Webdir is a Web Browser Helper Object (BHO) used to collect user information and display targeted advertisings using Internet Explorer browser. Webdir attempts to modify certain visited urls to include affiliate IDs.
Installation
Webdir is a Win32 DLL and may be installed by other programs as a BHO. The DLL may be present as a file named 'VirtualDNS.DLL'. When loaded and executed, the DLL makes the following registry modifications:
Adds value: "(default)"
With data: "cvirtualdnsobj object"
To subkey: HKLM\SOFTWARE\Classes\VirtualDNS.VirtualDNSObj.1
Adds value: "(default)"
With data: "{86c510e9-97ef-4749-914f-0280247be3a6}"
To subkey: HKLM\SOFTWARE\Classes\VirtualDNS.VirtualDNSObj.1\CLSID
Adds value: "(default)"
With data: "cvirtualdnsobj object"
To subkey: HKLM\SOFTWARE\Classes\VirtualDNS.VirtualDNSObj
Adds value: "(default)"
With data: "{86c510e9-97ef-4749-914f-0280247be3a6}"
To subkey: HKLM\SOFTWARE\Classes\VirtualDNS.VirtualDNSObj\CLSID
Adds value: "(default)"
With data: "virtualdns.virtualdnsobj.1"
To subkey: HKLM\SOFTWARE\Classes\VirtualDNS.VirtualDNSObj\CurVer
Adds value: "(default)"
With data: "cvirtualdnsobj object"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}
Adds value: "(default)"
With data: "virtualdns.virtualdnsobj.1"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}
Adds value: "(default)"
With data: "cvirtualdnsobj object"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\ProgID
Adds value: "(default)"
With data: "virtualdns.virtualdnsobj"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\VersionIndependentProgID
Adds value: "(default)"
With data: "VirtualDNS.DLL"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\InprocServer32
Adds value: "(default)"
With data: "VirtualDNS.DLL, 1"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\ToolboxBitmap32
Adds value: "(default)"
With data: "0"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\MiscStatus
Adds value: "(default)"
With data: "131473"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\MiscStatus\1
Adds value: "(default)"
With data: "{143414d1-c324-4d6f-9756-5075d9a4a485}"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\TypeLib
Adds value: "(default)"
With data: "1.0"
To subkey: HKLM\SOFTWARE\Classes\CLSID\{86C510E9-97EF-4749-914F-0280247BE3A6}\Version
Adds value: "(default)"
With data: "virtualdns 1.0 type library"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{143414D1-C324-4D6F-9756-5075D9A4A485}\1.0
Adds value: "(default)"
With data: "0"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{143414D1-C324-4D6F-9756-5075D9A4A485}\1.0\FLAGS
Adds value: "(default)"
With data: "VirtualDNS.DLL"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{143414D1-C324-4D6F-9756-5075D9A4A485}\1.0\0\win32
Adds value: "(default)"
With data: "<current folder>\"
To subkey: HKLM\SOFTWARE\Classes\TypeLib\{143414D1-C324-4D6F-9756-5075D9A4A485}\1.0\HELPDIR
Adds value: "(default)"
With data: "ivirtualdnsobj"
To subkey: HKLM\SOFTWARE\Classes\Interface\{1F63B171-E2F3-4362-A484-8563144D62E6}
Adds value: "(default)"
With data: "{00020424-0000-0000-c000-000000000046}"
To subkey: HKLM\SOFTWARE\Classes\Interface\{1F63B171-E2F3-4362-A484-8563144D62E6}\ProxyStubClsid
Adds value: "(default)"
With data: "{00020424-0000-0000-c000-000000000046}"
To subkey: HKLM\SOFTWARE\Classes\Interface\{1F63B171-E2F3-4362-A484-8563144D62E6}\ProxyStubClsid32
Adds value: "(default)"
With data: "{143414d1-c324-4d6f-9756-5075d9a4a485}"
To subkey: HKLM\SOFTWARE\Classes\Interface\{1F63B171-E2F3-4362-A484-8563144D62E6}\TypeLib
Adds value: "(default)"
With data: "virtualdns"
To subkey: HKLM\SOFTWARE\Classes\AppID\
Adds value: "AppID"
With data: "0"
To subkey: HKLM\SOFTWARE\Classes\AppID\VirtualDNS.DLL
Additional Information
Win32/WebDir requests information from the following URL:
rss.everer.com/rssfeed.xml
Analysis by Oleg Petrovsky