I discovered a new virus unpleasant today it took me a while to get rid of, Here is details. rundll32.exe (not a virus) * affected byjdpxgo.dll <- launches (VIRUS) boot name * Name: BMe30d5070 Route: rundll32.exe; "C:\WINDOWS\system32\byjdpxgo.dll",s ; Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run Once deleted it re names its self
Path: rundll32.exe "C:\WINDOWS\system32\lrlrvovu.dll",b
Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
This was a nasty virus and How to remove?
Please be careful!
Get a Live CD ... (not boot to windows) remove the DLL's infection eliminate rundll32.exe to restart the Windows system.
Changes services and startup items Deactivate these services:
TCP / IP
Windows Installer (not sure if that is all disables) * I had a backup of my registration * restore
It allows these services : messenger (the service is annoying ... LOT OF SPAM!)
Source : http://dhuwuh.blogspot.com/2008/09/careful-with-new-virus-affecting.html