My blog has moved!

You should be automatically redirected in 6 seconds. If not, visit
http://kavachai.com
and update your bookmarks.

Wednesday, January 28, 2009

Mistical trojan mmmsfusf.dll

Two days ago for some reason my computer stopped working as expected. Every time I was open results of Google search a page to arclane.com opened. I scaned computer with antivirus and took a look in internet. But it didn't help much. Unfortunally I didn't have much time and decided to come back to the problem at the end of this week.

And guess what happened today? A compete nightmare every time I used my internet browser (which is IE 5) it took forever to open a page. Just like in old times of dial-up.
I couldn't live with such a problem even a day. After some inverstigation I found a dll called mmmgfwgf.dll in my system32 directory. Creation date + strange name + search in google.com = looks like it is my problem. And again I found just a little information. Actually I found just one link: http://www.threatexpert.com/report.aspx?md5=4d013b3b1e327cc9582acc74f65ac150. It explains what this, but there were nothing about repairing the system.

My first try to remove this trojan finished with the crash of system. Fortunally I created an image before starting experimenting.
Second try was much better:
  • First of all I used CopyLock to remove mmmsfusf.dll from system32.
  • Then I changed value of "AppInit_DLLs" registery value that is located in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows". I simply removed path to mmmsfusf.dll from it.
  • And finally I removed "HKEY_CURRENT_USER\Software\Microsoft\WinPathCRC" key.
And I can work again!

No comments:

Post a Comment