↓
 

Computer Aid

Ph: 0402 133 866

  • Home
  • Blog
  • Contact
  • Web Services
    • Websites
    • SEO
    • Hosting
    • Domain Names
    • Portfolio
Home→Tags smitfraud

Tag Archives: smitfraud

Another smitfraud variant: advrepnok.dll hupsrv.dll bindmod.dll sdrmod.dll wtopmod.exe softwarereferral.com

Computer Aid Posted on 8 November, 2007 by Luigi Martin8 November, 2007

I removed a spyware infection, and I’m called out again about 6 days later with another infection. The PC is a newish Dell PC running Norton IS, and it has about 4 user accounts.

At first I worry that I didn’t clean out the infection correctly the first time, but I later find the dates of the infected files are from 2 days ago (Sunday 03/11/2007).

I can’t run task manager (its been disabled), and starting IE results in a browser hijack attempt (luckily winpatrol pops up and warns of a home page change to softwarereferral.com). 

Norton IS doesn’t start correctly (no icons in the taskbar).

I decide to go into safe mode. I login as Administrator

I then run bhodemon, and winpatrol and notice that advrepnok.dll is regarded as an unknown BHO… a google search shows its another smitfraud variant.

The file is in the c:windows folder… a sort by date order shows 5 files with the same date (and very similar time): 3rd November 2007.

The files are: advrepnok.dll, hupsrv.dll, bindmod.dll, sdrmod.dll, wtopmod.exe

I rename them to *.dlll or *.exee so that they cannot be “found” (ie I add an extra character to the extension)

I then scan the registry with regedit, and rename any reference to the 5 files to *.dl or *.ex (ie I remove a character from the extension)

Next, I use bhodemon to disable any bho related to the 5 bad files. I also check using winpatrol, just to be sure

I restart into normal XP mode, and Norton gives a brief complaint about some other trojan, and then settles down. Otherwise everything seems to work perfectly.

Now I just go to regedit and re-enable taskmanager.

Continue reading →

Posted in Technical | Tagged advrepnok.dll, bindmod.dll, hupsrv.dll, sdrmod.dll, smitfraud, softwarereferral.com, wtopmod.exe

smitfraud variant (mxduo.dll, safewebnavigate.com) and how to remove

Computer Aid Posted on 16 September, 2007 by Luigi Martin16 September, 2007

A customer called, saying her daughters laptop is almost unusable, due to some infection.

When I get there, the daughter tells me that she noticed the laptop was running slow, and was generating many popup messages about a virus infection… So she bought and installed norton internet security.

Norton says everything is fine, and it couldn’t see a problem. I installed avg antispyware and windows defender, and they also said nothing was wrong with the system (I did a scan in safe mode, and everything was fully updated)

After some digging around, I eventually disabled some suspicious-looking startup programs, but after a reboot, the popups still poped-up (particularly browser hijacks to www.safewebnavigate.com)!

It was getting close to 2 hours, so I asked if I could complete the removal back at the office… By that stage, I had figured out that the problem seemed to revolve around a file called mxduo.dll

Further analysis showed that this was yet another smitfraud variant. I also found excellent advice on how to deal with it on:

http://forums.techguy.org/malware-removal-hijackthis-logs/616547-winavxx-exe-tried-delete-safemode.html

And it seems this variant was first seen on 25 aug 2007 (I saw it on 8 sep 2007… just 2 weeks later!). The chances of norton detecting it are virtually nil.

It seems that the area I had overlooked in doing a manual cleanup, was the O21 section of hijackthis.

O21 is otherwise known as SSODL (ShellServiceObjectDelayLoad), an undocumented autorun method,  found in the windows registry at: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad

After removing the relevant startup methods, and removing the infected files (in safe mode), the PC became a lot more responsive.

Posted in Technical | Tagged mxduo.dll, safewebnavigate.com, smitfraud, SSODL

Archives

Categories

Recent Comments

  • Sue Jones on outlook error 0X800ccc0e while sending emails
  • Blair Newmann on AdSmartMedia advertising
  • Private Investigator in GTA on Divorce, consent orders, and superannuation splits: getting the wording correct

Tags

802.11g ADSL amd android bigpond broadband bsod defender dell email exitjunction firefox firewall gmail Google google contacts ie7 infection internet connection ISP laptop Linux m1188a ntldr is missing office 2007 outlook outlook express password power supply problems ram registry repair install sata scam slow telstra thunderbird usb vista wifi windows 7 wireless wordpress xp
Copyright © 2005-2015 Computer Aid
↑