<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6525630119168364793</id><updated>2012-02-08T20:38:30.637+01:00</updated><category term='Preventie'/><category term='Malware'/><category term='haxfix'/><category term='Music'/><title type='text'>Moment of Surrender</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default?start-index=101&amp;max-results=100'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>101</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2597327564766493618</id><published>2012-02-08T20:35:00.002+01:00</published><updated>2012-02-08T20:38:30.641+01:00</updated><title type='text'>Financial malware</title><content type='html'>Mooie reportage van de BBC ivm Financial malware: &lt;br /&gt;&lt;a href="http://www.youtube.com/watch?feature=player_embedded&amp;v=EUGTlVSefeo#!"&gt;Financial malware&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2597327564766493618?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.youtube.com/watch?feature=player_embedded&amp;v=EUGTlVSefeo#!' title='Financial malware'/><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2597327564766493618/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2597327564766493618&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2597327564766493618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2597327564766493618'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2012/02/mooie-reportage-van-de-bbc-ivm.html' title='Financial malware'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5352937573903825454</id><published>2011-11-20T12:07:00.002+01:00</published><updated>2011-11-20T12:09:56.758+01:00</updated><title type='text'>Reglooks</title><content type='html'>New version up: 0.993&lt;br /&gt;Download &lt;a href="http://users.telenet.be/marcvn/tools/reglooks.exe"&gt;reglooks&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5352937573903825454?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5352937573903825454/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5352937573903825454&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5352937573903825454'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5352937573903825454'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2011/11/reglooks.html' title='Reglooks'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-785910271994506458</id><published>2011-10-29T22:05:00.000+02:00</published><updated>2011-10-29T22:06:42.272+02:00</updated><title type='text'>Reglooks</title><content type='html'>New version up: 0992&lt;br /&gt;&lt;a href="http://users.telenet.be/marcvn/spyware/1022467.htm"&gt;&lt;br /&gt;Download reglooks.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-785910271994506458?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/785910271994506458/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=785910271994506458&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/785910271994506458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/785910271994506458'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2011/10/reglooks_9967.html' title='Reglooks'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-184687753130024700</id><published>2011-10-29T17:19:00.001+02:00</published><updated>2011-10-29T17:21:36.805+02:00</updated><title type='text'>Reglooks</title><content type='html'>New version up: 0.991.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://users.telenet.be/marcvn/spyware/1022467.htm"&gt;Download reglooks.exe &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-184687753130024700?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/184687753130024700/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=184687753130024700&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/184687753130024700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/184687753130024700'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2011/10/reglooks_29.html' title='Reglooks'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-4541323123588330609</id><published>2011-10-21T17:29:00.001+02:00</published><updated>2011-10-21T17:34:26.282+02:00</updated><title type='text'>Reglooks</title><content type='html'>Reglooks version 0.990.&lt;br /&gt;&lt;br /&gt;I added a few new things to the tool.&lt;br /&gt;&lt;a href="http://users.telenet.be/marcvn/spyware/1022467.htm"&gt;http://users.telenet.be/marcvn/spyware/1022467.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download: &lt;a href="http://users.telenet.be/marcvn/tools/reglooks.exe"&gt;reglooks.exe&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-4541323123588330609?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://users.telenet.be/marcvn/spyware/1022467.htm' title='Reglooks'/><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/4541323123588330609/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=4541323123588330609&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4541323123588330609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4541323123588330609'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2011/10/reglooks.html' title='Reglooks'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3568632559555600233</id><published>2011-04-23T19:57:00.002+02:00</published><updated>2011-04-23T19:59:22.607+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix Version 5.097</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;5.097&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2011 04 23&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;Bugfix.&lt;br /&gt;Ready for windows 7 SP1.&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3568632559555600233?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3568632559555600233/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3568632559555600233&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3568632559555600233'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3568632559555600233'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2011/04/haxfix-version-5097.html' title='HaxFix Version 5.097'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7163041066659145173</id><published>2011-01-09T13:26:00.002+01:00</published><updated>2011-01-09T13:31:00.692+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.096</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:officedocumentsettings&gt;   &lt;o:targetscreensize&gt;800x600&lt;/o:TargetScreenSize&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:hyphenationzone&gt;21&lt;/w:HyphenationZone&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;NL-BE&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:enableopentypekerning/&gt;    &lt;w:dontflipmirrorindents/&gt;    &lt;w:overridetablestylehps/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="0" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:Standaardtabel;  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Verdana&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="EN-US"&gt;&lt;span style="font-weight: bold;"&gt;5.096&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2011 01 09&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Updated the appinit detection.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7163041066659145173?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7163041066659145173/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7163041066659145173&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7163041066659145173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7163041066659145173'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2011/01/haxfix-version-5096.html' title='HaxFix version 5.096'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3590546189884348706</id><published>2010-10-10T11:08:00.003+02:00</published><updated>2011-01-09T13:32:06.078+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix  version 5.095</title><content type='html'>&lt;span style="font-weight: bold;"&gt;5.095&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2010 10 10&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Haxdoor&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\boot32&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\boot32.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\boot32.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\boot32.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3590546189884348706?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3590546189884348706/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3590546189884348706&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3590546189884348706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3590546189884348706'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2010/10/haxfix-version-5095.html' title='HaxFix  version 5.095'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5880768988440274319</id><published>2010-04-04T13:11:00.002+02:00</published><updated>2010-04-04T13:15:04.029+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix Version 5.094</title><content type='html'>&lt;span style="font-weight: bold;"&gt;5.094&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2010 04 04&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Updated the detection for random services.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5880768988440274319?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5880768988440274319/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5880768988440274319&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5880768988440274319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5880768988440274319'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2010/04/haxfix-version-5094.html' title='HaxFix Version 5.094'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7413064762872770284</id><published>2010-01-28T12:46:00.001+01:00</published><updated>2010-01-28T12:48:28.897+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.93</title><content type='html'>&lt;span style="font-weight: bold;"&gt;5.093&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2010 01 28&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lixgap&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lixgax&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lixgax.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lixgax.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a99k.bin&lt;br /&gt;system32\lixgax.sys&lt;br /&gt;system32\lixgap.dll&lt;br /&gt;system32\mod_st.dat&lt;br /&gt;windows\pxysdb.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7413064762872770284?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7413064762872770284/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7413064762872770284&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7413064762872770284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7413064762872770284'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2010/01/haxfix-version-5093.html' title='Haxfix version 5.0.93'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8810153793640955433</id><published>2010-01-19T09:21:00.002+01:00</published><updated>2010-01-19T09:25:02.634+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.92</title><content type='html'>&lt;span style="font-weight: bold;"&gt;5.092&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2010 01 20&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxop81&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lingap&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lingax&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lingax.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lingax.sys&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{209a54af-418a-4b1e-a68d-21fc33494303}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E14B6F5F-3F90-4871-AC57-18DFE244EE8F}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1E88A88-9B9B-45D8-9CDC-39A934318E46}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3063ABBF-1257-4B23-A672-9E29A508A2FA}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\nnurri9.dll&lt;br /&gt;system32\jtaqhghuc47.dll&lt;br /&gt;system32\xxupuykyz65.dll&lt;br /&gt;system32\ywud.dll&lt;br /&gt;system32\ijqwv45.dll&lt;br /&gt;system32\lingap.dll&lt;br /&gt;system32\lingax.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8810153793640955433?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8810153793640955433/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8810153793640955433&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8810153793640955433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8810153793640955433'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2010/01/haxfix-version-5092.html' title='Haxfix version 5.0.92'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7534850880483154888</id><published>2010-01-09T14:05:00.003+01:00</published><updated>2010-01-09T14:10:04.475+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.91</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Version 5.091&lt;br /&gt;2010 01 09&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Haxfix has been updated for &lt;span style="font-weight: bold;"&gt;Windows Vista&lt;/span&gt; (32-bit) en &lt;span style="font-weight: bold;"&gt;Windows 7&lt;/span&gt; (32-bit).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7534850880483154888?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7534850880483154888/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7534850880483154888&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7534850880483154888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7534850880483154888'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2010/01/haxfix-version-5091.html' title='Haxfix version 5.0.91'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1936941656250700313</id><published>2009-12-24T14:17:00.003+01:00</published><updated>2009-12-24T14:42:50.860+01:00</updated><title type='text'>Greetings...</title><content type='html'>&lt;a href="http://www.u2.com/news/title/seasons-greetings?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+U2comNews+%28U2.com+News%29&amp;amp;utm_content=Google+International"&gt;They said there'd be snow at Christmas...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To everybody who occasionally takes a look at this blog.&lt;br /&gt;I wish you a merry Christmas and happy New Year.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.u2.com/news/title/seasons-greetings?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+U2comNews+%28U2.com+News%29&amp;amp;utm_content=Google+International"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1936941656250700313?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1936941656250700313/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1936941656250700313&amp;isPopup=true' title='2 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1936941656250700313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1936941656250700313'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/12/greetings.html' title='Greetings...'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1841954698855571561</id><published>2009-12-19T19:37:00.001+01:00</published><updated>2009-12-19T19:39:50.215+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.90</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.090&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 12 19&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\simdpp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\simdpx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\simdpx.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\simdpx.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\mod_st.dat&lt;br /&gt;system32\simdpx.sys&lt;br /&gt;system32\simdpp.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\saifx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sorrd&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sorrd.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sorrd.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\saifx.dll&lt;br /&gt;system32\sorrd.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection Goldun:&lt;/span&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\linkap&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\linkax&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\linkax.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\linkax.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\linkap.dll&lt;br /&gt;system32\linkax.sys&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1841954698855571561?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1841954698855571561/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1841954698855571561&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1841954698855571561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1841954698855571561'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/12/haxfix-version-5090.html' title='Haxfix version 5.0.90'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7743525571423083954</id><published>2009-10-31T09:35:00.001+01:00</published><updated>2009-10-31T09:36:44.530+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.89</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.089&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 10 31&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\semdpp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\semdpx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semdpx.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semdpx.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\semdpp.dll&lt;br /&gt;system32\semdpx.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7743525571423083954?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7743525571423083954/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7743525571423083954&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7743525571423083954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7743525571423083954'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/10/haxfix-version-5089.html' title='Haxfix version 5.0.89'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1194882894708504326</id><published>2009-10-07T20:25:00.001+02:00</published><updated>2009-10-07T20:27:25.411+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.88</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.088&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 10 07 &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: SpyBanker&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9ad1747-7b19-4dea-bc02-0ab12c4fc468}&lt;br /&gt;system32\GbpDist.dl&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sebdpp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sebdpx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sebdpx.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sebdpx.sys&lt;br /&gt;%Windir%\pxysdb.dat&lt;br /&gt;system32\sebdpp.dll&lt;br /&gt;system32\sebdpx.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1194882894708504326?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1194882894708504326/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1194882894708504326&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1194882894708504326'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1194882894708504326'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/10/haxfix-version-5088.html' title='Haxfix version 5.0.88'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6382813165512081213</id><published>2009-09-12T19:16:00.001+02:00</published><updated>2009-09-12T19:17:27.907+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.87</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.087&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 09 12&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Updated the appinit detection.