<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; autorun.inf</title>
	<atom:link href="http://htlogs.com/category/startup-type/autoruninf/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Tue, 07 Sep 2010 14:14:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>What is cgaqyi.exe, How to remove cgaqyi.exe</title>
		<link>http://htlogs.com/what-is-cgaqyi-exe-how-to-remove-cgaqyi-exe/</link>
		<comments>http://htlogs.com/what-is-cgaqyi-exe-how-to-remove-cgaqyi-exe/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 12:43:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1797</guid>
		<description><![CDATA[cgaqyi.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: cgaqyi Filename: cgaqyi.exe Command: c:\cgaqyi.exe Startup Type: autorun.inf Notes: a trojan that uses autorun.inf file [...]]]></description>
			<content:encoded><![CDATA[<h2>cgaqyi.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> cgaqyi<br />
<strong>Filename:</strong> cgaqyi.exe<br />
<strong>Command:</strong> c:\cgaqyi.exe<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong>Notes:</strong> a trojan that uses autorun.inf file to run itself</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">autorun.inf trojan removal</a> instructions</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-cgaqyi-exe-how-to-remove-cgaqyi-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is 9fo3ar0j.exe, How to remove 9fo3ar0j.exe</title>
		<link>http://htlogs.com/what-is-9fo3ar0j-exe-how-to-remove-9fo3ar0j-exe/</link>
		<comments>http://htlogs.com/what-is-9fo3ar0j-exe-how-to-remove-9fo3ar0j-exe/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 04:17:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1348</guid>
		<description><![CDATA[9fo3ar0j.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: 9fo3ar0j Filename: 9fo3ar0j.exe Command: c:\9fo3ar0j.exe Startup Type: autorun.inf Description: autorun.inf trojan also known as Mal/Generic-A [...]]]></description>
			<content:encoded><![CDATA[<h2>9fo3ar0j.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> 9fo3ar0j<br />
<strong>Filename:</strong> 9fo3ar0j.exe<br />
<strong>Command:</strong> c:\9fo3ar0j.exe<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong>Description:</strong> autorun.inf trojan also known as Mal/Generic-A [Sophos], PWS.Win32 [Ikarus], packed with ASPack [Kaspersky Lab]. The trojan is installed with <a href="http://htlogs.com/what-is-herss-exe-how-to-remove-herss-exe/">herss.exe</a> trojan.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">autorun.inf trojans removal</a> instructions + run <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-9fo3ar0j-exe-how-to-remove-9fo3ar0j-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is pbudsara.exe, How to remove pbudsara.exe</title>
		<link>http://htlogs.com/what-is-pbudsara-exe-how-to-remove-pbudsara-exe/</link>
		<comments>http://htlogs.com/what-is-pbudsara-exe-how-to-remove-pbudsara-exe/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 11:50:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1080</guid>
		<description><![CDATA[pbudsara.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: pbudsara Filename: pbudsara.exe Command: c:\pbudsara.exe Startup Type: autorun.inf Description: trojan that using autorun.inf files to [...]]]></description>
			<content:encoded><![CDATA[<h2>pbudsara.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> pbudsara<br />
<strong>Filename:</strong> pbudsara.exe<br />
<strong>Command:</strong> c:\pbudsara.exe<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong>Description:</strong> trojan that using autorun.inf files to spread inself</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">autorun.inf trojans removal</a> instructions</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-pbudsara-exe-how-to-remove-pbudsara-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is herss.exe, How to remove herss.exe</title>
		<link>http://htlogs.com/what-is-herss-exe-how-to-remove-herss-exe/</link>
		<comments>http://htlogs.com/what-is-herss-exe-how-to-remove-herss-exe/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 11:41:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1078</guid>
		<description><![CDATA[herss.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: herss Filename: herss.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; cdoosoft Command: %Temp%\herss.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>herss.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> herss<br />
<strong>Filename:</strong> herss.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | cdoosoft</p></blockquote>
<p><strong>Command:</strong> %Temp%\herss.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [cdoosoft] %Temp%\herss.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [cdoosoft] %Temp%\herss.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;cdoosoft&#8221;=%Temp%\herss.exe</p></blockquote>
