<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; HijackThis</title>
	<atom:link href="http://htlogs.com/category/hijackthis/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Fri, 10 Sep 2010 15:36:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>What is KB5625711.exe, How to remove KB5625711.exe</title>
		<link>http://htlogs.com/what-is-kb5625711-exe-how-to-remove-kb5625711-exe/</link>
		<comments>http://htlogs.com/what-is-kb5625711-exe-how-to-remove-kb5625711-exe/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 14:16:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Startup folder]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1955</guid>
		<description><![CDATA[KB5625711.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: KB5625711 Filename: KB5625711.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; KB5625711.exe Command: %AppData%\{RANDOM}\KB5625711.exe Startup Type: HKCU->Run, Startup Folder [...]]]></description>
			<content:encoded><![CDATA[<h2>KB5625711.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> KB5625711<br />
<strong>Filename:</strong> KB5625711.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | KB5625711.exe</p></blockquote>
<p><strong>Command:</strong> %AppData%\{RANDOM}\KB5625711.exe<br />
<strong>Startup Type:</strong> HKCU->Run, Startup Folder<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [KB5625711.exe] C:\Documents and Settings\user\Application Data\692A3AB5356E8BA8D60B237EB24238F7\KB5625711.exe<br />
O4 – Startup: Malware Destructor.lnk = C:\Documents and Settings\user\Application Data\692A3AB5356E8BA8D60B237EB24238F7\KB5625711.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [KB5625711.exe] C:\Documents and Settings\user\Application Data\692A3AB5356E8BA8D60B237EB24238F7\KB5625711.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;KB5625711.exe&#8221;=C:\Documents and Settings\user\Application Data\692A3AB5356E8BA8D60B237EB24238F7\KB5625711.exe</p></blockquote>
<p><strong>Description:</strong> core component of Malware Destructor 2011 (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/09/10/how-to-remove-malware-destructor-2011-uninstall-instructions/">Malware Destructor 2011 removal</a> guide or the steps below.</p>
<p>1. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop. </p>
<p>2. Run HijackThis. Main menu opens. Click to “Do a system scan only” button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>O4 – HKCU\..\Run: [KB5625711.exe] C:\Documents and Settings\user\Application Data\692A3AB5356E8BA8D60B237EB24238F7\KB5625711.exe<br />
O4 – Startup: Malware Destructor.lnk = C:\Documents and Settings\user\Application Data\692A3AB5356E8BA8D60B237EB24238F7\KB5625711.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-kb5625711-exe-how-to-remove-kb5625711-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is XBV6RD5SZF, How to remove XBV6RD5SZF</title>
		<link>http://htlogs.com/what-is-xbv6rd5szf-how-to-remove-xbv6rd5szf/</link>
		<comments>http://htlogs.com/what-is-xbv6rd5szf-how-to-remove-xbv6rd5szf/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 16:31:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1945</guid>
		<description><![CDATA[XBV6RD5SZF is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Filename: {RANDOM:3}.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; XBV6RD5SZF Command: %Temp%\{RANDOM:3}.exe Startup Type: HKCU->Run HijackThis Category: O4 HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>XBV6RD5SZF is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Filename:</strong> {RANDOM:3}.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | XBV6RD5SZF</p></blockquote>
<p><strong>Command:</strong> %Temp%\{RANDOM:3}.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [XBV6RD5SZF] C:\DOCUME~1\username\LOCALS~1\Temp\Ude.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [XBV6RD5SZF] C:\DOCUME~1\username\LOCALS~1\Temp\Ude.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;XBV6RD5SZF&#8221;=C:\DOCUME~1\username\LOCALS~1\Temp\Ude.exe</p></blockquote>
<p><strong>Description:</strong> new variant of trojan FakeAlert that also known as Mal/FakeAV-CX [Sophos], TrojanDownloader:Win32/Renos.KF [Microsoft], Win-Trojan/Variant.183296.B [AhnLab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> or the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“XBV6RD5SZF”=-</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-xbv6rd5szf-how-to-remove-xbv6rd5szf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is AWM.exe, How to remove AWM.exe</title>
		<link>http://htlogs.com/what-is-awm-exe-how-to-remove-awm-exe/</link>
		<comments>http://htlogs.com/what-is-awm-exe-how-to-remove-awm-exe/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 16:36:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1941</guid>
		<description><![CDATA[AWM.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: AWM Filename: AWM.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; awm Command: %AppData%\AWM\AWM.exe Startup Type: HijackThis Category: O4 [...]]]></description>