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6382813165512081213?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6382813165512081213/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6382813165512081213&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6382813165512081213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6382813165512081213'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/09/haxfix-version-5087.html' title='Haxfix version 5.0.87'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1378939353613226378</id><published>2009-09-11T21:18:00.003+02:00</published><updated>2009-09-12T19:18:04.054+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.86</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.086&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 09 11&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Haxdoor&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pdx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pdx32&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pdx32.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\pdx32.sys&lt;br /&gt;system32\cfgh.ini&lt;br /&gt;system32\pdx.dll&lt;br /&gt;system32\pdx32.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f675c54f-60b6-4fd8-bba0-443c493305eb}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\rant32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1378939353613226378?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1378939353613226378/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1378939353613226378&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1378939353613226378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1378939353613226378'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/09/haxfix-version-5086.html' title='Haxfix version 5.0.86'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6317807814646147627</id><published>2009-08-12T19:07:00.003+02:00</published><updated>2009-08-12T19:11:07.958+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.85</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(0, 0, 0);"&gt;Version 5.085&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 0);"&gt;2009 08 12&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91704C3F-A675-4e0e-9FB7-B03E005EDDA7}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\systran.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rgadtm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rgadta&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rgadta.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rgadta.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\rgadtm.dll&lt;br /&gt;system32\rgadta.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6317807814646147627?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6317807814646147627/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6317807814646147627&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6317807814646147627'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6317807814646147627'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/08/haxfix-version-5085.html' title='Haxfix version 5.0.85'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5016482779704649071</id><published>2009-07-26T19:49:00.002+02:00</published><updated>2009-07-26T19:52:18.693+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.84</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.084&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 07 26&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rbadmm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rbadmm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rbadmm.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rbadmm.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\rbadma.sys&lt;br /&gt;system32\rbadmm.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rbadzm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rbadza&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rbadza.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rbadza.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\rbadza.sys&lt;br /&gt;system32\rbadzm.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED78190A-DFB2-4336-A960-979CD88F7A8D}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Amble&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61DC85A0-4A32-4c38-92CF-24652B3F416C}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{544735C9-AE13-4721-9DE7-D529BE675038}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\locsock32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFF01325-0FC2-4749-8914-FBF0565AD9CC}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\jbnmcd.dll&lt;br /&gt;system32\jbnmck.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{480FA3BD-A372-4f65-9F8A-15DF38F4E2AB}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\pcmfd3.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{996D4E16-517F-474a-870F-F882C6133C47}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\gacaq32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5016482779704649071?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5016482779704649071/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5016482779704649071&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5016482779704649071'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5016482779704649071'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/07/version-5.html' title='Haxfix version 5.0.84'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8277172667513063195</id><published>2009-06-27T21:32:00.000+02:00</published><updated>2009-06-27T21:33:07.424+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.83</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.083&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 06 27&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{46B35542-A3CF-4cca-9C0B-259DB2FFF078}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8277172667513063195?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8277172667513063195/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8277172667513063195&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8277172667513063195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8277172667513063195'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/06/haxfix-version-5083.html' title='Haxfix version 5.0.83'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7923373425511965432</id><published>2009-06-13T11:21:00.001+02:00</published><updated>2009-06-13T11:21:57.617+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.82</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.082.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 06 13&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection Goldun.&lt;/span&gt;&lt;br /&gt;Updated appinit detection&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7923373425511965432?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7923373425511965432/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7923373425511965432&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7923373425511965432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7923373425511965432'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/06/haxfix-version-5082.html' title='Haxfix version 5.0.82'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-4750107085148646031</id><published>2009-06-09T20:12:00.001+02:00</published><updated>2009-06-13T11:22:19.128+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.81</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.081&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 06 09&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection Goldun&lt;/span&gt;&lt;br /&gt;Updated appinit detection.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-4750107085148646031?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/4750107085148646031/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=4750107085148646031&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4750107085148646031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4750107085148646031'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/06/haxfix-version-5081.html' title='Haxfix version 5.0.81'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8981284369372358437</id><published>2009-06-06T13:28:00.001+02:00</published><updated>2009-06-09T20:15:39.681+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.80</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.080&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 06 06&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7B303E07-7C7D-45ad-8D42-EB41C9CBC908}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\krpod32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0D75B38F-C5F6-444e-ABB3-FD0F77201602}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\c2d.dat&lt;br /&gt;system32\idm.dat&lt;br /&gt;system32\jc.dat&lt;br /&gt;system32\q1.dat&lt;br /&gt;system32\lpxg&lt;br /&gt;system32\nk.dat&lt;br /&gt;system32\udinfrm.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F66FC8B-DCF6-4db0-908A-2D566D7EF66D}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\afha&lt;br /&gt;system32\blkernel.dll&lt;br /&gt;system32\c2d.dat&lt;br /&gt;system32\ck.dat&lt;br /&gt;system32\idm.dat&lt;br /&gt;system32\jc.dat&lt;br /&gt;system32\nk.dat&lt;br /&gt;system32\q1.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91673BA2-1DC6-411c-9CD0-150750A2ECB5}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\armad32.dll&lt;br /&gt;system32\c2d.dat&lt;br /&gt;system32\ck.dat&lt;br /&gt;system32\idm.dat&lt;br /&gt;system32\lkjd&lt;br /&gt;system32\nk.dat&lt;br /&gt;system32\q1.dat&lt;br /&gt;system32\xd.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10C0B0C0-FC01-473b-8EBB-4376353F96E4}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\bekbn.dll&lt;br /&gt;system32\ck.dat&lt;br /&gt;system32\idm.dat&lt;br /&gt;system32\q1.dat&lt;br /&gt;system32\xd.dat&lt;br /&gt;system32\fkas&lt;br /&gt;system32\nk.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8AA4410F-A3EE-4279-8F2C-4BFAB8CEB231}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\c2d.dat&lt;br /&gt;system32\ck.dat&lt;br /&gt;system32\idm.dat&lt;br /&gt;system32\q1.dat&lt;br /&gt;system32\xd.dat&lt;br /&gt;system32\krmnat.dll&lt;br /&gt;system32\pis&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F30B5E7E-CFBB-44fb-A947-226E5A7A4290}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\jhxm32.dll&lt;br /&gt;system32\sft.res&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8981284369372358437?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8981284369372358437/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8981284369372358437&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8981284369372358437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8981284369372358437'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/06/haxfix-version-5080.html' title='Haxfix version 5.0.80'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1364745276650043133</id><published>2009-05-21T10:23:00.000+02:00</published><updated>2009-05-21T10:24:52.478+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.78</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.078&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 05 21&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{7C7EFE99-C71F-48b8-8CC8-BA506CA76A33}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\xagkf32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{1925C7E1-5540-4675-8198-8A2779D4072A}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\msfgw32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{D6E0FAFC-2B61-4753-B3DA-D83BE96A2C39}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\mashtuic32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1364745276650043133?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1364745276650043133/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1364745276650043133&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1364745276650043133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1364745276650043133'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/05/haxfix-version-5078.html' title='Haxfix version 5.0.78'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8189476516796876570</id><published>2009-05-10T12:23:00.002+02:00</published><updated>2009-05-21T10:25:38.630+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.77</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.77&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 05 &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;10&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{FFCC6792-7219-4ff8-98D2-5D632A5FA01C}&lt;br /&gt;system32\al.txt&lt;br /&gt;system32\dz1.txt&lt;br /&gt;system32\kixm32.dll&lt;br /&gt;system32\opxd&lt;br /&gt;system32\p1.txt&lt;br /&gt;system32\r24.txt&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{C3221010-0AD7-4c09-B17B-EDCFFDA4B7F9}&lt;br /&gt;system32\fow64.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: SpyBanker&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{DCF49866-8F81-4F5F-8193-7EC75A2AB321}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper obJects\{73364D99-1240-4dff-B11A-67E448373048}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\ipv6mons.dll&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8189476516796876570?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8189476516796876570/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8189476516796876570&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8189476516796876570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8189476516796876570'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/05/haxfix-version-5077.html' title='Haxfix version 5.0.77'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3811127549450287895</id><published>2009-05-01T19:17:00.001+02:00</published><updated>2009-05-01T19:18:19.029+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.76</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.76&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 05 01&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rksocket&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rkskt&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rkskt.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rkskt.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\hrpdcf.bin&lt;br /&gt;system32\rkskt.sys&lt;br /&gt;system32\rksocket.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmod11&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\pmod11.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3811127549450287895?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3811127549450287895/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3811127549450287895&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3811127549450287895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3811127549450287895'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/05/version-5.html' title='Haxfix version 5.0.76'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-851263975120502380</id><published>2009-04-29T20:13:00.001+02:00</published><updated>2009-04-29T20:14:43.118+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.75</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.75&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 04 29&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dbbin&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dbbin&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dbbin.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dbbin.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\dbbin.dll&lt;br /&gt;system32\dbbin.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-851263975120502380?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/851263975120502380/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=851263975120502380&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/851263975120502380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/851263975120502380'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/04/version-5.html' title='Haxfix version 5.0.75'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7264289967378629828</id><published>2009-04-18T16:26:00.001+02:00</published><updated>2009-04-18T16:27:32.376+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.74</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.74&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 04 18&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"Microsoft Update Machine"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ramdmm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ramdma&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ramdma.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ramdma.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;a99k.bin&lt;br /&gt;ramdma.sys&lt;br /&gt;ramdmm.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ctasys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mmcta&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mmcta.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mmcta.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;ctasys.dll&lt;br /&gt;mmcta.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection Goldun:&lt;/span&gt;&lt;br /&gt;Detection updated for the variants that are using the orphaned service registrykeys.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;Detection updated for the variants that are using the appinit key.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7264289967378629828?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7264289967378629828/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7264289967378629828&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7264289967378629828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7264289967378629828'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/04/haxfix-version-5074.html' title='HaxFix version 5.0.74'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-4831931328243012307</id><published>2009-04-12T19:00:00.002+02:00</published><updated>2009-04-12T19:02:51.996+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.73</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.73&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 04 12&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ntpdxt&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntpdxt&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ntpdxt.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ntpdxt.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;ntpdxt.dll&lt;br /&gt;ntpdxt.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sphub&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sphub&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sphub.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sphub.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\sphub.dll&lt;br /&gt;system32\sphub.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{56BB6D01-7BD5-4458-A4AE-F03DF643D6EE}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{C2C3339C-2559-4b81-B9EF-CBAF906D5DA2}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;bxx.txt&lt;br /&gt;sft.res&lt;br /&gt;system32\smstf.dll&lt;br /&gt;system32\trinf32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-4831931328243012307?