maandag 12 januari 2009

Haxfix version 5.0.55

Version 5.0.55
2009 01 12

Infection: Goldun

O20 - Winlogon Notify: sbfxi - C:\WINDOWS\system32\sbfxi.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sbfxi

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\surrd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\surrd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\surrd.sys]

system32\a9k.bin
system32\sbfxi.dll
system32\surrd.sys



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

Geen opmerkingen: