<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; F2</title>
	<atom:link href="http://htlogs.com/category/hijackthis/f2/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Fri, 10 Sep 2010 15:36:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>What is ntload.exe, How to remove ntload.exe</title>
		<link>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/</link>
		<comments>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 14:56:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1925</guid>
		<description><![CDATA[ntload.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ntload Filename: ntload.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run &#124; rundll32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: %Windir%\system32\ntload.exe Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>ntload.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ntload<br />
<strong>Filename:</strong> ntload.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | rundll32<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> %Windir%\system32\ntload.exe<br />
<strong>Startup Type:</strong> Winlogon->Shell, HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2, O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\ntload.exe<br />
O4 – HKLM\..\Run: [rundll32] C:\WINDOWS\system32\ntload.exe</p></blockquote>
<p><strong>Description:</strong> component of Advanced Security Tool 2010 (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/27/how-to-remove-advanced-security-tool-2010-uninstall-instructions/">Advanced Security Tool 2010 removal</a> guide or or the steps below.</p>
<p>1. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop. Most important, in the Save dialog, rename HijackThis.exe to iexplore.exe !!!<br />
2. Run HijackThis. Main menu opens. Click to “Do a system scan only” button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>F2 – REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\ntload.exe<br />
O4 – HKLM\..\Run: [rundll32] C:\WINDOWS\system32\ntload.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.<br />
3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is srnh.lto, How to remove srnh.lto</title>
		<link>http://htlogs.com/what-is-srnh-lto-how-to-remove-srnh-lto/</link>
		<comments>http://htlogs.com/what-is-srnh-lto-how-to-remove-srnh-lto/#comments</comments>
		<pubDate>Wed, 19 May 2010 13:19:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1720</guid>
		<description><![CDATA[srnh.lto is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: srnh Filename: srnh.lto Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe srnh.lto iqfnr CLSID: [...]]]></description>
			<content:encoded><![CDATA[<h2>srnh.lto is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> srnh<br />
<strong>Filename:</strong> srnh.lto<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe srnh.lto iqfnr<br />
<strong>CLSID:</strong> clsid<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe rundll32.exe srnh.lto iqfnr</p></blockquote>
<p><strong>Description:</strong> component of Win32/Oficla trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-srnh-lto-how-to-remove-srnh-lto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is hspe.uvo, How to remove hspe.uvo</title>
		<link>http://htlogs.com/what-is-hspe-uvo-how-to-remove-hspe-uvo/</link>
		<comments>http://htlogs.com/what-is-hspe-uvo-how-to-remove-hspe-uvo/#comments</comments>
		<pubDate>Wed, 21 Apr 2010 17:11:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1652</guid>
		<description><![CDATA[hspe.uvo is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: hspe Filename: hspe.uvo Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe, rundll32.exe hspe.uvo bnjpid Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>hspe.uvo is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> hspe<br />
<strong>Filename:</strong> hspe.uvo<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe, rundll32.exe hspe.uvo bnjpid<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe, rundll32.exe hspe.uvo bnjpid</p></blockquote>
<p><strong>Description:</strong> component of a trojan that also known as Backdoor.Bredolab [PCTools], Mal/EncPk-NS, Mal/FakeAV-BW, Mal/FakeAV-DF, Mal/FakeAV-BW [Sophos], packed with: PE_Patch.UPX [Kaspersky Lab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-hspe-uvo-how-to-remove-hspe-uvo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is awxm.vho, How to remove awxm.vho</title>
		<link>http://htlogs.com/what-is-awxm-vho-how-to-remove-awxm-vho/</link>
		<comments>http://htlogs.com/what-is-awxm-vho-how-to-remove-awxm-vho/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 14:20:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1643</guid>
		<description><![CDATA[awxm.vho is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: awxm Filename: awxm.vho Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe awxm.vho rlvgf Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>awxm.vho is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> awxm<br />
<strong>Filename:</strong> awxm.vho<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe awxm.vho rlvgf<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe rundll32.exe awxm.vho rlvgf</p></blockquote>
<p><strong>Description:</strong> component of a trojan that also known as Backdoor.Bredolab [PCTools], Mal/EncPk-NS, Mal/FakeAV-BW, Mal/FakeAV-DF, Mal/FakeAV-BW [Sophos], packed with: PE_Patch.UPX [Kaspersky Lab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-awxm-vho-how-to-remove-awxm-vho/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ngts.vao, How to remove ngts.vao</title>
		<link>http://htlogs.com/what-is-ngts-vao-how-to-remove-ngts-vao/</link>
		<comments>http://htlogs.com/what-is-ngts-vao-how-to-remove-ngts-vao/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 08:39:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1634</guid>
		<description><![CDATA[ngts.vao is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ngts Filename: ngts.vao Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe ngts.vao uvibls Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>ngts.vao is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ngts<br />
<strong>Filename:</strong> ngts.vao<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe ngts.vao uvibls<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe rundll32.exe ngts.vao uvibls</p></blockquote>