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/4831931328243012307/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=4831931328243012307&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4831931328243012307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4831931328243012307'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/04/haxfix-version-5073.html' title='HaxFix version 5.0.73'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8462097710361044328</id><published>2009-03-26T21:24:00.001+01:00</published><updated>2009-03-26T21:24:48.949+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.72</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.72&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 03 26&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;Detection updated for the variants that are using the appinit key.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8462097710361044328?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8462097710361044328/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8462097710361044328&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8462097710361044328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8462097710361044328'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/03/haxfix-version-5072.html' title='HaxFix version 5.0.72'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6642010430188542352</id><published>2009-03-24T20:42:00.001+01:00</published><updated>2009-03-24T20:43:22.823+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.71</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.71&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 03 24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jstdrv&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jscript&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\jscript.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\jscript.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\ak9.bin&lt;br /&gt;system32\jscript.sys&lt;br /&gt;system32\jstdrv.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ipfwrd&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ipfwrd&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ipfwrd.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipfwrd.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\ak9.bin&lt;br /&gt;system32\ipfwrd.dll&lt;br /&gt;system32\ipfwrd.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6642010430188542352?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6642010430188542352/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6642010430188542352&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6642010430188542352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6642010430188542352'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/03/haxfix-version-5071.html' title='HaxFix version 5.0.71'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3578788904182956947</id><published>2009-03-22T17:18:00.000+01:00</published><updated>2009-03-22T17:20:13.915+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.70</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.70&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 03 22&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{36DBC179-A19F-48F2-B16A-6A3E19B42A87}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pptpr&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pptpr&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pptpr.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\pptpr.sys&lt;br /&gt;Detection updated for the variants that are using the orphaned service registrykeys.&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\pptpr.dll&lt;br /&gt;system32\pptpr.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3578788904182956947?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3578788904182956947/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3578788904182956947&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3578788904182956947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3578788904182956947'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/03/haxfix-version-5070.html' title='HaxFix version 5.0.70'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3568602221962423086</id><published>2009-03-17T19:04:00.000+01:00</published><updated>2009-03-17T19:05:12.812+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.69</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.69&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 03 17&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{013DFA9D-4A04-4907-B043-46BDE4B090E6}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\al.txt&lt;br /&gt;system32\dz1.txt&lt;br /&gt;system32\mld&lt;br /&gt;system32\p1.txt&lt;br /&gt;system32\r24.txt&lt;br /&gt;system32\sdd.txt&lt;br /&gt;system32\utrmk.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3568602221962423086?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3568602221962423086/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3568602221962423086&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3568602221962423086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3568602221962423086'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/03/haxfix-version-5069.html' title='HaxFix version 5.0.69'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6935917203444910016</id><published>2009-03-16T19:31:00.001+01:00</published><updated>2009-03-16T19:33:11.778+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.68</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.068&lt;br /&gt;2009 03 16&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vmbox2&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vmbox2&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmbox2.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmbox2.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\vmbox2.dll&lt;br /&gt;system32\vmbox2.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6935917203444910016?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6935917203444910016/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6935917203444910016&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6935917203444910016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6935917203444910016'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/03/haxfix-version-5068.html' title='HaxFix version 5.0.68'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7395242030367997732</id><published>2009-03-14T17:10:00.001+01:00</published><updated>2009-03-17T19:05:54.139+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.67</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.67&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 03 14&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 102);"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\684EE1DB-CD52-4ca9-9CCF-93D5F6B419BA&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\kmsvc32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun:&lt;/span&gt;&lt;br /&gt;Detection updated for the variants that are using the appinit key.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7395242030367997732?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7395242030367997732/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7395242030367997732&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7395242030367997732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7395242030367997732'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/03/haxfix-version-5067.html' title='HaxFix version 5.0.67'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-59343156578985052</id><published>2009-02-24T19:54:00.001+01:00</published><updated>2009-02-24T19:56:36.077+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.66</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.66&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 02 24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\utsync&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\uvsync&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uvsync.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uvsync.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\hrpdcf.bin&lt;br /&gt;system32\utsync.dll&lt;br /&gt;system32\uvsync.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-59343156578985052?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/59343156578985052/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=59343156578985052&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/59343156578985052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/59343156578985052'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/02/version-5.html' title='HaxFix version 5.0.66'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-49348295015029042</id><published>2009-02-22T20:14:00.002+01:00</published><updated>2009-02-22T20:16:52.102+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.65</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.65&lt;br /&gt;2009 02 22&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection Goldun:&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\i975gl&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mjva&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mjva.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mjva.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\i975gl.dll&lt;br /&gt;system32\mjva.sys&lt;br /&gt;system32\z98.bin&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection Goldun:&lt;/span&gt;&lt;br /&gt;Detection updated for the variants that are using the orphaned service registrykeys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-49348295015029042?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/49348295015029042/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=49348295015029042&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/49348295015029042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/49348295015029042'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/02/haxfix-version-5065.html' title='HaxFix version 5.0.65'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6241486285042320055</id><published>2009-02-16T20:40:00.002+01:00</published><updated>2009-02-16T20:44:44.025+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.64</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.64&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 02 16&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 0); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\eeekp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eeekp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\eeekp.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\eeekp.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\eeekp.sll&lt;br /&gt;system32\eeekp.sys&lt;br /&gt;system32\wdh.bin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6241486285042320055?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6241486285042320055/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6241486285042320055&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6241486285042320055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6241486285042320055'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/02/haxfix-version-5064.html' title='HaxFix version 5.0.64'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8885553435598508938</id><published>2009-02-08T19:56:00.001+01:00</published><updated>2009-02-08T19:59:57.331+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.63</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.63&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 02 08&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CC2F638-99FF-45d2-97C7-E30E83CF04D2}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\ak&lt;br /&gt;system32\alog.txt&lt;br /&gt;system32\bb1.dat&lt;br /&gt;system32\cs.dat&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rc.dat&lt;br /&gt;system32\tb.dr&lt;br /&gt;system32\ipv6sp.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8885553435598508938?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8885553435598508938/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8885553435598508938&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8885553435598508938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8885553435598508938'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/02/haxfix-version-5063.html' title='HaxFix version 5.0.63'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5787950507123770408</id><published>2009-02-06T23:24:00.003+01:00</published><updated>2009-02-06T23:35:46.829+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.62</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.62&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 02&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6607E676-1BDE-4cb3-9913-4DC5EBCAE35E}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\alog.txt&lt;br /&gt;system32\conf.dat&lt;br /&gt;system32\cs.dat&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rc.dat&lt;br /&gt;system32\unifff.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5787950507123770408?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5787950507123770408/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5787950507123770408&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5787950507123770408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5787950507123770408'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/02/haxfix-version-5062.html' title='Haxfix version 5.0.62'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3424385308669599604</id><published>2009-02-05T20:44:00.000+01:00</published><updated>2009-02-05T20:45:40.731+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.61</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.61&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 02 05&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;O20 - Winlogon Notify: tomto - C:\WINDOWS\system32\tomto.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tomto&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tomto&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tomto.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tomto.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\tomto.dll&lt;br /&gt;system32\tomto.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;O20 - Winlogon Notify: iokey - C:\WINDOWS\system32\iokey.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iokey&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iokey&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iokey.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\iokey.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\iokey.dll&lt;br /&gt;system32\iokey.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3424385308669599604?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3424385308669599604/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3424385308669599604&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3424385308669599604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3424385308669599604'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/02/haxfix-version-5061.html' title='Haxfix version 5.0.61'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2744722493755045276</id><published>2009-02-04T18:58:00.001+01:00</published><updated>2009-02-04T19:00:10.406+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>HaxFix version 5.0.60</title><content type='html'>&lt;span style="color: rgb(0, 0, 0); font-weight: bold;"&gt;Version 5.0.60&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0); font-weight: bold;"&gt;2009 02 04&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Detection updated for the variants that are using the orphaned service registrykeys and the appinit key.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2744722493755045276?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2744722493755045276/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2744722493755045276&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2744722493755045276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2744722493755045276'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/02/haxfix-version-5060.html' title='HaxFix version 5.0.60'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-778064079595645590</id><published>2009-01-21T12:12:00.004+01:00</published><updated>2009-01-21T12:14:26.966+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.59</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Verion 5.0.59&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 01 21&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rssync&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdsync&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rdsync.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsync.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\hrpdcf.bin&lt;br /&gt;system32\rdsync.sys&lt;br /&gt;system32\rssync.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Banker Trojan&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6458C00E-EF7F-4f06-9E06-49EA923386FD}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\AmSoft&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\kj32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan/Ambler&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{89F2C12A-027A-4de3-88F6-9F31A1C0F17C}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\alog.txt&lt;br /&gt;system32\bb1.dat&lt;br /&gt;system32\cs.dat&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rc.dat&lt;br /&gt;system32\rs&lt;br /&gt;system32\tb.dr&lt;br /&gt;system32\xlk.dll&lt;br /&gt;system32\xwa.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-778064079595645590?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/778064079595645590/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=778064079595645590&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/778064079595645590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/778064079595645590'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/01/haxfix-version-5059.html' title='Haxfix version 5.0.59'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7075157026611829001</id><published>2009-01-18T15:48:00.000+01:00</published><updated>2009-01-18T15:49:09.056+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.58</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.58&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 01 18&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Scanning the whole drive for random used files, can take a while.&lt;br /&gt;I added the possibility to use a quick scan to search for random used files in the most important windows folders.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7075157026611829001?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7075157026611829001/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7075157026611829001&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7075157026611829001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7075157026611829001'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/01/haxfix-version-5058.html' title='Haxfix version 5.0.58'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-4602328934898459375</id><published>2009-01-14T18:45:00.001+01:00</published><updated>2009-01-14T18:45:47.923+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.57</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.057&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 01 14&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Detection updated for the variants that are using the orphaned service registrykeys.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-4602328934898459375?