<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; O22</title>
	<atom:link href="http://htlogs.com/category/hijackthis/o22/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>gitabiga.dll is trojan Vundo</title>
		<link>http://htlogs.com/gitabiga-dll-is-trojan-vundo/</link>
		<comments>http://htlogs.com/gitabiga-dll-is-trojan-vundo/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 04:34:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[O22]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[SharedTaskScheduler]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=778</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: gitabiga Filename: gitabiga.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run &#124; derijidob hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler &#124; {e826441e-0920-4e05-9b2c-84189ccd7cba} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; gefiraled Command: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> gitabiga<br />
<strong>Filename:</strong> gitabiga.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | derijidob<br />
hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler | {e826441e-0920-4e05-9b2c-84189ccd7cba}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | gefiraled</p></blockquote>
<p><strong>Command:</strong> c:\windows\system32\gitabiga.dll<br />
<strong>CLSID:</strong> {e826441e-0920-4e05-9b2c-84189ccd7cba}<br />
<strong>Startup Type:</strong> HKLM->Run, SharedTaskScheduler, ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4, O21, O22<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>2009-09-19 01:46 . 2009-06-19 01:46 88576 &#8211;sha-w- c:\windows\system32\gitabiga.dll<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;derijidob&#8221;=&#8221;c:\windows\system32\gitabiga.dll&#8221; [2009-09-19 88576]<br />
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]<br />
&#8220;{e826441e-0920-4e05-9b2c-84189ccd7cba}&#8221;= &#8220;c:\windows\system32\gitabiga.dll&#8221; [2009-09-19 88576]<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
&#8220;gefiraled&#8221;= {e826441e-0920-4e05-9b2c-84189ccd7cba} &#8211; c:\windows\system32\gitabiga.dll [2009-09-19 88576]</p></blockquote>
<p><strong>Description:</strong> trojan Vundo</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/gitabiga-dll-is-trojan-vundo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>vitamine.dll is a trojan</title>
		<link>http://htlogs.com/vitaminedll-is-a-trojan/</link>
		<comments>http://htlogs.com/vitaminedll-is-a-trojan/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 15:12:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[AppInit DLLs]]></category>
		<category><![CDATA[O20]]></category>
		<category><![CDATA[O21]]></category>
		<category><![CDATA[O22]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[SharedTaskScheduler]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=351</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: vitamine Filename: vitamine.dll Command: c:\windows\system32\vitamine.dll CLSID: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} Startup Type: HKLM->Run, AppInit DLL, SSODL, SharedTaskScheduler HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> vitamine<br />
<strong>Filename:</strong> vitamine.dll<br />
<strong>Command:</strong> c:\windows\system32\vitamine.dll<br />
<strong>CLSID:</strong> {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}<br />
<strong>Startup Type:</strong> HKLM->Run, AppInit DLL, SSODL, SharedTaskScheduler<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4, O20, O21, O22<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [CPMfbaed640] Rundll32.exe &#8220;c:\windows\system32\vitamine.dll&#8221;,a<br />
O20 &#8211; AppInit_DLLs: c:\windows\system32\vitamine.dll<br />
O21 &#8211; SSODL: SSODL &#8211; {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} &#8211; c:\windows\system32\vitamine.dll<br />
O22 &#8211; SharedTaskScheduler: STS &#8211; {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} &#8211; c:\windows\system32\vitamine.dll</p></blockquote>
<p><strong>Description:</strong> trojan (Vundo)</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Use Malwarebytes Antimalware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/vitaminedll-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

