Version 5.0.712009 03 24Infection: GoldunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jstdrv
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jscript
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\jscript.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\jscript.sys
Files:
system32\ak9.bin
system32\jscript.sys
system32\jstdrv.dll
Infection: GoldunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ipfwrd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ipfwrd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ipfwrd.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipfwrd.sys
Files:
system32\ak9.bin
system32\ipfwrd.dll
system32\ipfwrd.sys
Use haxfix to remove this infection.
Removalinstructions for this infection, you can find
here or
here.