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/4602328934898459375/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=4602328934898459375&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4602328934898459375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4602328934898459375'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/01/haxfix-version-5057.html' title='Haxfix version 5.0.57'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5787185246488188492</id><published>2009-01-13T20:27:00.000+01:00</published><updated>2009-01-13T20:28:07.483+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.56</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.56&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 01 13&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O2 - BHO: Microsoft copyright - {4D88F653-4230-4af1-A6A3-54B8D3CD7DF4} - msfacat32.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D88F653-4230-4af1-A6A3-54B8D3CD7DF4}]&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5EB96953-7D02-4594-AC15-F55FC9AACFCB}]&lt;br /&gt;"StubPath"="rundll32 msfacat32.dll,InitModule"&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\msfacat32.dll&lt;br /&gt;system32\sft.res&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O2 - BHO: Microsoft copyright - {085E2757-F41D-42d1-B4CC-9DADF7113BBC} - aj32.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{085E2757-F41D-42d1-B4CC-9DADF7113BBC}]&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0EA88F0F-B698-4ab1-8DBC-EBE2CD00927F}]&lt;br /&gt;"StubPath"="rundll32 aj32.dll,InitO"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\aj32.dll&lt;br /&gt;system32\alog.txt&lt;br /&gt;system32\bb1.dat&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rc.dat&lt;br /&gt;system32\lp&lt;br /&gt;windows\inform.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Troj/Ambler&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6825FAC3-D7D2-4045-97A2-87DF42CB6728}]&lt;br /&gt;"StubPath"="rundll32 kcms.dll,InitO"&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\kcms.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5787185246488188492?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5787185246488188492/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5787185246488188492&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5787185246488188492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5787185246488188492'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/01/haxfix-version-5056.html' title='Haxfix version 5.0.56'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3285251230368497442</id><published>2009-01-12T19:24:00.001+01:00</published><updated>2009-01-12T19:25:14.783+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.55</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.55&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 01 12&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: sbfxi - C:\WINDOWS\system32\sbfxi.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sbfxi&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\surrd&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\surrd.sys]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\surrd.sys]&lt;br /&gt;&lt;br /&gt;system32\a9k.bin&lt;br /&gt;system32\sbfxi.dll&lt;br /&gt;system32\surrd.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3285251230368497442?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3285251230368497442/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3285251230368497442&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3285251230368497442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3285251230368497442'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/01/haxfix-version-5055.html' title='Haxfix version 5.0.55'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1251497273280003754</id><published>2009-01-10T22:20:00.001+01:00</published><updated>2009-01-10T22:20:50.630+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.54</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.54&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 01 10 &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;Detection added for other variants that use random orphaned service keys.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1251497273280003754?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1251497273280003754/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1251497273280003754&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1251497273280003754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1251497273280003754'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/01/haxfix-version-5054.html' title='Haxfix version 5.0.54'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7270468416482303771</id><published>2009-01-08T22:00:00.005+01:00</published><updated>2009-01-12T19:33:11.225+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.53</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.53&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2009 01 08&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Detection added for the ones using the orphaned driver keys.&lt;br /&gt;&lt;br /&gt;Sample from the logfiles.&lt;br /&gt;&lt;br /&gt;Logfile option 1:&lt;br /&gt;…&lt;br /&gt;checking for random used files and services&lt;br /&gt;C:\WINDOWS\system32\1.tmp&lt;br /&gt;C:\WINDOWS\system32\drivers\gmer.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEMSWEEP2&lt;br /&gt;Imagepath    REG_EXPAND_SZ      \??\C:\WINDOWS\System32\1.tmp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gmer&lt;br /&gt;Imagepath    REG_EXPAND_SZ      System32\DRIVERS\gmer.sys&lt;br /&gt;…[/quote]&lt;br /&gt;&lt;br /&gt;Logfile option 2:&lt;br /&gt;&lt;br /&gt;…&lt;br /&gt;--- checking for random used files and services ---&lt;br /&gt;these files and services will not be deleted by HaxFix&lt;br /&gt;C:\WINDOWS\system32\1.tmp&lt;br /&gt;C:\WINDOWS\system32\drivers\gmer.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEMSWEEP2&lt;br /&gt;Imagepath    REG_EXPAND_SZ      \??\C:\WINDOWS\System32\1.tmp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gmer&lt;br /&gt;Imagepath    REG_EXPAND_SZ      System32\DRIVERS\gmer.sys&lt;br /&gt;…&lt;br /&gt;&lt;br /&gt;Haxfix will not delete these services and files.&lt;br /&gt;If you want to remove them, use SC DELETE &lt;servicename&gt;, reboot the computer and delete the file(s).&lt;br /&gt;&lt;br /&gt;These are samples from a logfile. In this case the infection was using the legit service gmer and the legit filename gmer.sys. (Gmer is a legit program, a rootkitscanner.)&lt;br /&gt;The other service used by this infection is memsweep2. Not necessarily a bad service, but here used by the infection.&lt;br /&gt;&lt;br /&gt;&lt;/servicename&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7270468416482303771?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7270468416482303771/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7270468416482303771&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7270468416482303771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7270468416482303771'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2009/01/haxfix-version-5053.html' title='Haxfix version 5.0.53'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5716581674788023940</id><published>2008-12-29T18:36:00.002+01:00</published><updated>2008-12-29T18:37:50.122+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.52</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.52&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 29&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Trojan Nethell&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O2 - BHO: Gamburg provider - {59D94AAD-0A67-417e-969B-8311296E8364} - condw32.dll&lt;br /&gt;O2 - BHO: Gamburg provider - {59D94AAD-0A67-417e-969B-8311296E8364} - contrld.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59D94AAD-0A67-417e-969B-8311296E8364}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\alog.txt&lt;br /&gt;system32\condw32.dll&lt;br /&gt;system32\contrld.dll&lt;br /&gt;system32\msft.txt&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rc.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: swapdm - C:\WINDOWS\system32\swapdm.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\swapdm&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swapm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\swapm.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\swapm.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\k86.bin&lt;br /&gt;system32\swapdm.dll&lt;br /&gt;system32\swapm.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Other related files:&lt;/span&gt;&lt;br /&gt;system32\vkj.bin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5716581674788023940?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5716581674788023940/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5716581674788023940&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5716581674788023940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5716581674788023940'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/haxfix-version-5052.html' title='Haxfix version 5.0.52'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3188227757486829720</id><published>2008-12-28T10:30:00.003+01:00</published><updated>2009-01-02T22:13:57.101+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.51</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.51&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;28&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: TrojanSpy:Win32/Ambler.D - Trojan Nethell&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O2 - BHO: Microsoft copyright - {0DDD155F-B89C-4f34-90F0-53D7BD21A37C} - mscont32.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0DDD155F-B89C-4f34-90F0-53D7BD21A37C}&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5EB96953-7D02-4594-AC15-F55FC9AACFCB}]&lt;br /&gt;"StubPath"= "rundll32 mscont32.dll,InitModule"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\mscont32.dll&lt;br /&gt;system32\sft.res&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Troj/Ambler-G&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O2 - BHO: Microsoft copyright - {32C620D6-CC10-4e6a-9715-BACACD5B0E61} - sxmg4.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32C620D6-CC10-4e6a-9715-BACACD5B0E61}&lt;br /&gt;&lt;br /&gt;O21 - SSODL: WebProxy - {A744F16C-B2D5-4138-81A2-085CDFCDE83A} - sxmg4.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]&lt;br /&gt;"WebProxy"="{A744F16C-B2D5-4138-81A2-085CDFCDE83A}"&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A744F16C-B2D5-4138-81A2-085CDFCDE83A}]&lt;br /&gt;"StubPath"="rundll32 sxmg4.dll,InitModule"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\lt.res&lt;br /&gt;system32\sft.res&lt;br /&gt;system32\sn.txt&lt;br /&gt;system32\sxmg4.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Troj/Ambler-G&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O2 - BHO: Microsoft copyright - {FFFFFFFF-BBBB-4146-86FD-A722E8AB3489} - sockins32.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}&lt;br /&gt;&lt;br /&gt;O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]&lt;br /&gt;"WebProxy"="{66186F05-BBBB-4a39-864F-72D84615C679}"&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{66186F05-BBBB-4a39-864F-72D84615C679}]&lt;br /&gt;"StubPath"="rundll32 sockins32.dll,InitModule"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\lt.res&lt;br /&gt;system32\sft.res&lt;br /&gt;system32\sn.txt&lt;br /&gt;system32\sockins32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: SpyBanker - Trojan Nethell&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{01BE3276-1420-45b5-9762-172C5C184EB7}]&lt;br /&gt;"StubPath"= "rundll32 svchstb.dll,InitO&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\svchstb.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Spybanker - Trojan Nethell&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67525E1B-5B8E-41d4-AFCC-03CC04F141FA}]&lt;br /&gt;"StubPath"="rundll32 rbsgam.dll,InitO"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\log.txt&lt;br /&gt;system32\bb1.dat&lt;br /&gt;system32\kaxs.dat&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rbsgam.dll&lt;br /&gt;system32\rc.dat&lt;br /&gt;%Windir%\inform.dat&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;&lt;br /&gt;Other files:&lt;/span&gt;&lt;br /&gt;system32\kaxs.dat&lt;br /&gt;system32\Spool\hpprintqueue.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3188227757486829720?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3188227757486829720/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3188227757486829720&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3188227757486829720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3188227757486829720'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/version-5_28.html' title='Haxfix version 5.0.51'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6551206905155437241</id><published>2008-12-27T13:01:00.004+01:00</published><updated>2008-12-27T15:27:53.316+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.50</title><content type='html'>&lt;span style="color: rgb(0, 0, 0); font-weight: bold;"&gt;Version 5.0.50&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0); font-weight: bold;"&gt;2008 12 27&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: modzlib - C:\WINDOWS\system32\modzlib.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\modzlib&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gzvba.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\gzvba.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\modzlib.dll&lt;br /&gt;system32\gzvba.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Trojan-Downloader.Win32.BHO.aej - TrojanSpy:Win32/Ambler.D - Trojan-Dropper.Win32.Ambler&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O2 - BHO: Google plugin - {18CACF0E-72A4-4be1-AA42-DC2ECDB197F1} - C:\WINDOWS\system32\kcms.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18CACF0E-72A4-4be1-AA42-DC2ECDB197F1}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\alog.txt&lt;br /&gt;system32\bb1.dat&lt;br /&gt;system32\kcms.dll&lt;br /&gt;system32\mx&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rc.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Virus.Neshta - Trojan-Banker.Win32.Banker.ghd - TSPY_BANKER.LJU TrojanSpy:Win32/Ambler.A - Trojan-Spy.Win32.Banker &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\accs.txt&lt;br /&gt;system32\cookie.dat&lt;br /&gt;system32\ps.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6551206905155437241?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6551206905155437241/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6551206905155437241&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6551206905155437241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6551206905155437241'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/haxfix-version-5050.html' title='Haxfix version 5.0.50'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6532261469404426078</id><published>2008-12-26T11:00:00.004+01:00</published><updated>2008-12-27T13:06:21.496+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.49</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.49&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 26&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: syncps - C:\WINDOWS\system32\syncps.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\syncps&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\syncmc&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\syncmc.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\syncmc.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\syncmc.sys&lt;br /&gt;system32\syncps.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6532261469404426078?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6532261469404426078/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6532261469404426078&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6532261469404426078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6532261469404426078'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/haxfix-version-5049.html' title='Haxfix version 5.0.49'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-719271185312236913</id><published>2008-12-24T14:44:00.002+01:00</published><updated>2008-12-27T13:07:15.227+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.48</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.48&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Updated the appinit detection.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Spy.Banker - TrojanSpy:Win32/Ambler.D&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63845B64-69B6-4b9a-9461-C59B2AFDC0A9}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\vgf32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-719271185312236913?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/719271185312236913/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=719271185312236913&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/719271185312236913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/719271185312236913'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/haxfix-version-5048.html' title='Haxfix version 5.0.48'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6940256164209367223</id><published>2008-12-23T20:43:00.004+01:00</published><updated>2008-12-27T13:08:02.507+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.47</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.47&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 23&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 51); font-weight: bold;"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Updated the appinit detection.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Spy.Banker - TrojanSpy:Win32/Ambler.D&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F6E0EF5F-5F03-43f9-8E02-BBAAA95EAA9C}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\nods32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: modgzip - C:\WINDOWS\system32\modgzip.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\modgzip\modgzip&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\modgzip.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6940256164209367223?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6940256164209367223/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6940256164209367223&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6940256164209367223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6940256164209367223'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/haxfix-version-5047.html' title='Haxfix version 5.0.47'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3012604160539485358</id><published>2008-12-20T15:45:00.001+01:00</published><updated>2008-12-27T13:09:37.134+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.46</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.46&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 20&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: snjava - C:\WINDOWS\system32\snjava.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\snjava&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\java2.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\java2.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\snjava.dll&lt;br /&gt;system32\java2.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3012604160539485358?