<p><strong>Description:</strong> component of a trojan that also known as Backdoor.Bredolab [PCTools], Mal/EncPk-NS, Mal/FakeAV-BW, Mal/FakeAV-DF, Mal/FakeAV-BW [Sophos], packed with: PE_Patch.UPX [Kaspersky Lab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> +  <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ngts-vao-how-to-remove-ngts-vao/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is rihd.pno, How to remove rihd.pno</title>
		<link>http://htlogs.com/what-is-rihd-pno-how-to-remove-rihd-pno/</link>
		<comments>http://htlogs.com/what-is-rihd-pno-how-to-remove-rihd-pno/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 18:08:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1628</guid>
		<description><![CDATA[rihd.pno is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: rihd Filename: rihd.pno Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe, rundll32.exe rihd.pno eaoydsi Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>rihd.pno is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> rihd<br />
<strong>Filename:</strong> rihd.pno<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe, rundll32.exe rihd.pno eaoydsi<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe, rundll32.exe rihd.pno eaoydsi</p></blockquote>
<p><strong>Description:</strong> component of Bredolab trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-rihd-pno-how-to-remove-rihd-pno/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is lgou.rlo, How to remove lgou.rlo</title>
		<link>http://htlogs.com/what-is-lgou-rlo-how-to-remove-lgou-rlo/</link>
		<comments>http://htlogs.com/what-is-lgou-rlo-how-to-remove-lgou-rlo/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 06:56:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1592</guid>
		<description><![CDATA[lgou.rlo is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: lgou Filename: lgou.rlo Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe lgou.rlo nhemkk Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>lgou.rlo is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> lgou<br />
<strong>Filename:</strong> lgou.rlo<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe lgou.rlo nhemkk<br />
<strong>Startup Type:</strong> Winlogon\Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: Shell=Explorer.exe rundll32.exe lgou.rlo nhemkk</p></blockquote>
<p><strong>Description:</strong> component of Bredolab trojan, also known as Trojan-Downloader.Win32.Agent.dkld [Kaspersky Lab], Mal/Oficla-A [Sophos], Trojan:Win32/Oficla.M [Microsoft]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-lgou-rlo-how-to-remove-lgou-rlo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is nnfj.tqo, How to remove nnfj.tqo</title>
		<link>http://htlogs.com/what-is-nnfj-tqo-how-to-remove-nnfj-tqo/</link>
		<comments>http://htlogs.com/what-is-nnfj-tqo-how-to-remove-nnfj-tqo/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 03:35:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1565</guid>
		<description><![CDATA[nnfj.tqo is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: nnfj Filename: nnfj.tqo Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe nnfj.tqo nhemkk Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>nnfj.tqo is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> nnfj<br />
<strong>Filename:</strong> nnfj.tqo<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe nnfj.tqo nhemkk<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe rundll32.exe nnfj.tqo nhemkk</p></blockquote>
<p><strong>Description:</strong> trojan also known as Trojan.Win32.Sasfis.ajil [Kaspersky Lab], SpyAgent-br.dll [McAfee], Mal/Oficla-A [Sophos], Trojan:Win32/Oficla.M [Microsoft], Win-Trojan/Xema.variant [AhnLab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-nnfj-tqo-how-to-remove-nnfj-tqo/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>What is nynw.wmo, How to remove nynw.wmo</title>
		<link>http://htlogs.com/what-is-nynw-wmo-how-to-remove-nynw-wmo/</link>
		<comments>http://htlogs.com/what-is-nynw-wmo-how-to-remove-nynw-wmo/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 16:08:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1488</guid>
		<description><![CDATA[nynw.wmo is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: nynw Filename: nynw.wmo Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command:Explorer.exe rundll32.exe nynw.wmo mynleeq Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>nynw.wmo is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> nynw<br />
<strong>Filename:</strong> nynw.wmo<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong>Explorer.exe rundll32.exe nynw.wmo mynleeq<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: Shell=&#8221;Explorer.exe rundll32.exe nynw.wmo mynleeq”</p></blockquote>
<p><strong>Description:</strong> trojan also known as Trojan.Sasfis [PCTools], Trojan.Sasfis [Symantec], Mal/Oficla-A [Sophos], Trojan:Win32/Oficla.M [Microsoft]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-nynw-wmo-how-to-remove-nynw-wmo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Antispyware.exe, How to remove Antispyware.exe</title>
		<link>http://htlogs.com/what-is-antispyware-exe-how-to-remove-antispyware-exe/</link>
		<comments>http://htlogs.com/what-is-antispyware-exe-how-to-remove-antispyware-exe/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 14:53:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Winlogon\UserInit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1461</guid>
		<description><![CDATA[Antispyware.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: Antispyware.exe Filename: Antispyware.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Userinit Command: C:\Program Files\Def Group\PC Defender\Antispyware.exe Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>Antispyware.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> Antispyware.exe<br />
<strong>Filename:</strong> Antispyware.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Userinit</p></blockquote>
<p><strong>Command:</strong> C:\Program Files\Def Group\PC Defender\Antispyware.exe<br />
<strong>Startup Type:</strong> Winlogon\UserInit<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,”C:\Program Files\Def Group\PC Defender\Antispyware.exe”</p></blockquote>
<p><strong>Description:</strong> core component of PC Defender. PC Defender is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/02/20/how-to-remove-pc-defender-uninstall-instructions/">PC Defender removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-antispyware-exe-how-to-remove-antispyware-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
