Version 5.0902009 12 19Infection: GoldunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\simdpp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\simdpx
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\simdpx.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\simdpx.sys
Files:
system32\mod_st.dat
system32\simdpx.sys
system32\simdpp.dll
Infection: GoldunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\saifx
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sorrd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sorrd.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sorrd.sys
Files:
system32\saifx.dll
system32\sorrd.sys
Infection Goldun:[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\linkap
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\linkax
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\linkax.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\linkax.sys
Files:
system32\linkap.dll
system32\linkax.sys