			<content:encoded><![CDATA[<h2>AWM.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> AWM<br />
<strong>Filename:</strong> AWM.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | awm</p></blockquote>
<p><strong>Command:</strong> %AppData%\AWM\AWM.exe<br />
<strong>Startup Type:</strong><br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [awm] C:\Documents and Settings\username\Application Data\AWM\AWM.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [awm] C:\Documents and Settings\username\Application Data\AWM\AWM.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;awm&#8221;=C:\Documents and Settings\username\Application Data\AWM\AWM.exe</p></blockquote>
<p><strong>Description:</strong> core component of AWM Antivirus</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/09/02/how-to-remove-awm-antivirus-uninstall-instructions/">AWM Antivirus removal</a> guide or the steps below.</p>
<p>Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-awm-exe-how-to-remove-awm-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is mediafix70700en02.exe, How to remove mediafix70700en02.exe</title>
		<link>http://htlogs.com/what-is-mediafix70700en02-exe-how-to-remove-mediafix70700en02-exe/</link>
		<comments>http://htlogs.com/what-is-mediafix70700en02-exe-how-to-remove-mediafix70700en02-exe/#comments</comments>
		<pubDate>Sun, 29 Aug 2010 13:34:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1934</guid>
		<description><![CDATA[mediafix70700en02.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: mediafix70700en02 Filename: mediafix70700en02.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; mediafix70700en02.exe Command: %AppData%\{RANDOM}\mediafix70700en02.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>mediafix70700en02.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> mediafix70700en02<br />
<strong>Filename:</strong> mediafix70700en02.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | mediafix70700en02.exe</p></blockquote>
<p><strong>Command:</strong> %AppData%\{RANDOM}\mediafix70700en02.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [mediafix70700en02.exe] C:\Documents and Settings\User\Application Data\CA196E3D0F2D18F19323483E318BCFD5\mediafix70700en02.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [mediafix70700en02.exe] C:\Documents and Settings\User\Application Data\CA196E3D0F2D18F19323483E318BCFD5\mediafix70700en02.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;mediafix70700en02.exe&#8221;=C:\Documents and Settings\User\Application Data\CA196E3D0F2D18F19323483E318BCFD5\mediafix70700en02.exe</p></blockquote>
<p><strong>Description:</strong> core component of Antimalware Doctor (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/02/20/how-to-remove-antimalware-doctor-uninstall-instructions/">Antimalware Doctor removal</a> guide or the steps below.</p>
<p>1. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop. </p>
<p>2. Run HijackThis. Main menu opens. Click to “Do a system scan only” button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [mediafix70700en02.exe] C:\Documents and Settings\User\Application Data\CA196E3D0F2D18F19323483E318BCFD5\mediafix70700en02.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-mediafix70700en02-exe-how-to-remove-mediafix70700en02-exe/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>What is Advanced Security Tool 2010, How to remove Advanced Security Tool 2010</title>
		<link>http://htlogs.com/what-is-advanced-security-tool-2010-how-to-remove-advanced-security-tool-2010/</link>
		<comments>http://htlogs.com/what-is-advanced-security-tool-2010-how-to-remove-advanced-security-tool-2010/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 15:08:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1929</guid>
		<description><![CDATA[Advanced Security Tool 2010 is a malicious program. It is a malware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Filename: asectool.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] &#8220;AdvSecTool Command: %UserProfile%\Application Data\asectool.exe Startup Type: HKCU->Run Description: rogue antivirus program How [...]]]></description>
			<content:encoded><![CDATA[<h2>Advanced Security Tool 2010 is a malicious program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a malware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Filename:</strong> <a href="http://htlogs.com/what-is-asectool-exe-how-to-remove-asectool-exe/">asectool.exe</a><br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;AdvSecTool</p></blockquote>
<p><strong>Command:</strong> %UserProfile%\Application Data\asectool.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong>Description:</strong> rogue antivirus program</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/27/how-to-remove-advanced-security-tool-2010-uninstall-instructions/">Advanced Security Tool 2010 removal</a> instructions</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-advanced-security-tool-2010-how-to-remove-advanced-security-tool-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is asectool.exe, How to remove asectool.exe</title>
