Posts tonen met het label haxfix. Alle posts tonen
Posts tonen met het label haxfix. Alle posts tonen

zaterdag 23 april 2011

HaxFix Version 5.097

5.097
2011 04 23

Bugfix.
Ready for windows 7 SP1.

zondag 9 januari 2011

HaxFix version 5.096

5.096
2011 01 09

Infection: Goldun

Updated the appinit detection.


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.
Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).

zondag 10 oktober 2010

HaxFix version 5.095

5.095
2010 10 10

Infection: Haxdoor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\boot32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\boot32.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\boot32.sys

Files:
system32\boot32.sys


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.
Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).

zondag 4 april 2010

HaxFix Version 5.094

5.094
2010 04 04

Infection: Goldun
Updated the detection for random services.

donderdag 28 januari 2010

Haxfix version 5.0.93

5.093
2010 01 28

Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lixgap
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lixgax
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lixgax.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lixgax.sys

Files:
system32\a99k.bin
system32\lixgax.sys
system32\lixgap.dll
system32\mod_st.dat
windows\pxysdb.dat


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.
Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).

dinsdag 19 januari 2010

Haxfix version 5.0.92

5.092
2010 01 20

Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxop81
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lingap
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lingax
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lingax.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lingax.sys

Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{209a54af-418a-4b1e-a68d-21fc33494303}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E14B6F5F-3F90-4871-AC57-18DFE244EE8F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1E88A88-9B9B-45D8-9CDC-39A934318E46}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3063ABBF-1257-4B23-A672-9E29A508A2FA}

Files:
system32\nnurri9.dll
system32\jtaqhghuc47.dll
system32\xxupuykyz65.dll
system32\ywud.dll
system32\ijqwv45.dll
system32\lingap.dll
system32\lingax.sys


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.
Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).

zaterdag 9 januari 2010

Haxfix version 5.0.91

Version 5.091
2010 01 09


Haxfix has been updated for Windows Vista (32-bit) en Windows 7 (32-bit).



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

zaterdag 19 december 2009

Haxfix version 5.0.90

Version 5.090
2009 12 19

Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\simdpp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\simdpx
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\simdpx.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\simdpx.sys

Files:
system32\mod_st.dat
system32\simdpx.sys
system32\simdpp.dll


Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\saifx
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sorrd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sorrd.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sorrd.sys

Files:
system32\saifx.dll
system32\sorrd.sys


Infection Goldun:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\linkap
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\linkax
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\linkax.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\linkax.sys

Files:
system32\linkap.dll
system32\linkax.sys

zaterdag 31 oktober 2009

Haxfix version 5.0.89

Version 5.089
2009 10 31

Infection: Goldun

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\semdpp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\semdpx
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semdpx.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semdpx.sys

Files:
system32\semdpp.dll
system32\semdpx.sys


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

woensdag 7 oktober 2009

Haxfix version 5.0.88

Version 5.088
2009 10 07

Infection: SpyBanker

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9ad1747-7b19-4dea-bc02-0ab12c4fc468}
system32\GbpDist.dl

Infection: Goldun

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sebdpp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sebdpx
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sebdpx.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sebdpx.sys
%Windir%\pxysdb.dat
system32\sebdpp.dll
system32\sebdpx.sys



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

zaterdag 12 september 2009

Haxfix version 5.0.87

Version 5.087
2009 09 12

Infection: Goldun

Updated the appinit detection.


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

vrijdag 11 september 2009

Haxfix version 5.0.86

Version 5.086
2009 09 11

Infection: Haxdoor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pdx
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pdx32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pdx32.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\pdx32.sys
system32\cfgh.ini
system32\pdx.dll
system32\pdx32.sys


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f675c54f-60b6-4fd8-bba0-443c493305eb}

File:
system32\rant32.dll


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

woensdag 12 augustus 2009

Haxfix version 5.0.85

Version 5.085
2009 08 12

Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91704C3F-A675-4e0e-9FB7-B03E005EDDA7}

Files:
system32\systran.dll


Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rgadtm
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rgadta
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rgadta.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rgadta.sys

Files:
system32\rgadtm.dll
system32\rgadta.sys



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

zondag 26 juli 2009

Haxfix version 5.0.84

Version 5.084
2009 07 26

Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rbadmm
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rbadmm
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rbadmm.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rbadmm.sys

