Name : rtdx32.exe
Path : %SYSTEM%\rtdx32.exe
[ C:\Windows\System32\rtdx32.exe ]
Name : Trojan.Win32.Webber
Alias : Downloader-DI,
TrojanProxy.Win32.Webber, Troj/Webber-A, Trojan.Download.Berbew,
level : Low
Rtdx32.exe process is
downloaded by Webber. It is a backdoor
Trojan, can be used to steal passwords in the
infected system. It arrives as an e-mail attachment.
The infected attachment name will be "web.da.us.citi.heloc.pif".
message subject will be
message body will be
Thank you for your online application for a
Citibank Home Equity Loan. In order to be
approved for any loan application we pull your
Credit Profile and Chexsystems information, which
didn't satisfy our minimum needs. Consequently,
we regret to say that we cannot approve you for
Citibank Home Equity Loan at this time.
*Attached are copy of your Credit Profile and
Your Application that you submitted with us.
Please take a close look at it, you will receive
hard copy by mail withing next few days."
When executed, the Trojan
connects to a website and downloads the file rtdx32.exe
in the Windows system folder. The downloaded file
copies to a random file name and drops a DLL file.
Then it modifies registry keys to load
automatically. Webber Trojan
steals cached password from the infected system
and posts them to a pre configured web site.
How can I protect my
Solo has incorporated
rtdx32.exe in its signature file to protect users
from this Trojan attack. Solo antivirus
registered users are already protected from this
Trojan. Make sure that you have installed
registered version of Solo Antivirus to protect
your system from all virus threats.
to remove this Trojan?
you are already infected with rtdx32.exe,
you can remove it from your computer using Solo
Antivirus software. Use the
following link to Download 30 day trial
version of Solo antivirus to remove
viruses from your computer.
Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VB, Java scripts, Trojans,
Backdoors, boot sector, partition table and macro
purchase Solo antivirus using the link