http://net-studio.org
>> Patch>
softhomepage.com Fix (sbsm.exe, sbsm.dll)
Entrez les termes que vous recherchez.
Web
net-studio.org
Envoyer un formulaire de recherche
Patchs for virus
Tutorials
Tips
Forum
Windows Optimum
USB FireWall
Boost Google Search
Information
Download files automatically on the Internet
Create an entry in the register to be launched automatically
Integrates into IE (Browser Helper Object)
Run as service
Make softhomepage.com your home page and connects to the site through the 80 port
File
<System>\sbmdl.dll
<System>\sbsm.dll
Registry
Keys created :
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DAED9266-8C28-4C1C-8B58-5C66EFF1D302}
Values created :
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}\InprocServer32]
(Default) = "%System%\sbmdl.dll"
ThreadingModel = "Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C109800-A5D5-438F-9640-18D17E168B88}]
xxx = "xxx"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}]
MenuText = "IE Anti-Spyware"
Exec = "http://www.gateietool.com/redirect.php"
CLSID = "{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]
(Default) = ""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
start = "nom crée aléatoirement "
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping]
{9034A523-D068-4BE8-A284-9DF278BE776E} = 0x00002001
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DAED9266-8C28-4C1C-8B58-5C66EFF1D302}]
DisplayName = "Search"
URL = "http://www.searchagate.com/index.php?b=1&t=0&q={searchTerms}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
DefaultScope = "{DAED9266-8C28-4C1C-8B58-5C66EFF1D302}"
Values created
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping]
NextId = 0x00002002
ATTENTION
Even if you can remove the virus by using an Antivirus application, it does not restore the Internet Explorer's settings from where the idea of using a patch.
Link
Latest fixs:
cftmonn.exe
(ksven, Autorun.dhl)
sbsm.exe, softhomepage.com
(sbsm.dll,sbmdl.dll)
Virtual Made
(Virtual Maid.dll, http://www.searchmaid.com)
VirusHeat
(VirusHeat 4.3.exe, VirusHeat.exe)
MonaRonaDona
(srvspool.exe, registrycleaner2008.exe)
Noooh
(Sys.exe, ComSys.dll)
NetSky
(FVProtect.exe,FirewallSvr.exe,netstats.exe) and all its variants
Tavo.exe
(tavo0.dll, tavo1.dll) and all its variants
Patty.exe
(S0UNDMANS.EXE,1sasrv.dll,adsldps.dll,twain.dll,realsched.exe)
Kxvo.exe
and all its variants
Kavo.exe
and all its variants
VirtuMonde
(VirtuMondo, Vundo, TROJ_VUNDO, TROJ_MEREDROP,DL.Small.ADIB)
Sohanad fix
(SCVVHSOT.exe, svchost.exe) (W32.Imaut.A, TROJ_AUTORUN.AH, Worm.Sohanad)
SdBot fix
(ctfmonn.exe) (Backdoor.SdBot, Sdbot.worm.gen.a)
Amvo.exe
(3o.exe, y82td3td.com, i.cmd, fppg1.exe, ekugb3.bat...) and its variants other than already proposed here
COPYRIGHT (C) 2008 NET STUDIO, ALL RIGHT RESERVED