ruby13.exe - Dangerous

ruby13.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

ruby13.exe
W32.Mexer.E@mm is a mass-mailing worm that also spreads through several file-sharing networks.
Adds the value: "Dir0"="012345:c:\sysnet\" to the registry keys:
HKEY_CURRENT_USER\Software\Imesh\Client\LocalContent\
HKEY_CURRENT_USER\Software\Kazaa\LocalContent
HKEY_CURRENT_USER\Software\Kazaa\Transfer
to spread using the iMesh and KaZaA peer-to-peer file-sharing networks.
Gathers the email addresses from the files and sends itself to the email addresses found, using its own SMTP engine.

Automatic removal: Use RegRun Startup Optimizer to automatically remove it from startup.

Remove ruby13.exe now!