Gamingforce Interactive Forums
85242 35212

Go Back   Exploding Garrmondo Weiner Interactive Swiss Army Penis > Garrmondo Network > Help Desk
Register FAQ GFWiki Community Donate Arcade ChocoJournal Calendar

Notices

Welcome to the Exploding Garrmondo Weiner Interactive Swiss Army Penis.
GFF is a community of gaming and music enthusiasts. We have a team of dedicated moderators, constant member-organized activities, and plenty of custom features, including our unique journal system. If this is your first visit, be sure to check out the FAQ or our GFWiki. You will have to register before you can post. Membership is completely free (and gets rid of the pesky advertisement unit underneath this message).


Caught Malware/Virus! Please Help!
Reply
 
Thread Tools
Cetra
oh shi-


Member 445

Level 24.23

Mar 2006


Reply With Quote
Old Oct 12, 2008, 03:05 PM Local time: Oct 12, 2008, 12:05 PM #1 of 18
Sounds like the latest Antivirus 2008 variation that just starting going around. I can see the files in your log. O4 - HKLM\..\Run: [88ae9fcb] rundll32.exe "C:\WINDOWS\system32\whtmbhyt.dll",b for example.

Download and run Malwarebytes Anti-Malware

Jam it back in, in the dark.
Cetra
oh shi-


Member 445

Level 24.23

Mar 2006


Reply With Quote
Old Oct 12, 2008, 03:19 PM Local time: Oct 12, 2008, 12:19 PM #2 of 18
You're going to have to wait for a Malwarebytes update. It looks like you got a brand new variation that is not databased yet. I would give it to at least mid week and see if an update comes through and run it again.

I'm pretty sure its an Antivirus variation though and these guys are the only ones right now that are on top of this malware.

For now you can try and remove the following from your Run registry location:

O4 - Startup: Rapid Antivirus.lnk = C:\Program Files\Rapid Antivirus\Rapid Antivirus.exe

O4 - HKLM\..\Run: [88ae9fcb] rundll32.exe "C:\WINDOWS\system32\whtmbhyt.dll",b


O4 - HKCU\..\Run: [smartsetmsg] C:\WINDOWS\system32\sledyfqv.exe


Reboot then go and delete those files yourself.

There's nowhere I can't reach.
Cetra
oh shi-


Member 445

Level 24.23

Mar 2006


Reply With Quote
Old Oct 12, 2008, 04:45 PM Local time: Oct 12, 2008, 01:45 PM #3 of 18
I think i'm going to reformat anyway. Just before though, how would I go about removing them Cetra?
Delete "Rapid Antivirus.lnk" from the Startup folder in the start menu.

Then go to start -> run and type 'regedit'

Navigate to -> HKey_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run

Locate the key in the right panel with the data "C:\WINDOWS\system32\sledyfqv.exe" and delete it.

Navigate to ->HKey_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Cur rentVersion\Run

Locate the key in the right panel with the data "rundll32.exe "C:\WINDOWS\system32\whtmbhyt.dll",b" And delete it.


Reboot (In Safe Mode to be...well safe). Delete the folder C:\Program Files\Rapid Antivirus\

Delete the Files: C:\WINDOWS\system32\whtmbhyt.dll ; C:\WINDOWS\system32\sledyfqv.exe (These might be hidden files so make sure you have view hidden files on.)

This thing is sticky, and I don't like it. I don't appreciate it.

Last edited by Cetra; Oct 12, 2008 at 04:47 PM.
Cetra
oh shi-


Member 445

Level 24.23

Mar 2006


Reply With Quote
Old Oct 12, 2008, 05:56 PM Local time: Oct 12, 2008, 02:56 PM #4 of 18
OK, I removed the Rapid Antivirus.Ink. I also got rid of the first value in regedit, the second didn't seem to be there. I then went into safe mode and removed the sledyfqv.exe file, but couldn't find the .dll file.
So far no popups, but I don't want to speak to soon.

Could you post a fresh HiJack This log? It's possible that the DLL file is randomly named on each start. Please don't turn your computer off again either if possible after posting the log as we don't want the dll file to change names again.

Most amazing jew boots
Reply


Exploding Garrmondo Weiner Interactive Swiss Army Penis > Garrmondo Network > Help Desk > Caught Malware/Virus! Please Help!

Forum Jump


All times are GMT -5. The time now is 05:48 PM.


Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2026, vBulletin Solutions, Inc.