<p><strong>Description:</strong> trojan also known as Trojan-GameThief.Win32.Magania.cmla [Kaspersky Lab], Mal/Taterf-A [Sophos], Worm:Win32/Taterf.B [Microsoft], Trojan.Win32.Inhoo [Ikarus]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + these <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">autorun.inf trojans removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-herss-exe-how-to-remove-herss-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is rise.exe, How to remove rise.exe</title>
		<link>http://htlogs.com/what-is-rise-exe-how-to-remove-rise-exe/</link>
		<comments>http://htlogs.com/what-is-rise-exe-how-to-remove-rise-exe/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 11:28:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=884</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: rise Filename: rise.exe Registry key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8396306-163b-11de-acda-001a4df2dae2} Command: F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\rise.exe CLSID: {b8396306-163b-11de-acda-001a4df2dae2} Startup Type: autorun.inf Combofix/RSIT Line: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> rise<br />
<strong>Filename:</strong> rise.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8396306-163b-11de-acda-001a4df2dae2}</p></blockquote>
<p><strong>Command:</strong> F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\rise.exe<br />
<strong>CLSID:</strong> {b8396306-163b-11de-acda-001a4df2dae2}<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8396306-163b-11de-acda-001a4df2dae2}]<br />
shell\AutoRun\command &#8211; F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\rise.exe<br />
shell\open\command &#8211; F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\rise.exe</p></blockquote>
<p><strong>Description:</strong> a trojan that uses autorun.inf file to spread itself</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">autorun.inf trojans removal</a> instructions, after that manually remove rise.exe</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-rise-exe-how-to-remove-rise-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ise32.exe is autorun.inf trojan</title>
		<link>http://htlogs.com/ise32-exe-is-autorun-inf-trojan/</link>
		<comments>http://htlogs.com/ise32-exe-is-autorun-inf-trojan/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 04:23:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=774</guid>
		<description><![CDATA[ise32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ise32 Filename: ise32.exe Registry key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dac57b3a-30d1-11dd-ad23-0008a1a9244d} Command: E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe CLSID: {dac57b3a-30d1-11dd-ad23-0008a1a9244d} Startup Type: autorun.inf Combofix/RSIT Line: [...]]]></description>
			<content:encoded><![CDATA[<h2>ise32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ise32<br />
<strong>Filename:</strong> ise32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dac57b3a-30d1-11dd-ad23-0008a1a9244d}</p></blockquote>
<p><strong>Command:</strong> E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe<br />
<strong>CLSID:</strong> {dac57b3a-30d1-11dd-ad23-0008a1a9244d}<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dac57b3a-30d1-11dd-ad23-0008a1a9244d}]<br />
shell\AutoRun\command &#8211; E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe<br />
shell\open\command &#8211; E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe</p></blockquote>
<p><strong>Description:</strong> autorun.inf trojan also known as Trojan-DDoS.Win32.Agent</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">autorun.inf trojans removal</a> instructions + use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/ise32-exe-is-autorun-inf-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>jwgkvsq.vmx is component of Conficker worm</title>
		<link>http://htlogs.com/jwgkvsq-vmx-is-component-of-conficker-worm/</link>
		<comments>http://htlogs.com/jwgkvsq-vmx-is-component-of-conficker-worm/#comments</comments>
		<pubDate>Sun, 26 Jul 2009 13:22:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Worm]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=653</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: jwgkvsq Filename: jwgkvsq.vmx Registry key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adaa1c54-332e-11de-bf44-001c25045ca7} Command: F:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx CLSID: {adaa1c54-332e-11de-bf44-001c25045ca7} Startup Type: autorun.inf Combofix/RSIT Line: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> jwgkvsq<br />
<strong>Filename:</strong> jwgkvsq.vmx<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adaa1c54-332e-11de-bf44-001c25045ca7}</p></blockquote>
<p><strong>Command:</strong> F:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx<br />
<strong>CLSID:</strong> {adaa1c54-332e-11de-bf44-001c25045ca7}<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adaa1c54-332e-11de-bf44-001c25045ca7}]<br />
shell\AutoRun\command &#8211; C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn</p></blockquote>