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3012604160539485358/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3012604160539485358&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3012604160539485358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3012604160539485358'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/haxfix-version-5046.html' title='Haxfix version 5.0.46'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6885158557281998465</id><published>2008-12-19T22:34:00.002+01:00</published><updated>2008-12-27T13:09:56.166+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.45</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.45&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 19&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gzvba.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\gzvba.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gzvba&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\gzvba.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6885158557281998465?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6885158557281998465/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6885158557281998465&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6885158557281998465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6885158557281998465'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/version-5.html' title='Haxfix version 5.0.45'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8853632397733167847</id><published>2008-12-18T19:10:00.003+01:00</published><updated>2008-12-27T13:10:15.567+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.44</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.44&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 12 18&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: xliftm - C:\WINDOWS\system32\xliftm.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xliftm&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xlift.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\xlift.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xlift&lt;br /&gt;&lt;br /&gt;system32\cardb.dat&lt;br /&gt;system32\xlift.sys&lt;br /&gt;system32\xliftm.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8853632397733167847?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8853632397733167847/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8853632397733167847&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8853632397733167847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8853632397733167847'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/12/haxfix-version-5044.html' title='Haxfix version 5.0.44'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5145905819301435276</id><published>2008-11-30T08:51:00.004+01:00</published><updated>2008-12-27T13:11:15.664+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.43</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Version 5.0.43&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2008 11 30&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: mckwave - C:\WINDOWS\system32\mckwave.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mckwave&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kwave&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\kwave.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\kwave.sys&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\mckwave.dll&lt;br /&gt;system32\kwave.sys&lt;br /&gt;system32\drivers\mrxdavv.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Haxdoor&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sksdrvr2&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\sksdrvr2.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: wrapkm - C:\WINDOWS\system32\wrapkm.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wrapkm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wrapk&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wrapk.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wrapk.sys&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;"advap32"=""%Temp%\load2.exe" /r"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\wrapkm.dll&lt;br /&gt;system32\wrapk.sys&lt;br /&gt;windows\wiaserviv.log&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Infection: Goldun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: sbrige - C:\WINDOWS\system32\sbrige.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sbrige&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sbunit.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sbunit.sys&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sbunit&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;"rs32net"="%System%\rs32net.exe"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\rs32net.exe&lt;br /&gt;system32\sbrige.dll&lt;br /&gt;system32\sbunit.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5145905819301435276?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5145905819301435276/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5145905819301435276&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5145905819301435276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5145905819301435276'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5043.html' title='Haxfix version 5.0.43'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6754557750478998618</id><published>2008-11-29T19:25:00.003+01:00</published><updated>2008-11-30T08:54:48.568+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix down</title><content type='html'>I removed haxfix this afternoon from my site and from bleeping, because the tool can not delete some of the latest goldun and haxdoor variants.&lt;br /&gt;&lt;br /&gt;I found a solution, and the tool will be available again soon&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6754557750478998618?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6754557750478998618/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6754557750478998618&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6754557750478998618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6754557750478998618'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-down.html' title='Haxfix down'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6722396505370059928</id><published>2008-11-24T19:19:00.001+01:00</published><updated>2008-11-24T19:19:59.986+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.42</title><content type='html'>Version 5.0.42&lt;br /&gt;2008 11 24&lt;br /&gt;Infection: Haxdoor&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;"Microsoft Update" = "system.exe"&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices&lt;br /&gt;"Microsoft Update" = "system.exe"&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;"Microsoft Update" = "system.exe"&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32/system.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: SpyBanker - Trojan Nethell&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABADC07C-9990-405a-AA24-2C209B50AE79}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32/svchstb.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6722396505370059928?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6722396505370059928/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6722396505370059928&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6722396505370059928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6722396505370059928'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5042.html' title='Haxfix version 5.0.42'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6332533475657361600</id><published>2008-11-21T15:17:00.000+01:00</published><updated>2008-11-21T15:18:09.483+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.41</title><content type='html'>Version 5.0.41&lt;br /&gt;2008 11 21&lt;br /&gt;&lt;br /&gt;Added the file mmsystem.dll to the whitelist.&lt;br /&gt;It wil not be detected anymore as a "possible infected file".&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: priarsz - C:\WINDOWS\SYSTEM32\priarsz.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\priarsz&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6332533475657361600?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6332533475657361600/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6332533475657361600&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6332533475657361600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6332533475657361600'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5041.html' title='Haxfix version 5.0.41'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5585118820581299655</id><published>2008-11-17T19:23:00.002+01:00</published><updated>2008-11-17T19:26:19.495+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.40</title><content type='html'>Version 5.0.40&lt;br /&gt;2008 11 17&lt;br /&gt;&lt;br /&gt;Infection: SpyBanker - Trojan Nethell&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2FDA60DF-6D94-4f16-A48C-3C4EC57FEF58}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\nokia32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: Spy.Banker - Infostealer.Bancos&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{890C7964-9320-4055-BE11-7D7B562A6417}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\mstrans.dll&lt;br /&gt;system32\mstrans1.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;O20 - Winlogon Notify: netwrp - C:\WINDOWS\SYSTEM32\netwrp.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\netwrp&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netwp&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\netwrp.dll&lt;br /&gt;system32\netwp.sys&lt;br /&gt;system32\a9k.bin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5585118820581299655?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5585118820581299655/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5585118820581299655&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5585118820581299655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5585118820581299655'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5040.html' title='Haxfix version 5.0.40'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6307823289504905937</id><published>2008-11-12T22:06:00.000+01:00</published><updated>2008-11-12T22:07:29.326+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.39</title><content type='html'>Version 5.0.39&lt;br /&gt;2008 11 12&lt;br /&gt;&lt;br /&gt;Infection: SpyBanker - Trojan Nethell&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8FD36B2-A25B-47e3-9477-82557F5F5995}&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ECBA18CA-FF22-464c-A963-70BEC79D2485}&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\cukert.dll&lt;br /&gt;system32\masyan.dll&lt;br /&gt;system32\savec32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: SpyBanker&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60FD4F58-4748-48f6-B661-5FCE71B0D907}&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\torm.dll&lt;br /&gt;system32\torm1.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6307823289504905937?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6307823289504905937/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6307823289504905937&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6307823289504905937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6307823289504905937'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5039.html' title='Haxfix version 5.0.39'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3112380250878315485</id><published>2008-11-12T19:50:00.002+01:00</published><updated>2008-11-12T19:53:53.762+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.38</title><content type='html'>Version 5.0.38&lt;br /&gt;2008 11 12&lt;br /&gt;&lt;br /&gt;Infection: Haxdoor&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: mt49hub - C:\WINDOWS\SYSTEM32\mt49hub.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mt49hub&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msvtch&lt;br /&gt;"ImagePath" = "system32\msvtch.sys"&lt;br /&gt;"DisplayName" = "Kernel Mode SND msvtcher"&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\msvtch.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\msvtch.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\adrnln.bin &lt;br /&gt;system32\mt49hub.dll&lt;br /&gt;system32\msvtch.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: SpyBanker&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{850C7964-9320-4055-BE11-7D7B562A6417}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\Helper.dll &lt;br /&gt;system32\Helper1.dll &lt;br /&gt;system32\mstrans.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3112380250878315485?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3112380250878315485/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3112380250878315485&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3112380250878315485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3112380250878315485'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5038.html' title='Haxfix version 5.0.38'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3765530313024442012</id><published>2008-11-11T13:40:00.001+01:00</published><updated>2008-11-11T13:42:23.829+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.37</title><content type='html'>Version 5.0.37&lt;br /&gt;2008 11 11&lt;br /&gt;&lt;br /&gt;Infection: Haxdoor&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\status]&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tage32]&lt;br /&gt;"ImagePath" = "system32\tage32.sys"&lt;br /&gt;"DisplayName = "NGate service"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\mprexe.exe&lt;br /&gt;system32\snowx.ini &lt;br /&gt;system32\status.dll&lt;br /&gt;system32\tage32.sys &lt;br /&gt;Windows\svchost32.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: SpyBanker - Trojan Nethell&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68DF1496-983B-9ED5-03A6-F78E3267FB52}]&lt;br /&gt;&lt;br /&gt;Files: &lt;br /&gt;system32\gh.dat &lt;br /&gt;system32\nokia32.dll&lt;br /&gt;system32\symdb32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3765530313024442012?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3765530313024442012/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3765530313024442012&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3765530313024442012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3765530313024442012'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5037.html' title='Haxfix version 5.0.37'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3257136191164882549</id><published>2008-11-09T14:52:00.003+01:00</published><updated>2008-11-11T13:43:18.038+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.36</title><content type='html'>Version 5.0.36&lt;br /&gt;2008 11 09&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;&lt;br /&gt;Added a new variant that is using the appinit key to load.&lt;br /&gt;Filename is semi-random.&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]&lt;br /&gt;"AppInit_DLLs" = "%System%\mms******.dll"&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;%System%\DefaultColor.info&lt;br /&gt;%System%\mms******.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3257136191164882549?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3257136191164882549/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3257136191164882549&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3257136191164882549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3257136191164882549'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5036.html' title='Haxfix version 5.0.36'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5068880168734400481</id><published>2008-11-05T18:21:00.001+01:00</published><updated>2008-11-05T18:23:05.433+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.35</title><content type='html'>Version 5.0.35&lt;br /&gt;2008 11 05&lt;br /&gt;&lt;br /&gt;Infection: Spybanker - Trojan Nethell&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BEEFD1C-446F-48a7-A7C7-C8E5986A9760}]&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\rbsgam.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5068880168734400481?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5068880168734400481/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5068880168734400481&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5068880168734400481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5068880168734400481'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5035.html' title='Haxfix Version 5.0.35'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7084256437060497786</id><published>2008-11-02T18:53:00.000+01:00</published><updated>2008-11-02T18:54:11.534+01:00</updated><title type='text'>Haxfix Version 5.0.34</title><content type='html'>Version 5.0.34&lt;br /&gt;2008 11 02&lt;br /&gt;&lt;br /&gt;Infection: Goldun.&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ctlsys]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mmctl]&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\ctlsys.dll&lt;br /&gt;system32\mmctl.sys &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7084256437060497786?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7084256437060497786/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7084256437060497786&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7084256437060497786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7084256437060497786'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5034.html' title='Haxfix Version 5.0.34'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1596003140515310267</id><published>2008-11-01T09:40:00.002+01:00</published><updated>2008-11-01T09:45:45.930+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.33</title><content type='html'>Version 5.0.33&lt;br /&gt;2008 11 01&lt;br /&gt;&lt;br /&gt;Infection Haxdoor / Goldun.&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: kryostm - C:\Windows\System32\kryostm.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kryostm]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kryo2.sys]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\kryo2.sys]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kryo2]&lt;br /&gt;"DisplayName" = "CPU FUN Controller"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\kryostm.dll&lt;br /&gt;system32\kryo2.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1596003140515310267?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1596003140515310267/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1596003140515310267&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1596003140515310267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1596003140515310267'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/11/haxfix-version-5033.html' title='Haxfix version 5.0.33'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1921893962824970924</id><published>2008-10-31T20:25:00.001+01:00</published><updated>2008-11-01T09:29:40.450+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.32</title><content type='html'>Version 5.0.32&lt;br /&gt;2008 10 31&lt;br /&gt;&lt;br /&gt;Infection Goldun.&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mdhash]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mdhsh]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mdhsh.sys]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mdhsh.sys]&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\mdhash.dll&lt;br /&gt;system32\mdhsh.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1921893962824970924?