		<link>http://htlogs.com/what-is-asectool-exe-how-to-remove-asectool-exe/</link>
		<comments>http://htlogs.com/what-is-asectool-exe-how-to-remove-asectool-exe/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 15:03:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1927</guid>
		<description><![CDATA[asectool.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: asectool Filename: asectool.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; AdvSecTool Command: %UserProfile%\Application Data\asectool.exe Startup Type: HKCU->Run HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>asectool.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> asectool<br />
<strong>Filename:</strong> asectool.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AdvSecTool</p></blockquote>
<p><strong>Command:</strong> %UserProfile%\Application Data\asectool.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [AdvSecTool] “%UserProfile%\Application Data\asectool.exe”</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [AdvSecTool] %UserProfile%\Application Data\asectool.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;AdvSecTool&#8221;=%UserProfile%\Application Data\asectool.exe</p></blockquote>
<p><strong>Description:</strong> core component of Advanced Security Tool 2010 (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/27/how-to-remove-advanced-security-tool-2010-uninstall-instructions/">Advanced Security Tool 2010 removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-asectool-exe-how-to-remove-asectool-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ntload.exe, How to remove ntload.exe</title>
		<link>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/</link>
		<comments>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 14:56:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1925</guid>
		<description><![CDATA[ntload.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ntload Filename: ntload.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run &#124; rundll32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: %Windir%\system32\ntload.exe Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>ntload.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ntload<br />
<strong>Filename:</strong> ntload.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | rundll32<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> %Windir%\system32\ntload.exe<br />
<strong>Startup Type:</strong> Winlogon->Shell, HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2, O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\ntload.exe<br />
O4 – HKLM\..\Run: [rundll32] C:\WINDOWS\system32\ntload.exe</p></blockquote>
<p><strong>Description:</strong> component of Advanced Security Tool 2010 (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/27/how-to-remove-advanced-security-tool-2010-uninstall-instructions/">Advanced Security Tool 2010 removal</a> guide or or the steps below.</p>
<p>1. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop. Most important, in the Save dialog, rename HijackThis.exe to iexplore.exe !!!<br />
2. Run HijackThis. Main menu opens. Click to “Do a system scan only” button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>F2 – REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\ntload.exe<br />
O4 – HKLM\..\Run: [rundll32] C:\WINDOWS\system32\ntload.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.<br />
3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is defender.exe, How to remove defender.exe</title>
		<link>http://htlogs.com/what-is-defender-exe-how-to-remove-defender-exe/</link>
		<comments>http://htlogs.com/what-is-defender-exe-how-to-remove-defender-exe/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 18:16:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1918</guid>
		<description><![CDATA[defender.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: defender Filename: defender.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; tmp Command: %AppData%\defender.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>defender.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> defender<br />
<strong>Filename:</strong> defender.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | tmp</p></blockquote>
<p><strong>Command:</strong> %AppData%\defender.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [tmp] C:\Documents and Settings\comp\Application Data\defender.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [tmp] C:\Documents and Settings\comp\Application Data\defender.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;tmp&#8221;=C:\Documents and Settings\comp\Application Data\defender.exe</p></blockquote>
