clsid\{7eb15626-cb8e-4174-8a72-c055b12b4310}
HKEY_LOCAL_MACHINE\software\classes\clsid\{bcaa3a19-1051-4c2f-88b9-4d05985aa2c6}
HKEY_LOCAL_MACHINE\software\classes\fwn.fwntoolbar
HKEY_LOCAL_MACHINE\software\classes\fwn.isubclass
HKEY_LOCAL_MACHINE\software\classes\interface\{10d4adb7-0842-42eb-8c97-d94233d2dd5a}
HKEY_LOCAL_MACHINE\software\classes\interface\{3b879007-84a4-476a-82b0-819b3f1f9a6e}
HKEY_LOCAL_MACHINE\software\classes\interface\{3dbbf8b7-a97c-4a92-8d27-d29222e6b60f}
HKEY_LOCAL_MACHINE\software\classes\interface\{68831d00-169e-4feb-89b9-e099df439321}
HKEY_LOCAL_MACHINE\software\classes\interface\{ea9d65a3-8fa2-433e-9caf-68c6e43555af}
HKEY_LOCAL_MACHINE\software\classes\qd2.qd2loader
HKEY_LOCAL_MACHINE\software\classes\qd2.qd2loader.1
HKEY_LOCAL_MACHINE\software\classes\typelib\{0e9db3ab-d16a-47cf-b59a-f74d649bea5b}
HKEY_LOCAL_MACHINE\software\classes\typelib\{15e7d23b-736e-46fa-bffd-cbec4126befd}
HKEY_LOCAL_MACHINE\software\classes\typelib\{f72cbc6d-6cbe-4570-ad54-4a51bff58036}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7EB15626-CB8E-4174-8A72-C055B12B4310}
HKEY_CLASSES_ROOT\clsid\{67d26f9a-4ece-4ba8-bf86-41398d5f25e9}
HKEY_CLASSES_ROOT\clsid\{efd0334a-d40b-4937-8b09-271a4ac78ac6}
HKEY_CLASSES_ROOT\clsid\{f0aa2376-f073-4e57-86e8-0238f99087c7}
HKEY_CLASSES_ROOT\interface\{67d26f9a-4ece-4ba8-bf86-41398d5f25e9}
HKEY_CLASSES_ROOT\typelib\{efd0334a-d40b-4937-8b09-271a4ac78ac6}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{7eb15626-cb8e-4174-8a72-c055b12b4310}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{f0aa2376-f073-4e57-86e8-0238f99087c7}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\notepad
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\rapidblaster
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\rb32
HKEY_LOCAL_MACHINE\software\rapidblaster

Registry Values:
HKEY_LOCAL_MACHINE\software\classes\appid\qd2.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\fwn toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\fwn toolbar
HKEY_LOCAL_MACHINE\software\classes\appid\qd2.dll
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/installer.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/installer.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\[%WINDOWS%]\downloaded program files
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\fwn toolbar
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\fwn toolbar

Removing Adware.RBlast:

you can run trial version of ExterminateIt, or remove Adware.RBlast manually..


ExterminateIt effectively and automatically removes Trojan Horses, Rootkits, Backdoors, spyware, botnets, keystroke loggers, dialers and other malicious software(malware) from you computer.

Download ExterminateIt! to instantly get rid of Adware.RBlast!


Also Be Aware of the Following Threats:
Account.ker Trojan Removal
AA Trojan Removal instruction
AdRoad.Cpr Adware Removal instruction
Adware.BitLocker.dr Adware Cleaner
ActivityX.Custom.Control Spyware Cleaner