http://net-studio.org >> Patch>
    logininscription
 

softhomepage.com Fix (sbsm.exe, sbsm.dll)

   
Google

 

 

Information

 

  • Download files automatically on the Internet
  • Create an entry in the register to be launched automatically
  • Integrates into IE (Browser Helper Object)
  • Run as service
  • Make softhomepage.com your home page and connects to the site through the 80 port

 

File

 

  • <System>\sbmdl.dll
  • <System>\sbsm.dll

 

Registry

Keys created :

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DAED9266-8C28-4C1C-8B58-5C66EFF1D302}

Values created :

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}\InprocServer32]
    • (Default) = "%System%\sbmdl.dll"
    • ThreadingModel = "Apartment"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}]
    • xxx = "xxx"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}]
    • MenuText = "IE Anti-Spyware"
    • Exec = "http://www.gateietool.com/redirect.php"
    • CLSID = "{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]
    • (Default) = ""
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
    • start = "nom crée aléatoirement "

  • [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping]
    • {9034A523-D068-4BE8-A284-9DF278BE776E} = 0x00002001
  • [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DAED9266-8C28-4C1C-8B58-5C66EFF1D302}]
    • DisplayName = "Search"
    • URL = "http://www.searchagate.com/index.php?b=1&t=0&q={searchTerms}"
  • [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    • DefaultScope = "{DAED9266-8C28-4C1C-8B58-5C66EFF1D302}"

Values created

  • [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping]
    • NextId = 0x00002002

 

ATTENTION
Even if you can remove the virus by using an Antivirus application, it does not restore the Internet Explorer's settings from where the idea of using a patch.
 
 
  Link  
 

Télécharger

 
 

Latest fixs:

  • cftmonn.exe (ksven, Autorun.dhl)
  • sbsm.exe, softhomepage.com (sbsm.dll,sbmdl.dll)
  • Virtual Made (Virtual Maid.dll, http://www.searchmaid.com)
  • VirusHeat (VirusHeat 4.3.exe, VirusHeat.exe)
  • MonaRonaDona (srvspool.exe, registrycleaner2008.exe)
  • Noooh (Sys.exe, ComSys.dll)
  • NetSky (FVProtect.exe,FirewallSvr.exe,netstats.exe) and all its variants
  • Tavo.exe (tavo0.dll, tavo1.dll) and all its variants
  • Patty.exe (S0UNDMANS.EXE,1sasrv.dll,adsldps.dll,twain.dll,realsched.exe)
  • Kxvo.exe and all its variants
  • Kavo.exe and all its variants
  • VirtuMonde (VirtuMondo, Vundo, TROJ_VUNDO, TROJ_MEREDROP,DL.Small.ADIB)
  • Sohanad fix (SCVVHSOT.exe, svchost.exe) (W32.Imaut.A, TROJ_AUTORUN.AH, Worm.Sohanad)
  • SdBot fix (ctfmonn.exe) (Backdoor.SdBot, Sdbot.worm.gen.a)
  • Amvo.exe (3o.exe, y82td3td.com, i.cmd, fppg1.exe, ekugb3.bat...) and its variants other than already proposed here
Top  
 
 
COPYRIGHT (C) 2008 NET STUDIO, ALL RIGHT RESERVED