Careful With New Virus Affecting rundll32.exe

Careful With New Virus Affecting rundll32.exe

I discovered a new virus unpleasant today it took me a while to get rid of, Here is details. rundll32.exe (not a virus) * affected byjdpxgo.dll <- launches (VIRUS) boot name * Name: BMe30d5070 Route: rundll32.exe; "C:\WINDOWS\system32\byjdpxgo.dll",s ; Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run Once deleted it re names its self


Name: e03e63ec

Path: rundll32.exe "C:\WINDOWS\system32\lrlrvovu.dll",b

Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run


This was a nasty virus and How to remove?

Please be careful!

Get a Live CD ... (not boot to windows) remove the DLL's infection eliminate rundll32.exe to restart the Windows system.


Changes services and startup items Deactivate these services:


TCP / IP

telephony

Windows Installer (not sure if that is all disables) * I had a backup of my registration * restore


It allows these services : messenger (the service is annoying ... LOT OF SPAM!)




Source : http://dhuwuh.blogspot.com/2008/09/careful-with-new-virus-affecting.html



Related Posts by Categories :


5 comments:

Anonymous said... on April 18, 2009 at 11:25 PM  

Solution from Search-and-destroy.
If you own a computer, you must have antispyware to keep it running at its best. The problem is choosing a scan that works. I have tried many different types of scans in the past and then I ran across Search-and-destroy Antispyware. I have to say that the antispyware solution from Search-and-destroy is the best that I have used to date. It gets the job done and keeps my computer working like new. If you are interested in seeing for yourself just how good this antispyware works you can click on http://www.Search-and-destroy.com to learn more. I’m sure it would be worth your time to check it out.

Post a Comment

"Using DOFOLLOW System. Pease don`t SPAM!!!"

Thanks To Comment My Articles. God Bless You People.

Add to Technorati Favorites

Technorati Ping To Your Blog
Including Yours E-Mail Address To Subscribe New Tricks