<p><strong>Description:</strong> core component of Microsoft Security Essentials Alert trojan</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/26/how-to-remove-fake-microsoft-security-essentials-alert/">fake Microsoft Security Essentials Alert removal</a> instructions</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-defender-exe-how-to-remove-defender-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is newsecureapp70700.exe, How to remove newsecureapp70700 .exe</title>
		<link>http://htlogs.com/what-is-newsecureapp70700-exe-how-to-remove-newsecureapp70700-exe/</link>
		<comments>http://htlogs.com/what-is-newsecureapp70700-exe-how-to-remove-newsecureapp70700-exe/#comments</comments>
		<pubDate>Sun, 22 Aug 2010 14:41:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1911</guid>
		<description><![CDATA[newsecureapp70700.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: newsecureapp70700 Filename: newsecureapp70700.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; newsecureapp70700.exe Command: %AppData%\{RANDOM}\newsecureapp70700.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>newsecureapp70700.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> newsecureapp70700<br />
<strong>Filename:</strong> newsecureapp70700.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | newsecureapp70700.exe</p></blockquote>
<p><strong>Command:</strong> %AppData%\{RANDOM}\newsecureapp70700.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [newsecureapp70700.exe] C:\Documents and Settings\User\Application Data\788802FCB8E32AB6DD188F1B84357D9C\newsecureapp70700.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [newsecureapp70700.exe] C:\Documents and Settings\User\Application Data\788802FCB8E32AB6DD188F1B84357D9C\newsecureapp70700.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;newsecureapp70700.exe&#8221;=C:\Documents and Settings\User\Application Data\788802FCB8E32AB6DD188F1B84357D9C\newsecureapp70700.exe</p></blockquote>
<p><strong>Description:</strong> core component of Antimalware Doctor. Antimalware Doctor is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/02/20/how-to-remove-antimalware-doctor-uninstall-instructions/">Antimalware Doctor removal</a> instructions or the steps below.</p>
<p>1. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop.<br />
2. Run HijackThis. Main menu opens. Click to “Do a system scan only” button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [newsecureapp70700.exe] C:\Documents and Settings\User\Application Data\{RANDOM}\newsecureapp70700.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.<br />
3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-newsecureapp70700-exe-how-to-remove-newsecureapp70700-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is secureapp70700.exe, How to remove secureapp70700.exe</title>
		<link>http://htlogs.com/what-is-secureapp70700-exe-how-to-remove-secureapp70700-exe/</link>
		<comments>http://htlogs.com/what-is-secureapp70700-exe-how-to-remove-secureapp70700-exe/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 17:34:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1904</guid>
		<description><![CDATA[secureapp70700.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: secureapp70700 Filename: secureapp70700.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; secureapp70700.exe Command: %AppData%\{RANDOM}\secureapp70700.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>secureapp70700.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> secureapp70700<br />
<strong>Filename:</strong> secureapp70700.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | secureapp70700.exe</p></blockquote>
<p><strong>Command:</strong> %AppData%\{RANDOM}\secureapp70700.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [secureapp70700.exe] C:\Documents and Settings\User\Application Data\788802FCB8E32AB6DD188F1B84357D9A\secureapp70700.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [secureapp70700.exe] C:\Documents and Settings\User\Application Data\788802FCB8E32AB6DD188F1B84357D9A\secureapp70700.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;secureapp70700.exe&#8221;=C:\Documents and Settings\User\Application Data\788802FCB8E32AB6DD188F1B84357D9A\secureapp70700.exe</p></blockquote>
<p><strong>Description:</strong> core component of Antimalware Doctor. Antimalware Doctor is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/02/20/how-to-remove-antimalware-doctor-uninstall-instructions/">Antimalware Doctor removal</a> instructions or the steps below.</p>
<p>1. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop.<br />
2. Run HijackThis. Main menu opens. Click to “Do a system scan only” button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [secureapp70700.exe] C:\Documents and Settings\User\Application Data\{RANDOM}\secureapp70700.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.<br />
3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-secureapp70700-exe-how-to-remove-secureapp70700-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
