Senin, 01 September 2008

Careful With New Virus Affecting rundll32.exe

I discovered a new virus unpleasant today it took me a while to get rid of, Here is details. rundll32.exe (not a virus) * affected byjdpxgo.dll <- launches (VIRUS) boot name * Name: BMe30d5070 Route: rundll32.exe; "C:\WINDOWS\system32\byjdpxgo.dll",s ; Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run Once deleted it re names its self


Name: e03e63ec

Path: rundll32.exe "C:\WINDOWS\system32\lrlrvovu.dll",b

Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run


This was a nasty virus and How to remove?

Please be careful!

Get a Live CD ... (not boot to windows) remove the DLL's infection eliminate rundll32.exe to restart the Windows system.


Changes services and startup items Deactivate these services:


TCP / IP

telephony

Windows Installer (not sure if that is all disables) * I had a backup of my registration * restore


It allows these services : messenger (the service is annoying ... LOT OF SPAM!)

Tidak ada komentar:

Posting Komentar