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1921893962824970924/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1921893962824970924&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1921893962824970924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1921893962824970924'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5032.html' title='Haxfix Version 5.0.32'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7413847592895033641</id><published>2008-10-26T16:39:00.001+01:00</published><updated>2008-10-26T16:45:44.555+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.31</title><content type='html'>Version 5.0.31:&lt;br /&gt;2008 10 26&lt;br /&gt;&lt;br /&gt;Infection: Goldun.&lt;br /&gt;&lt;br /&gt;O21 - SSODL: oledll - {12345B67-1234-1234-D123-7F84D123BC7D} - C:\WINDOWS\System32\wmldap.dll&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]&lt;br /&gt;"oledll" = "{12345B67-1234-1234-D123-7F84D123BC7D}"&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;System32\wmldap.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: Goldun.&lt;br /&gt;&lt;br /&gt;O18 - Filter hijack: text/html - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urikon.dll&lt;br /&gt;O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urikon.dll&lt;br /&gt;&lt;br /&gt;O18 - Filter hijack: text/html - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urinon.dll&lt;br /&gt;O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urinon.dll&lt;br /&gt;&lt;br /&gt;O18 - Filter hijack: text/html - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\ursnon.dll&lt;br /&gt;O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\ursnon.dll&lt;br /&gt;&lt;br /&gt;O18 - Filter hijack: text/html - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urunon.dll&lt;br /&gt;O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urunon.dll&lt;br /&gt;&lt;br /&gt;O18 - Filter hijack: text/html - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urwnon.dll&lt;br /&gt;O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urwnon.dll&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html]&lt;br /&gt;"CLSID = "{DC186800-657F-11D4-B0B5-0050BABFC904}"&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain]&lt;br /&gt;"CLSID" = "{DC186800-657F-11D4-B0B5-0050BABFC904}"&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DC186800-657F-11D4-B0B5-0050BABFC904}]&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;urikon.dll&lt;br /&gt;urinon.dll&lt;br /&gt;ursnon.dll&lt;br /&gt;urunon.dll&lt;br /&gt;urwnon.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection: Goldun.&lt;br /&gt;&lt;br /&gt;scrcki32.dll&lt;br /&gt;&lt;br /&gt;If scrcki32.dll or scrcwi32.dll is present in the system32 folder, the default path for this registrykey will be modified:&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]&lt;br /&gt;&lt;br /&gt;HaxFix will restore the default value: %systemroot%\system32\shell32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Other related files:&lt;br /&gt;%System%\spool\c.ini &lt;br /&gt;%System%\spool\desktops.ini &lt;br /&gt;%System%\spool\dr.ini&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7413847592895033641?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7413847592895033641/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7413847592895033641&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7413847592895033641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7413847592895033641'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5031.html' title='Haxfix version 5.0.31'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2848568183152816509</id><published>2008-10-24T19:56:00.003+02:00</published><updated>2008-11-01T09:30:09.303+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.30</title><content type='html'>Version 5.0.30&lt;br /&gt;&lt;br /&gt;Infection: Spybanker - Trojan.Nethell&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF99D588-3D5F-4194-828A-E03870A57A77}]&lt;br /&gt;&lt;br /&gt;system32\gcomd32.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2848568183152816509?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2848568183152816509/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2848568183152816509&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2848568183152816509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2848568183152816509'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5030.html' title='Haxfix Version 5.0.30'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6758018968481068121</id><published>2008-10-24T19:11:00.005+02:00</published><updated>2008-11-01T09:30:30.453+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.29</title><content type='html'>Version 5.0.29&lt;br /&gt;2008 10 24&lt;br /&gt;&lt;br /&gt;Infection Goldun.&lt;br /&gt;&lt;br /&gt;O2 - BHO: (no name) - {7ACB5731-5839-13AB-EABC-124791194525} - C:\WINDOWS\ system32\msindeo.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7ACB5731-5839-13AB-EABC-124791194525}]&lt;br /&gt;&lt;br /&gt;O21 - SSODL: msindeo.dll - {7ACB5731-5839-13AB-EABC-124791194525} - C:\WINDOWS\ system32\msindeo.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]&lt;br /&gt;"msindeo.dll" = "{7ACB5731-5839-13AB-EABC-124791194525}"&lt;br /&gt;&lt;br /&gt;File:&lt;br /&gt;system32\msindeo.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Infection Haxdoor / Goldun.&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: acpiz - C:\WINDOWS\SYSTEM32\acpiz.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\acpiz]&lt;br /&gt;O20 - Winlogon Notify: hpstp - C:\WINDOWS\SYSTEM32\hpstp.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hpstp]&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\acup]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmram]&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;system32\acpiz.dll&lt;br /&gt;system32\acup.sys&lt;br /&gt;system32\dmram.sys&lt;br /&gt;system32\hpstp.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6758018968481068121?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6758018968481068121/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6758018968481068121&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6758018968481068121'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6758018968481068121'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5029.html' title='Haxfix Version 5.0.29'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3963072421607055394</id><published>2008-10-17T16:58:00.004+02:00</published><updated>2008-11-01T09:30:44.372+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.28</title><content type='html'>Version 5.0.28&lt;br /&gt;2008 10 17&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\netprp]&lt;br /&gt;&lt;br /&gt;%System%\netprp.dll 23724 bytes&lt;br /&gt;%System%\netrp.sys 8512 bytes&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3963072421607055394?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3963072421607055394/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3963072421607055394&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3963072421607055394'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3963072421607055394'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5028.html' title='Haxfix Version 5.0.28'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2685754070671024016</id><published>2008-10-14T19:36:00.004+02:00</published><updated>2008-11-01T09:31:02.364+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.27</title><content type='html'>Version 5.0.27&lt;br /&gt;2008 10 14&lt;br /&gt;&lt;br /&gt;Infection: SpyBanker&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB59DF5-544D-4A1C-8A74-1FD054950140}]&lt;br /&gt;&lt;br /&gt;%System%\ipv6monl.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2685754070671024016?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2685754070671024016/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2685754070671024016&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2685754070671024016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2685754070671024016'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5027.html' title='Haxfix Version 5.0.27'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3138090528893212214</id><published>2008-10-12T20:39:00.005+02:00</published><updated>2008-11-08T13:18:57.343+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix instructions - updated</title><content type='html'>This article is an update for &lt;a href="http://marcvn.blogspot.com/2008/03/haxfix.html"&gt;this&lt;/a&gt; one.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Download&lt;/span&gt;&lt;br /&gt;You can download haxfix from &lt;a href="http://users.telenet.be/marcvn/tools/haxfix.exe"&gt;my site&lt;/a&gt;, or from &lt;a href="http://download.bleepingcomputer.com/marckie/haxfix.exe"&gt;Bleeping computer&lt;/a&gt;. &lt;br /&gt;On both sites you will find always an updated version of the tool.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How to use?&lt;/span&gt;&lt;br /&gt;Download haxfix.exe and save it to your desktop.&lt;br /&gt;Double click on haxfix.exe to run it.&lt;br /&gt;A red "dos window" (dos box) will open with this options:&lt;br /&gt;· 1. Make logfile&lt;br /&gt;·  E. Exit Haxfix&lt;br /&gt;&lt;br /&gt;After running option 1, you will get a new menu with all options:&lt;br /&gt;· 1. Make logfile&lt;br /&gt;· 2. Run auto fix&lt;br /&gt;· 3. Run manual fix&lt;br /&gt;· 4. Run unknow fix&lt;br /&gt;· U. Uninstall Hafix&lt;br /&gt;· E. Exit Haxfix&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option 1. Make logfile.&lt;/span&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;.&lt;/span&gt;&lt;br /&gt;When you use haxfix, always make a logfile first.&lt;br /&gt;The logfile is showing all services, safeboot services and notify keys, that are matching with the current haxdoor/goldun variants.&lt;br /&gt;Haxfix checks for known SSDOL keys related to Goldun.&lt;br /&gt;Haxfix checks for known Browser Helper Objects (BHO) related to Goldun of SpyBanker infections.&lt;br /&gt;Haxfix checks if iexplore.exe is infected with a (known) goldunvariant. If so, it looks for a clean alternative in the dllcache or the tempfolder.&lt;br /&gt;Haxfix checks for known goldunvariants that use the appinit key to load. These filenames are randome. Haxfix checks the MD5 checksum.&lt;br /&gt;Haxfix checks for a lot of related haxdoor and goldunfiles. If present haxfix will list them in the logfile. If the file is rootkitfile, haxfix will mark the file as a rootkitfile.&lt;br /&gt;Catchme.exe has been integrated in haxfix since version 4.43. &lt;br /&gt;The logfile produced by Catchme, will be analysed by haxfix for matching haxdoor- or goldunvariants.&lt;br /&gt;The logfile made by option 1, shows you if a known infection is present on you computer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option 2. Run autofix.&lt;/span&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;.&lt;/span&gt;&lt;br /&gt;Option 2 deletes all haxdoor-notify keys that are found when one, or more then one, matching service/safeboot service is present.&lt;br /&gt;You can use option 2 if the notify keys that are found, are related to haxdoor or goldun.&lt;br /&gt;- If there is a notify key (xxxx) and the letters xxxx are found between the matching services or matching safebootservices, haxfix deletes them&lt;br /&gt;- If there is an unknown notify key or a legit notify key (xxxx) in the logfile, and there are no matching services/safeboot services (xxxx), haxfix will not delete the keys&lt;br /&gt;- If there is an unknown notify key or a legit notify key in the haxdoor-logfile and a matching service, don't run option 2 (auto fix) but use the manual fix (option 3) to add the key(s) manually.&lt;br /&gt;- All known goldunvariants will be deleted with option 2.&lt;br /&gt;- All known SpyBankervariants will be deleted with option 2.&lt;br /&gt;- If ieplore.exe is infected, haxfix can fix this without a reboot.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option 3. Run manual fix.&lt;/span&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;.&lt;/span&gt;&lt;br /&gt;This gives you the possibilty to add one, or if necessary more then one haxdoor key.&lt;br /&gt;When you start option 3, you 'll get a message:&lt;br /&gt;echo Insert the haxdoorkey,&lt;br /&gt;and then press Enter:&lt;br /&gt;Insert the haxdoorkey without the numbers. (Ex: avpe, xtpt, fuxx,...)&lt;br /&gt;When this is a valid choice (there is a check for the services/safeboot services), the key will be added to delete.&lt;br /&gt;Next you have the possibilty to add a new key: Yes (press Y) or No (press N)&lt;br /&gt;When do we use option 3?&lt;br /&gt;Use option 3 if there are:&lt;br /&gt;- unknown or legit notify keys with related services in the haxlog.txt file.&lt;br /&gt;- no notify keys are found, but there are haxdoor related services / safeboot services. (be careful, don't add legit ones, because after reboot they are all gone.)&lt;br /&gt;If you use option 3 to delete a haxdoorvariant, and one or more goldun- or SpyBankervariants are present too, all infections will be deleted.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option 4. Run unknown fix.&lt;/span&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;.&lt;/span&gt;&lt;br /&gt;The logfile produced by Catchme will be analysed by haxfix for hax- or goldunvariants.&lt;br /&gt;If a match is found, you can delete them by using option 4 - remove unknown.&lt;br /&gt;(this only works with the variants that uses notify and services regkeys.)&lt;br /&gt;Variants that are not recognized by haxfix, but are detected by catchme, can now be deleted with haxfix.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option U. Uninstall Haxfix.&lt;/span&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;.&lt;/span&gt;&lt;br /&gt;This will remove all files and folders produced by haxfix.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option E. Exit Haxfix.&lt;/span&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;.&lt;/span&gt;&lt;br /&gt;Use option E to shut down haxfix.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;A few remarks&lt;/span&gt;&lt;br /&gt;If you see this in the logfile: registrysettings failed , use this command: &lt;span style="font-style:italic;"&gt;%systemdrive%\haxfix.exe /reset&lt;/span&gt;&lt;br /&gt;If you don't get the logfile after reboot, use this command: &lt;span style="font-style:italic;"&gt;%systemdrive%\haxfix.exe /after&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;More information about the tool you can find on &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;my website&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3138090528893212214?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3138090528893212214/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3138090528893212214&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3138090528893212214'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3138090528893212214'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html' title='Haxfix instructions - updated'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6452985272315623815</id><published>2008-10-12T11:38:00.002+02:00</published><updated>2008-11-01T09:31:27.292+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.26</title><content type='html'>Version 5.0.26&lt;br /&gt;2008 10 12&lt;br /&gt;&lt;br /&gt;Added detection for these Spy.Bankers: &lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB59DF5-544D-4A1C-8A74-1FD054950140}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D471CEA2-EDEC-4184-BE2E-574DD655DD2D}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7A4C0C8-2BFF-4241-9E8C-92E10245EC28}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68D5BBF9-EED5-4125-B227-55F81540BF4D}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C8A3B994-E27A-42f5-A053-C63799E621FB}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3AAB6591-87DD-424b-AFF2-4685EBF6A5EF}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47D92EB6-E52C-4cda-92A6-2369963F4913}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33161E98-0A6C-4d3c-BD62-3A7D56137F52}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D21D9540-6415-4288-BDD0-4453088D9D38}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4C579E8B-92F1-44d1-9444-66A4355E9386}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{930247B4-16BE-48d2-87DD-86D7FB314639}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF37362D-4088-4c36-AEF1-C167F9CD3DAD}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9249083-6055-476c-A69D-13E110BFEA91}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85911752-BC96-4fff-9121-6EB9D8F438E1}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FED228E-A6F7-49aa-A0BC-76E0A67C53BB}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00EBB3B3-DEAD-4440-B1F8-B09DDDB89EF3}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9916AF04-5F23-4ae8-A2B1-1C4FF50B2A51}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D9A7B3B6-1F8A-4cf9-A20C-BDF427DBDB4A}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-B432-46fc-9143-B82B832B1B14}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{096059FD-99AB-41eb-9E55-59AEB0A3B444}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-DAD2-4a4c-848D-2CBFC6F0FD21}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-D71D-41e4-A699-F506DBD097F0}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-08DF-483c-BD3A-99CBCF44E4DC}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-85A3-452b-B7A8-759AD9B42162}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0DE68A8A-8158-4bde-8F5F-849F00AF31FB}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-8F0D-4322-B01F-B42439E0B71C}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B87D203B-B43D-4af9-9E1B-9C20478CBB74}]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21D7135F-AEE9-45e7-A0C1-791A4654BFF1}]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;alivefor.dll&lt;br /&gt;alog.txt&lt;br /&gt;bagetionwll.dll&lt;br /&gt;bb1.dat&lt;br /&gt;bodrowis.dll&lt;br /&gt;bsn32.dll&lt;br /&gt;bsndcom.dll&lt;br /&gt;btaskv.dll&lt;br /&gt;bulgan.dll&lt;br /&gt;comd32.dll&lt;br /&gt;conf.dat&lt;br /&gt;cookie1.dat&lt;br /&gt;cs.dat&lt;br /&gt;csm.txt&lt;br /&gt;dcrick.dll&lt;br /&gt;dna32v1.dll&lt;br /&gt;drweb32.dll&lt;br /&gt;duis.txt&lt;br /&gt;es.dat&lt;br /&gt;gwin32.dll&lt;br /&gt;haskel32.dll&lt;br /&gt;hnew32.dll &lt;br /&gt;hyperconn.dll&lt;br /&gt;hyperser.dll&lt;br /&gt;IEBHO.dll&lt;br /&gt;IEBHO0B.dll&lt;br /&gt;IEBHO23.dll&lt;br /&gt;ieguard.dll&lt;br /&gt;interns32.dll&lt;br /&gt;jetaccss.dll&lt;br /&gt;jkcom32.dll&lt;br /&gt;jzcom32.dll&lt;br /&gt;kd.txt&lt;br /&gt;knmld.dll&lt;br /&gt;ktaskr.dll&lt;br /&gt;lbbd32.dll&lt;br /&gt;lbcd64.dll&lt;br /&gt;mac.dll&lt;br /&gt;mac1.dll&lt;br /&gt;macaaq.dll&lt;br /&gt;mcac.dll&lt;br /&gt;msindc.dll&lt;br /&gt;mvx.dat&lt;br /&gt;nod32.dll&lt;br /&gt;nortn32.dll&lt;br /&gt;paruisd.dll&lt;br /&gt;pidfenon.dll&lt;br /&gt;pns32.dll&lt;br /&gt;ppret2.dll&lt;br /&gt;roadmap16.dll&lt;br /&gt;ritz8.dll&lt;br /&gt;rozmchild.dll&lt;br /&gt;sac32.dll&lt;br /&gt;siemens32.dll&lt;br /&gt;simcard1.dll&lt;br /&gt;sincim32.dll&lt;br /&gt;sklh.dat&lt;br /&gt;skrb32.dll&lt;br /&gt;smb32.dll&lt;br /&gt;sndcom.dll&lt;br /&gt;strike12.dll&lt;br /&gt;strike45.dll&lt;br /&gt;svc32.dll&lt;br /&gt;swin32.dll&lt;br /&gt;tb.dr&lt;br /&gt;tconn1.dll&lt;br /&gt;tkcom32.dll&lt;br /&gt;tlove2.dll&lt;br /&gt;xd.txt&lt;br /&gt;xmd.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6452985272315623815?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6452985272315623815/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6452985272315623815&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6452985272315623815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6452985272315623815'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5026.html' title='Haxfix Version 5.0.26'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2547372448487850634</id><published>2008-10-09T16:32:00.006+02:00</published><updated>2008-11-01T09:31:42.852+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.25</title><content type='html'>Version 5.0.25&lt;br /&gt;2008 10 09&lt;br /&gt;&lt;br /&gt;Infection: Haxdoor - Infostealer&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\oedes]&lt;br /&gt;system32\oedes.dll &lt;br /&gt;system32\kedes.sys&lt;br /&gt;system32\dadr.dat&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2547372448487850634?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2547372448487850634/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2547372448487850634&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2547372448487850634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2547372448487850634'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5025.html' title='Haxfix Version 5.0.25'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1121853906967300379</id><published>2008-10-05T19:20:00.005+02:00</published><updated>2008-11-01T09:32:01.773+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.24</title><content type='html'>Version 5.0.24&lt;br /&gt;2008 10 05&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mt47hub]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svitch]&lt;br /&gt;mt47hub.dll&lt;br /&gt;svitch.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1121853906967300379?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1121853906967300379/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1121853906967300379&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1121853906967300379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1121853906967300379'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5024.html' title='Haxfix Version 5.0.24'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-4380722686880830800</id><published>2008-10-03T19:33:00.003+02:00</published><updated>2008-11-01T09:32:29.465+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.23</title><content type='html'>Version 5.023&lt;br /&gt;2008 10 03&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;&lt;br /&gt;Added detection for a new kind of files, using the Appinitkey.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-4380722686880830800?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/4380722686880830800/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=4380722686880830800&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4380722686880830800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/4380722686880830800'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5023.html' title='Haxfix Version 5.0.23'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2765518993304465654</id><published>2008-10-02T18:17:00.004+02:00</published><updated>2008-10-18T20:45:34.080+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.22</title><content type='html'>Version 5.0.22&lt;br /&gt;2008 10 02&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D032570A-5F63-4812-A094-87D007C23012}]&lt;br /&gt;%System%\IEBHO.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2765518993304465654?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2765518993304465654/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2765518993304465654&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2765518993304465654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2765518993304465654'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/10/haxfix-version-5022.html' title='Haxfix Version 5.0.22'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2499088941380988192</id><published>2008-09-29T19:11:00.003+02:00</published><updated>2008-10-18T20:45:45.050+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.21</title><content type='html'>Version 5.021&lt;br /&gt;2008 09 29&lt;br /&gt;&lt;br /&gt;Infection: Trojan.Win32.Agent&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"CIJBDYZA"="%systemroot%\CIJBDYZA.exe"&lt;br /&gt;&lt;br /&gt;%System%\tremir.bin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2499088941380988192?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2499088941380988192/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2499088941380988192&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2499088941380988192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2499088941380988192'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/09/haxfix-version-5021.html' title='Haxfix version 5.0.21'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8357993185946818676</id><published>2008-09-22T17:32:00.003+02:00</published><updated>2008-10-18T20:46:00.830+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.20</title><content type='html'>Version 5.0.20&lt;br /&gt;2008 09 22&lt;br /&gt;&lt;br /&gt;Infection: Goldun&lt;br /&gt;&lt;br /&gt;O20 - Winlogon Notify: asplug - C:\WINDOWS\SYSTEM32\asplug.dll&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\asplug]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asplg]&lt;br /&gt;DirectSound KDriver: \??\C:\WINDOWS\SYSTEM32\asplg.sys&lt;br /&gt;&lt;br /&gt;C:\WINDOWS\SYSTEM32\asplg.sys&lt;br /&gt;C:\WINDOWS\SYSTEM32\asplug.dll&lt;br /&gt;&lt;br /&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"solo"=-&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8357993185946818676?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8357993185946818676/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8357993185946818676&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8357993185946818676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8357993185946818676'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/09/haxfix-version-5020.html' title='Haxfix version 5.0.20'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8569384413542560706</id><published>2008-09-18T17:12:00.004+02:00</published><updated>2008-10-18T20:46:19.092+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.19</title><content type='html'>Version 5.0.19&lt;br /&gt;2008 09 18&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gzipmod]&lt;br /&gt;&lt;br /&gt;gzipmod.dll&lt;br /&gt;vbagz.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8569384413542560706?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8569384413542560706/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8569384413542560706&amp;isPopup=true' title='1 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8569384413542560706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8569384413542560706'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/09/haxfix-version-5019.html' title='Haxfix version 5.0.19'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6669772028715825923</id><published>2008-09-15T18:44:00.003+02:00</published><updated>2008-10-18T20:46:41.624+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.18</title><content type='html'>Version 5.018&lt;br /&gt;2008 09 15&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddrawxt]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cabpck]&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"braviax"=-&lt;br /&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"braviax"=-&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;ddrawxt.dll&lt;br /&gt;cabpck.dll &lt;br /&gt;ddraw.sys&lt;br /&gt;krnlcab.sys&lt;br /&gt;braviax.exe&lt;br /&gt;&lt;br /&gt;I changed the script that is checking for othter haxdoor and goldunfiles.&lt;br /&gt;If known rootkitfiles are present, haxfix will find and delete them.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6669772028715825923?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6669772028715825923/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6669772028715825923&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6669772028715825923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6669772028715825923'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/09/haxfix-version-5018.html' title='Haxfix Version 5.0.18'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2242392348400349615</id><published>2008-09-11T17:08:00.004+02:00</published><updated>2008-11-01T09:32:58.037+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.17</title><content type='html'>Version 5.017&lt;br /&gt;2008 09 11&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"WMedia16"="wmedia16.exe"&lt;br /&gt;&lt;br /&gt;%windir%\system32\wmedia16.exe&lt;br /&gt;%windir%\wmedia16.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2242392348400349615?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2242392348400349615/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2242392348400349615&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2242392348400349615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2242392348400349615'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/09/haxfix-version-5017.html' title='Haxfix Version 5.0.17'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-1395346435849282757</id><published>2008-09-11T16:57:00.003+02:00</published><updated>2008-11-01T09:33:17.191+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.16</title><content type='html'>Version 5.016&lt;br /&gt;2008 09 10&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hinet&lt;br /&gt;hinet.dll&lt;br /&gt;ddram.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-1395346435849282757?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/1395346435849282757/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=1395346435849282757&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1395346435849282757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/1395346435849282757'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/09/haxfix-version-5016.html' title='Haxfix Version 5.0.16'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3474892437508217670</id><published>2008-09-08T18:57:00.003+02:00</published><updated>2008-10-18T20:47:36.291+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.15</title><content type='html'>Version 5.015&lt;br /&gt;2008 09 07&lt;br /&gt;&lt;br /&gt;Added:&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\spndt.sys]&lt;br /&gt;[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\spndt.sys]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Fixed a bug with some of the newer goldunvariants that use the notifykey.&lt;br /&gt;Sometimes this notifykey is hidden.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Added detection for these browser helper objects:&lt;br /&gt;{92617934-9abc-def0-0fed-fad682644311}&lt;br /&gt;{68397934-9abc-def0-0fed-fad682644311}&lt;br /&gt;{61468245-A343-CF27-3452-44DF4679BDF1}&lt;br /&gt;{56262124-6251-5625-3072-548536364311}&lt;br /&gt;{46278903-5678-2464-3452-545679092D31}&lt;br /&gt;{68363724-9ABC-DEF0-0FED-FAD682644311}&lt;br /&gt;{92617934-9ABC-DEF0-0FED-FAD48C654321}&lt;br /&gt;{5240864B-FDFE-4563-3514-463926792311}&lt;br /&gt;{13146842-6251-5625-3072-548536364311}&lt;br /&gt;{62457936-6381-6170-3572-468926792311}&lt;br /&gt;{5FCA4D4F-CBDD-4263-3814-463926792311}&lt;br /&gt;{65194BCE-CBDD-4263-3814-463926792311}&lt;br /&gt;{BCD2AF6E-4271-6572-6429-A63F26792311}&lt;br /&gt;{80523A67-ABCD-CF37-3352-54DF4479BDF1}&lt;br /&gt;{4A26217C-5521-3459-2345-AB36721975AF}&lt;br /&gt;{78934132-3451-67A2-8919-678931572311}&lt;br /&gt;{7548953E-4371-6552-6419-A43F26792311}&lt;br /&gt;{73468251-2534-8760-3685-423479197575}&lt;br /&gt;{81463526-1357-4638-2418-538263794561}&lt;br /&gt;{0033669F-AADD-AA59-AA7D-AA4B78888000}&lt;br /&gt;{00534B55-3155-CA4F-B41D-0E922121D03C}&lt;br /&gt;{92617934-9ABC-DEF0-0FED-FAD48C654321}&lt;br /&gt;{00534B55-3155-CA4F-B41D-0E922121D03C}&lt;br /&gt;{BF468356-BB7E-42D7-9F15-4F3B9BCFCED2}&lt;br /&gt;{DABCE839-3831-3818-AF3A-3837BCD324D2}&lt;br /&gt;{DABCE839-3831-3818-AF3A-47D47A738D32}&lt;br /&gt;{DABFC839-F831-3D1A-A33A-A7D4BA7C8D3D}&lt;br /&gt;{0000AC13-3487-1583-C4BE-BE6A839DB000}&lt;br /&gt;{AE1AA4FA-C3A2-4c33-90CD-69DD021A35C8}&lt;br /&gt;&lt;br /&gt;Haxfix deletes the clsid and the file.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Added detection for goldunvariants that use the appinitkey.&lt;br /&gt;Detection is done by MD5 check: 21 different MD5's at this moment.&lt;br /&gt;&lt;br /&gt;Matching files that are not detected by MD5 check, will be enumerated.&lt;br /&gt;May I ask you to upload these file in my bleeping channel: http://www.bleepingcomputer.com/submit-malware.php?channel=11&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3474892437508217670?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3474892437508217670/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3474892437508217670&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3474892437508217670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3474892437508217670'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/09/version-5.html' title='Haxfix version 5.0.15'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7206721282504431269</id><published>2008-08-30T16:33:00.005+02:00</published><updated>2008-10-18T20:47:51.797+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.14</title><content type='html'>Version 5.014&lt;br /&gt;2008 08 30&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;berzk.dll&lt;br /&gt;core3.sys&lt;br /&gt;irptp.sys&lt;br /&gt;meth.bin&lt;br /&gt;meth.plg&lt;br /&gt;powerxt.dll&lt;br /&gt;spndt.sys&lt;br /&gt;xatcore.dll&lt;br /&gt;&lt;br /&gt;Notifykeys:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\powerxt&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xatcore&lt;br /&gt;&lt;br /&gt;Services:&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\core3&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\irptp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\spndt&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\core3.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7206721282504431269?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7206721282504431269/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7206721282504431269&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7206721282504431269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7206721282504431269'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/08/version-5.html' title='Haxfix Version 5.0.14'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-159667963329885902</id><published>2008-08-26T17:06:00.002+02:00</published><updated>2008-10-18T20:48:07.388+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.13</title><content type='html'>Version 5.013&lt;br /&gt;2008 08 26&lt;br /&gt;&lt;br /&gt;Files:&lt;br /&gt;windows\servicez.exe&lt;br /&gt;windows\nvchost.exe&lt;br /&gt;windows\winlogon.exe&lt;br /&gt;system32\alog.txt&lt;br /&gt;system32\crypto64.dll&lt;br /&gt;system32\csrcli32.dll&lt;br /&gt;system32\dpl.txt&lt;br /&gt;%System%\info.txt&lt;br /&gt;system32\NGIX.bin&lt;br /&gt;system32\ntld.bin&lt;br /&gt;system32\preved.bat&lt;br /&gt;system32\ps1.dat&lt;br /&gt;system32\rc.dat&lt;br /&gt;system32\rdata.bin&lt;br /&gt;system32\rhs.bin&lt;br /&gt;system32\scrcwi32.dll&lt;br /&gt;system32\sms.bat&lt;br /&gt;system32\sys32time.dll&lt;br /&gt;system32\winsms.bat&lt;br /&gt;system32\winsms.dll&lt;br /&gt;system32\cryptmd5.dll&lt;br /&gt;system32\datcom.dll&lt;br /&gt;system32\datmps.dll&lt;br /&gt;system32\droute.dll&lt;br /&gt;system32\dwave.sys&lt;br /&gt;system32\dx9sr.sys&lt;br /&gt;system32\emulx86.sys&lt;br /&gt;system32\hdtvu6.dll&lt;br /&gt;system32\hooka.sys&lt;br /&gt;system32\ke64boot.dll&lt;br /&gt;system32\kteproc.sys&lt;br /&gt;system32\mcrwave.dll&lt;br /&gt;system32\necsopp.sys&lt;br /&gt;system32\nkudpn1.sys&lt;br /&gt;system32\pcixm.sys&lt;br /&gt;system32\pcixmm.dll&lt;br /&gt;system32\pemulx86.dll&lt;br /&gt;system32\routew.dll&lt;br /&gt;system32\rotw.sys&lt;br /&gt;system32\stfilter.dll&lt;br /&gt;system32\syncm.sys &lt;br /&gt;system32\syslink.dll&lt;br /&gt;system32\tehlink0.dll&lt;br /&gt;system32\tehlink5.sys&lt;br /&gt;system32\wlite.sys&lt;br /&gt;&lt;br /&gt;Notifykeys:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptmd5&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\datcom&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\datmps&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\droute&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hdtvu6&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ke64boot&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mcrwave&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pcixmm&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pemulx86&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\routew&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\stfilter&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\syslink&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tehlink0&lt;br /&gt;&lt;br /&gt;Services:&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dwave&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dx9sr&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\emulx86&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hooka&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kteproc&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\necsopp&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nkudpn1&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pcixm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rotr&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rotw&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\syncm&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tehlink5&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wlite&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kteproc.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\kteproc.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\syncm.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\syncm.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wlite.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wlite.sys&lt;br /&gt;&lt;br /&gt;Runkeys:&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"nvchost"&lt;br /&gt;"winlogon"&lt;br /&gt;"Windows Services"&lt;br /&gt;"KIT3"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-159667963329885902?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/159667963329885902/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=159667963329885902&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/159667963329885902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/159667963329885902'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/08/haxfix-version-5013.html' title='Haxfix version 5.0.13'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-2363854490471586771</id><published>2008-07-13T11:54:00.004+02:00</published><updated>2008-11-20T20:38:09.165+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Preventie'/><title type='text'>Niets voor niets!</title><content type='html'>Veel computergebruikers maken gebruik van cracks, patches of keygenerators om dat ene progje waar men niet wil voor betalen, toch maar werkend te krijgen.&lt;br /&gt;Niets voor niets, is ook hier de boodschap.&lt;br /&gt;&lt;br /&gt;De meeste trucjes die 'gratis' verkrijgbaar zijn op het internet om niet-gratis software toch werkend te krijgen zijn, zijn helemaal niet gratis. Zonder medeweten van de gebruiker wordt immers malware mee op de computer geïnstalleerd. &lt;br /&gt;Malware die weer andere malware downloadt en installeert. &lt;br /&gt;Malware die je de nodige problemen bezorgd onder de vorm van ongevraagde advertenties.&lt;br /&gt;Deze advertenties zijn vaak vervelend, ze duiken te pas en te onpas op. &lt;br /&gt;Zoekmachines geven niet meer de gewenste zoekresultaten. &lt;br /&gt;Allemaal geen onoverkomelijke problemen, sommigen kunnen er mee leven, anderen niet.&lt;br /&gt;Malware is vaak ook slecht geprogrammeerd, en kan de computer onstabiel en traag maken: de computer is nog nauwelijks werkbaar.&lt;br /&gt;Een hoge prijs die je betaalt om dat ene programma waar je niet wenst voor te betalen toch werkend te krijgen.&lt;br /&gt;De problemen laten oplossen door het computerwinkeltje om de hoek, kost je vaak een aardige duit. Vaak meer dan indien je het programma wat je illegaal wenste te gebruiken, toch zou kopen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nog niet overtuigd?&lt;br /&gt;Met de eerder genoemde nevenwerkingen van cracks en keygenerators houdt het vaak niet op. &lt;br /&gt;De tijd dat malwaremakers je alleen maar brachten naar 'hun favoriete' websites is al lang voorbij.&lt;br /&gt;Indien jouw computer geïnfecteerd is met malware, kan afhankelijk van de infectie, deze ingezet worden in botnetwerken. Je computer kan onder meer gebruikt worden voor het het uitvoeren van DDos aanvallen, of voor het versturen van (massa's) hoeveelheden spam.&lt;br /&gt;Anderen hebben meer controle over de computer dan jij zelf...&lt;br /&gt;Ook kan bepaalde malware zich doorsturen naar jouw contactpersonen die jij dan ook weer de nodige problemen bezorgt. &lt;br /&gt;&lt;br /&gt;Malwaremakers willen echter nog meer. &lt;br /&gt;Men is uit op jouw persoonlijke informatie, jouw gegevens die je op het internet gebruikt om bijvoorbeeld te internetbankieren.&lt;br /&gt;Op diverse manieren probeert men deze informatie van jou te achterhalen en de methoden die men hiervoor gebruikt gaan ver, heel ver.&lt;br /&gt;Doe je niet aan internetbankieren op deze computer, maar misschien wel op een andere computer in het netwerk, geen probleem hoor. De malware kan zich via je netwerk of via draagbare media ook op andere computers nestelen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dit hele verhaal draait om geld.&lt;br /&gt;Geld dat jij niet wil betalen voor bepaalde software. De andere kant van het verhaal draait ook om geld. Men wil je producten laten kopen, door je verleidelijke advertenties te tonen en in het slechtste geval wil men jouw bankgegevens om geld te halen van jouw bankrekening...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Het gebruik van illegale verkregen software zorgt altijd voor problemen. &lt;br /&gt;Niet alleen voor jou, maar ook voor andere gebruikers van het internet.&lt;br /&gt;Jij als medegebruiker hebt ook je verantwoordelijkheden om het World Wide Web leefbaar te houden en om de verspreiding van malware tegen te gaan.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Gebruik van illegaal verkregen software is niet netjes tegenover de makers van deze programma's. Zij steken er tijd en geld in om deze software te ontwikkelen, en daar mag best wat tegenover staan.&lt;br /&gt;Wens je toch niet te betalen voor software, zoek dan naar gratis alternatieven, want die zijn er echt wel.&lt;br /&gt;&lt;br /&gt;Gebruik van legaal verkregen software, kan je veel problemen besparen!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-2363854490471586771?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/2363854490471586771/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=2363854490471586771&amp;isPopup=true' title='5 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2363854490471586771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/2363854490471586771'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/07/niets-voor-niets.html' title='Niets voor niets!'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-5279300658887501767</id><published>2008-07-10T22:43:00.002+02:00</published><updated>2008-10-18T20:49:28.884+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.0.12</title><content type='html'>2008 07 10&lt;br /&gt;Version 5.0.12&lt;br /&gt;O20 - Winlogon Notify: lstream - C:\WINDOWS\SYSTEM32\lstream.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lstream&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fsxxd&lt;br /&gt;XD FileSystemDriver: \??\C:\WINDOWS\System32\fsxxd.sys (system)&lt;br /&gt;lstream.dll&lt;br /&gt;fsxxd.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-5279300658887501767?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/5279300658887501767/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=5279300658887501767&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5279300658887501767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/5279300658887501767'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/07/haxfix-version-5012.html' title='Haxfix version 5.0.12'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-8638603745716315649</id><published>2008-05-20T08:30:00.002+02:00</published><updated>2008-10-18T20:49:42.874+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.11</title><content type='html'>2008 04 23&lt;br /&gt;O20 - Winlogon Notify: divxps - C:\WINDOWS\SYSTEM32\divxps.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\divxps&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\klite&lt;br /&gt;KLite Codec 3.0: \??\C:\WINDOWS\System32\klite.sys (system)&lt;br /&gt;divxps.dll&lt;br /&gt;klite.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-8638603745716315649?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/8638603745716315649/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=8638603745716315649&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8638603745716315649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/8638603745716315649'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/05/haxfix-version-5011.html' title='Haxfix Version 5.0.11'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6221259824203758119</id><published>2008-05-20T08:25:00.003+02:00</published><updated>2008-11-01T09:33:45.334+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix Version 5.0.10</title><content type='html'>2008 04 22&lt;br /&gt;Added the uninstall option to the menu&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6221259824203758119?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6221259824203758119/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6221259824203758119&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6221259824203758119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6221259824203758119'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/05/haxfix-version-5.html' title='Haxfix Version 5.0.10'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-41269249459471397</id><published>2008-04-21T18:31:00.003+02:00</published><updated>2008-10-10T23:29:16.714+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Music'/><title type='text'>Beautiful Day</title><content type='html'>Yesterday I was in South America for almost one hour and a half.&lt;br /&gt;I could not believe what I saw and what I heard. &lt;br /&gt;I was between a few ten thousand screaming U2 fans.&lt;br /&gt;It was a wonderful experience. It was amazing.&lt;br /&gt;I think I was at a place....where the streets have no name...a place where we are all together as One.&lt;br /&gt;If you like U2, come and go to this place.&lt;br /&gt;Go and see the movie &lt;a href="http://www.u23dmovie.com/"&gt;U23D&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://widgets.clearspring.com/o/47572cded2ffd3c3/48efc8f10108d1f5/47572cde422610d9/36c6352b/-cpid/3893050e5ad80e0e/widget.js"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-41269249459471397?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/41269249459471397/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=41269249459471397&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/41269249459471397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/41269249459471397'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/04/beautiful-day.html' title='Beautiful Day'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-3333430085259041367</id><published>2008-04-19T18:48:00.001+02:00</published><updated>2008-10-18T20:50:13.517+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.00.9</title><content type='html'>Haxfix version 5.00.9&lt;br /&gt;2008 04 19&lt;br /&gt;O20 - Winlogon Notify: divxrs - C:\WINDOWS\SYSTEM32\divxrs.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\divxrs&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dprot.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dprot&lt;br /&gt;DTM Protector: \??\C:\WINDOWS\System32\dprot.sys (system)&lt;br /&gt;divxrs.dll&lt;br /&gt;dprot.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-3333430085259041367?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/3333430085259041367/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=3333430085259041367&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3333430085259041367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/3333430085259041367'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/04/haxfix-version-5009.html' title='Haxfix version 5.00.9'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-7076349595622927612</id><published>2008-03-31T19:48:00.002+02:00</published><updated>2008-10-18T20:50:29.016+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix version 5.00.8</title><content type='html'>Haxfix version 5.00.8&lt;br /&gt;2008 03 31&lt;br /&gt;O20 - Winlogon Notify: ibudu - C:\WINDOWS\SYSTEM32\ibudu.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ibudu&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\itcoe&lt;br /&gt;itcoe adapter \\??\C:\WINDOWS\System32\itcoe.sys (system)&lt;br /&gt;ibudu.dll&lt;br /&gt;itcoe.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Use haxfix to remove this infection.&lt;br /&gt;Removalinstructions for this infection, you can find &lt;a href="http://marcvn.blogspot.com/2008/10/haxfix-instructions-updated.html"&gt;here&lt;/a&gt; or &lt;a href="http://users.telenet.be/marcvn/spyware/1970547.htm"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-7076349595622927612?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/7076349595622927612/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=7076349595622927612&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7076349595622927612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/7076349595622927612'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/03/haxfix-version-5008.html' title='Haxfix version 5.00.8'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6525630119168364793.post-6630255679316252252</id><published>2008-03-23T10:27:00.006+01:00</published><updated>2008-09-08T19:08:25.823+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='haxfix'/><title type='text'>Haxfix</title><content type='html'>Maybe you know, maybe you don't, but I made a small removaltool (haxifx) to delete haxdoor and goldun infections.&lt;br /&gt;&lt;a href="http://users.telenet.be/marcvn/tools/haxfix.exe" target="_blank"&gt;http://users.telenet.be/marcvn/tools/haxfix.exe&lt;/a&gt;&lt;br /&gt;&lt;a href="http://download.bleepingcomputer.com/marckie/haxfix.exe" target="_blank"&gt;http://download.bleepingcomputer.com/marckie/haxfix.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;When you start haxfix, you will get a menu with 4 options.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 0);"&gt;Option 1: Make logfile&lt;/span&gt;&lt;br /&gt;If you use haxfix, always make a log file first.&lt;br /&gt;The logfile is showing all services, safeboot services and notify keys, that are matching with the current haxdoor/goldun variants.&lt;br /&gt;Haxfix checks for known SSDOL keys related to goldun.&lt;br /&gt;Haxfix also checks if iexplore.exe is infected with a (known) goldunvariant. If so, it looks for a clean alternative in the dllcache or the tempfolder.&lt;br /&gt;Catchme.exe has been integrated in haxfix since version 4.43. (thank You Gmer)&lt;br /&gt;The logfile produced by Catchme, will be analysed by haxfix for matching haxdoor- or goldunvariants.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option 2: Run auto fix&lt;/span&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;.&lt;/span&gt;&lt;br /&gt;Option 2 deletes all haxdoor-notify keys that are found when one, or more then one, matching service/safeboot service is present.&lt;br /&gt;You can use option 2 if the notify keys that are found, are related to haxdooor or goldun.&lt;br /&gt;- If there is a notify key (xxxx) and the letters xxxx are found between the matching services or matching safebootservices, haxfix deletes them&lt;br /&gt;- If there is an unknown notify key or a legit notify key (xxxx) in the logfile, and there are no matching services/safeboot services (xxxx), haxfix will not delete the keys&lt;br /&gt;- If there is an unknown notify key or a legit notify key in the haxdoor-logfile and a matching service, don't run option 2 (auto fix) but use the manual fix (option 3) to add the key(s) manually.&lt;br /&gt;- All known goldunvariants will be deleted with option 2.&lt;br /&gt;- If ieplore.exe is infected, haxfix can fix this without reboot.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option 3: Run manual fix&lt;/span&gt;&lt;br /&gt;This gives you the possibilty to add one, or if necessary more then one haxdoor key.&lt;br /&gt;When you start option 3, you 'll get a message:&lt;br /&gt;&lt;br /&gt;echo Insert the haxdoorkey,&lt;br /&gt;and then press Enter:&lt;br /&gt;&lt;br /&gt;Insert the haxdoorkey without the numbers. (Ex: avpe, xtpt, fuxx,...)&lt;br /&gt;When this is a valid choice (there is a check for the services/safeboot services), the key will be added to delete.&lt;br /&gt;Next you have the possibilty to add a new key: Yes (press Y) or No (press N)&lt;br /&gt;When do we use option 3?&lt;br /&gt;Use option 3 if there are:&lt;br /&gt;- unknown or legit notify keys with related services in the haxlog.txt file.&lt;br /&gt;- no notify keys are found, but there are haxdoor related services / safeboot services. (be careful, don't add legit ones, because after reboot they are all gone.)&lt;br /&gt;If you use option 3 to delete a haxdoorvariant, and one or more goldunvariants are present too, all infection will be deleted.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Option 4: Run unknow fix.&lt;/span&gt;&lt;br /&gt;The logfile produced by Catchme will be analysed by haxfix for hax- or goldunvariants.&lt;br /&gt;If a match is found, you can delete them by using option 4 - remove unknown.&lt;br /&gt;(this only works with the variants that uses notify and services regkeys.)&lt;br /&gt;Variants that are not recognized by haxfix, but are detected by catchme, can now be deleted with haxfix.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;A few remarks:&lt;/span&gt;&lt;br /&gt;If you see this in the logfile: registrysettings failed&lt;br /&gt;use this command: &lt;span style="font-style: italic; color: rgb(102, 204, 204);"&gt;%systemdrive%\haxfix.exe /reset&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If you don't get a logfile after reboot:&lt;br /&gt;use this command: &lt;span style="font-style: italic; color: rgb(102, 204, 204);"&gt;%systemdrive%\haxfix.exe /after&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;More information about the tool you can find on my website (or on the security boards).&lt;br /&gt;http://users.pandora.be/marcvn/spyware/1541877.htm&lt;br /&gt;http://users.pandora.be/marcvn/spyware/1585977.htm&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);"&gt;Updates:&lt;/span&gt;&lt;br /&gt;From now on, I will post all updates of haxfix also here.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 204, 204);"&gt;Version 5.00.1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2008 01 22&lt;br /&gt;Goldun&lt;br /&gt;O20 - Winlogon Notify: sha1hsh - C:\WINDOWS\SYSTEM32\sha1hsh.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sha1hsh&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sha1krnl&lt;br /&gt;Kernel CryptoService: \??\C:\WINDOWS\System32\sha1krnl.sys (system)&lt;br /&gt;sha1hsh.dll&lt;br /&gt;sha1krnl.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 204, 204);"&gt;Version 5.00.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2008 01 28&lt;br /&gt;Goldun&lt;br /&gt;O20 - Winlogon Notify: px86emul - C:WINDOWS\SYSTEM32\px86emul.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\px86emul&lt;br /&gt;FPU emulation service: ??C:WINDOWS\system32\x86emul.sys (system)&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\x86emul&lt;br /&gt;px86emul.dll&lt;br /&gt;x86emul.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 204, 204);"&gt;Version 5.00.3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2008 02 20&lt;br /&gt;Goldun&lt;br /&gt;O20 - Winlogon Notify: alcomt - C:\WINDOWS\SYSTEM32\alcomt.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\alcomt&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\alcom&lt;br /&gt;alcom.sys&lt;br /&gt;alcomt.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 204, 204);"&gt;Version 5.00.4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2008 02 24&lt;br /&gt;Goldun&lt;br /&gt;O20 - Winlogon Notify: alcopt - C:\WINDOWS\SYSTEM32\alcopt.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\alcopt&lt;br /&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\alcop&lt;br /&gt;alcop server: \??\C:\WINDOWS\System32\alcop.sys (system)&lt;br /&gt;alcop.sys&lt;br /&gt;alcopt.dll&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 204, 204);"&gt;Version 5.00.5&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2008 02 27&lt;br /&gt;O20 - Winlogon Notify: mplink - C:\WINDOWS\SYSTEM32\mplink.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mplink&lt;br /&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\fprot&lt;br /&gt;FT StarForce Protector: \??\C:\WINDOWS\System32\fprot.sys (system)&lt;br /&gt;mplink.dll&lt;br /&gt;fprot.sys&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 204, 204);"&gt;Version 5.00.6&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2008 03 16&lt;br /&gt;O20 - Winlogon Notify: mp3res - C:\WINDOWS\SYSTEM32\mp3res.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mp3res&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xprot&lt;br /&gt;XPROTECTOR Driver \??\C:\WINDOWS\System32\xprot.sys (system)&lt;br /&gt;mp3res.dll&lt;br /&gt;xprot.sys&lt;br /&gt;k86.bin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 204, 204);"&gt;Version 5.00.7&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2008 03 20&lt;br /&gt;O20 - Winlogon Notify: upsctl - C:\WINDOWS\SYSTEM32\upsctl.dll&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\upsctl&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upscr&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;br /&gt;\Minimal\upscr.sys&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;br /&gt;\Network\upscr.sys&lt;br /&gt;hrs.bin&lt;br /&gt;upscr.sys&lt;br /&gt;upsctl.dll&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6525630119168364793-6630255679316252252?l=marcvn.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://marcvn.blogspot.com/feeds/6630255679316252252/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6525630119168364793&amp;postID=6630255679316252252&amp;isPopup=true' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6630255679316252252'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6525630119168364793/posts/default/6630255679316252252'/><link rel='alternate' type='text/html' href='http://marcvn.blogspot.com/2008/03/haxfix.html' title='Haxfix'/><author><name>Marc</name><uri>http://www.blogger.com/profile/08903414120157522970</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