<p><strong>Description:</strong> component of Conficker worm also known as Kido worm</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2009/01/12/how-to-remove-win32confickeraa-win32wormdownadupgen/">Conficker removal instructions</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/jwgkvsq-vmx-is-component-of-conficker-worm/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>brzycg.exe is an autorun.inf trojan</title>
		<link>http://htlogs.com/brzycgexe-is-an-autoruninf-trojan/</link>
		<comments>http://htlogs.com/brzycgexe-is-an-autoruninf-trojan/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 02:14:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=540</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: brzycg Filename: brzycg.exe Registry key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\ {fd700ec2-fc05-11dd-b448-001fd00766ec} CLSID: {fd700ec2-fc05-11dd-b448-001fd00766ec} Startup Type: autorun.inf Combofix/RSIT Line: [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fd700ec2-fc05-11dd-b448-001fd00766ec}] [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> brzycg<br />
<strong>Filename:</strong> brzycg.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\ {fd700ec2-fc05-11dd-b448-001fd00766ec}</p></blockquote>
<p><strong>CLSID:</strong> {fd700ec2-fc05-11dd-b448-001fd00766ec}<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fd700ec2-fc05-11dd-b448-001fd00766ec}]<br />
shell\AutoRun\command &#8211; brzycg.exe<br />
shell\explore\command &#8211; brzycg.exe<br />
shell\open\command &#8211; brzycg.exe
</p></blockquote>
<p><strong>Description:</strong> an autorun.inf trojan</p>
<p><strong>How to remove:</strong> read the article &#8211; <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">How to remove trojans that uses autorun.inf file</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/brzycgexe-is-an-autoruninf-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>uxdeiect.com is malware, autorun.inf trojan</title>
		<link>http://htlogs.com/uxdeiectcom-is-malware-autoruninf-trojan/</link>
		<comments>http://htlogs.com/uxdeiectcom-is-malware-autoruninf-trojan/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 14:24:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=335</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: uxdeiect Filename: uxdeiect.com CLSID: {8e508249-a76f-11dd-8359-001e4cf19625} Startup Type: autorun.inf Combofix/RSIT Line: [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e508249-a76f-11dd-8359-001e4cf19625}] shell\AutoRun\command &#8211; uxdeiect.com shell\explore\command [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> uxdeiect<br />
<strong>Filename:</strong> uxdeiect.com<br />
<strong>CLSID:</strong> {8e508249-a76f-11dd-8359-001e4cf19625}<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e508249-a76f-11dd-8359-001e4cf19625}]<br />
shell\AutoRun\command &#8211; uxdeiect.com<br />
shell\explore\command &#8211; uxdeiect.com<br />
shell\open\command &#8211; uxdeiect.com</p></blockquote>
<p><strong>Description:</strong> malware (autorun.inf trojan)</p>
<p><strong>How to remove:</strong> use the instructions <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">How to remove trojans that uses autorun.inf file</a> + manually remove the file.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/uxdeiectcom-is-malware-autoruninf-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>printer.exe is a malware, autorun.inf trojan</title>
		<link>http://htlogs.com/printerexe-is-a-malware-autoruninf-trojan/</link>
		<comments>http://htlogs.com/printerexe-is-a-malware-autoruninf-trojan/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 14:20:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=332</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: printer Filename: printer.exe CLSID: {86d2e059-9871-11dd-94d9-001e4cf19625} Startup Type: autorun.inf [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86d2e059-9871-11dd-94d9-001e4cf19625}] shell\Auto\command &#8211; F:\printer.exe shell\AutoRun\command &#8211; C:\Windows\system32\RunDLL32.EXE [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> printer<br />
<strong>Filename:</strong> printer.exe<br />
<strong>CLSID:</strong> {86d2e059-9871-11dd-94d9-001e4cf19625}<br />
<strong>Startup Type:</strong> autorun.inf</p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86d2e059-9871-11dd-94d9-001e4cf19625}]<br />
shell\Auto\command &#8211; F:\printer.exe<br />
shell\AutoRun\command &#8211; C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\printer.exe</p></blockquote>
<p><strong>Description:</strong> malware (autorun.inf trojan)</p>
<p><strong>How to remove:</strong> use the instructions <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">How to remove trojans that uses autorun.inf file</a> + manually remove the file.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/printerexe-is-a-malware-autoruninf-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