Files:
system32\rbadma.sys
system32\rbadmm.dll


Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rbadzm
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rbadza
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rbadza.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rbadza.sys

Files:
system32\rbadza.sys
system32\rbadzm.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED78190A-DFB2-4336-A960-979CD88F7A8D}


Infection: Trojan Amble
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61DC85A0-4A32-4c38-92CF-24652B3F416C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{544735C9-AE13-4721-9DE7-D529BE675038}

Files:
system32\locsock32.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFF01325-0FC2-4749-8914-FBF0565AD9CC}

Files:
system32\jbnmcd.dll
system32\jbnmck.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{480FA3BD-A372-4f65-9F8A-15DF38F4E2AB}

Files:
system32\pcmfd3.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{996D4E16-517F-474a-870F-F882C6133C47}

Files:
system32\gacaq32.dll


Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

zaterdag 27 juni 2009

Haxfix version 5.0.83

Version 5.083
2009 06 27

Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{46B35542-A3CF-4cca-9C0B-259DB2FFF078}



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

zaterdag 13 juni 2009

Haxfix version 5.0.82

Version 5.082.
2009 06 13

Infection Goldun.
Updated appinit detection



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

dinsdag 9 juni 2009

Haxfix version 5.0.81

Version 5.081
2009 06 09

Infection Goldun
Updated appinit detection.



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

zaterdag 6 juni 2009

Haxfix version 5.0.80

Version 5.080
2009 06 06

Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7B303E07-7C7D-45ad-8D42-EB41C9CBC908}

File:
system32\krpod32.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0D75B38F-C5F6-444e-ABB3-FD0F77201602}


Files:
system32\c2d.dat
system32\idm.dat
system32\jc.dat
system32\q1.dat
system32\lpxg
system32\nk.dat
system32\udinfrm.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F66FC8B-DCF6-4db0-908A-2D566D7EF66D}

Files:
system32\afha
system32\blkernel.dll
system32\c2d.dat
system32\ck.dat
system32\idm.dat
system32\jc.dat
system32\nk.dat
system32\q1.dat


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91673BA2-1DC6-411c-9CD0-150750A2ECB5}

Files:
system32\armad32.dll
system32\c2d.dat
system32\ck.dat
system32\idm.dat
system32\lkjd
system32\nk.dat
system32\q1.dat
system32\xd.dat


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10C0B0C0-FC01-473b-8EBB-4376353F96E4}

Files:
system32\bekbn.dll
system32\ck.dat
system32\idm.dat
system32\q1.dat
system32\xd.dat
system32\fkas
system32\nk.dat


Infection: Trojan Ambler
KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8AA4410F-A3EE-4279-8F2C-4BFAB8CEB231}

Files:
system32\c2d.dat
system32\ck.dat
system32\idm.dat
system32\q1.dat
system32\xd.dat
system32\krmnat.dll
system32\pis


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F30B5E7E-CFBB-44fb-A947-226E5A7A4290}

Files:
system32\jhxm32.dll
system32\sft.res



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

donderdag 21 mei 2009

Haxfix version 5.0.78

Version 5.078
2009 05 21

Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{7C7EFE99-C71F-48b8-8CC8-BA506CA76A33}

File:
system32\xagkf32.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{1925C7E1-5540-4675-8198-8A2779D4072A}

File:
system32\msfgw32.dll


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{D6E0FAFC-2B61-4753-B3DA-D83BE96A2C39}

File:
system32\mashtuic32.dll



Use haxfix to remove this infection.
Removalinstructions for this infection, you can find here or here.

zondag 10 mei 2009

Haxfix version 5.0.77

Version 5.0.77
2009 05 10

Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{FFCC6792-7219-4ff8-98D2-5D632A5FA01C}
system32\al.txt
system32\dz1.txt
system32\kixm32.dll
system32\opxd
system32\p1.txt
system32\r24.txt


Infection: Trojan Ambler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{C3221010-0AD7-4c09-B17B-EDCFFDA4B7F9}
system32\fow64.dll


Infection: SpyBanker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{DCF49866-8F81-4F5F-8193-7EC75A2AB321}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper objects\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}


Infection: Goldun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\browser helper obJects\{73364D99-1240-4dff-B11A-67E448373048}

File:
system32\ipv6mons.dll