<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Driver</title>
	<atom:link href="http://htlogs.com/category/startup-type/driver/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is svc.exe, How to remove svc.exe</title>
		<link>http://htlogs.com/what-is-svc-exe-how-to-remove-svc-exe/</link>
		<comments>http://htlogs.com/what-is-svc-exe-how-to-remove-svc-exe/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 13:32:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1853</guid>
		<description><![CDATA[svc.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: svc Filename: svc.exe Registry key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetLog HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETLOG Command: %WinDir%\svc.exe Startup Type: Driver DDS/Combofix/RSIT Line Line: [...]]]></description>
			<content:encoded><![CDATA[<h2>svc.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> svc<br />
<strong>Filename:</strong> svc.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetLog<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETLOG</p></blockquote>
<p><strong>Command:</strong> %WinDir%\svc.exe<br />
<strong>Startup Type:</strong> Driver<br />
<strong>DDS/<a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line Line:</strong></p>
<blockquote><p>R3 NetLog;NetLog;c:\windows\svc.exe</p></blockquote>
<p><strong>Description:</strong> trojan also known as Suspicious.MH690 [Symantec], New Malware.n [McAfee], Mal/EncPk-BW, Mal/EncPk-BW [Sophos], Trojan-Banker.Win32.Banker [Ikarus], Packed/Upack [AhnLab], packed with UPack [Kaspersky Lab]<br />
<strong>Notes:</strong> installed with <a href="http://htlogs.com/what-is-l84alx-exe-how-to-remove-l84alx-exe/">l84alx.exe</a>, <a href="http://htlogs.com/what-is-msgciutr-dll-how-to-remove-msgciutr-dll/">msgciutr.dll</a>, <a href="http://htlogs.com/what-is-wmiprves-how-to-remove-wmiprves/">wmiprves</a></p>
<p><strong>How to remove:</strong> use the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:services<br />
NetLog</p>
<p>:reg<br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]<br />
“tcyz46″=-</p>
<p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“tghlig”=-</p>
<p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“wmiprves”=-</p>
<p>:files<br />
C:\WINDOWS\system32\msgciutr.dll</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-svc-exe-how-to-remove-svc-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is klmdb.sys, How to remove klmdb.sys</title>
		<link>http://htlogs.com/what-is-klmdb-sys-how-to-remove-klmdb-sys/</link>
		<comments>http://htlogs.com/what-is-klmdb-sys-how-to-remove-klmdb-sys/#comments</comments>
		<pubDate>Thu, 20 May 2010 07:58:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1724</guid>
		<description><![CDATA[klmdb.sys is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: klmdb Filename: klmdb.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys Command: C:\WINDOWS\system32\drivers\klmdb.sys Startup Type: Driver Combofix/RSIT Line: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys] [...]]]></description>
			<content:encoded><![CDATA[<h2>klmdb.sys is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> klmdb<br />
<strong>Filename:</strong> klmdb.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\drivers\klmdb.sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]<br />
S4 klmdb;klmdb; C:\WINDOWS\system32\drivers\klmdb.sys [2010-05-14 36488]</p></blockquote>
<p><strong>Description:</strong> trojan-rootkit</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> +  <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a> or manually instructions below.</p>
<blockquote><p>Download Avenger from <a href="http://swandog46.geekstogo.com/avenger.zip">here</a> and unzip to your desktop. Run Avenger, copy,then paste the following text in Input script Box:<br />
<font color="blue">Drivers to delete:<br />
klmdb</p>
<p>Registry keys to delete:<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys</p>
<p>Files to delete:<br />
C:\WINDOWS\system32\drivers\klmdb.sys</font><br />
Then click on ‘Execute’.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-klmdb-sys-how-to-remove-klmdb-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is PRAGMAd.sys, How to remove PRAGMAd.sys</title>
		<link>http://htlogs.com/what-is-pragmad-sys-how-to-remove-pragmad-sys/</link>
		<comments>http://htlogs.com/what-is-pragmad-sys-how-to-remove-pragmad-sys/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 18:04:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1625</guid>
		<description><![CDATA[PRAGMAd.sys is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: PRAGMAd Filename: PRAGMAd.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PRAGMA{random} HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PRAGMAd.sys Command: C:\WINDOWS\system32\drivers\PRAGMA{random}.sys C:\WINDOWS\PRAGMArchxnseqxn\PRAGMAd.sys Startup Type: hidden driver RootRepeal [...]]]></description>
			<content:encoded><![CDATA[<h2>PRAGMAd.sys is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> PRAGMAd<br />
<strong>Filename:</strong> PRAGMAd.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PRAGMA{random}<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PRAGMAd.sys</p></blockquote>
<p><strong>Command:</strong></p>
<blockquote><p>C:\WINDOWS\system32\drivers\PRAGMA{random}.sys<br />
C:\WINDOWS\PRAGMArchxnseqxn\PRAGMAd.sys</p></blockquote>
<p><strong>Startup Type:</strong> hidden driver<br />
<strong>RootRepeal shows infection:</strong></p>
<blockquote><p>Hidden Services<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Service Name: PRAGMAd.sys<br />
Image Path C:\WINDOWS\system32\drivers\PRAGMAewxhsvitbd.sys</p>
<p>Service Name: PRAGMArchxnseqxn<br />
Image Path C:\WINDOWS\PRAGMArchxnseqxn\PRAGMAd.sys
</p></blockquote>
<p><strong>GMER shows infection:</strong></p>
<blockquote><p>Service  system32\drivers\PRAGMAewxhsvitbd.sys (*** hidden *** )    [SYSTEM] PRAGMAd.sys        <-- ROOTKIT !!!<br />
Service  C:\WINDOWS\PRAGMArchxnseqxn\PRAGMAd.sys (*** hidden *** )  [SYSTEM] PRAGMArchxnseqxn   <-- ROOTKIT !!! </p></blockquote>
<p><strong>Description:</strong> new variant of TDSS trojan</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2008/11/05/how-to-remove-trojan-tdsserv/">TDSS trojan removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-pragmad-sys-how-to-remove-pragmad-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is _VOIDd.sys, How to remove _VOIDd.sys</title>
		<link>http://htlogs.com/what-is-_voidd-sys-how-to-remove-_voidd-sys/</link>
		<comments>http://htlogs.com/what-is-_voidd-sys-how-to-remove-_voidd-sys/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 14:05:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1486</guid>
		<description><![CDATA[_VOIDd.sys is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: _VOID[random] Filename: _VOID[random].sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\_VOIDd.sys Command: %WinDir%\system32\drivers\_VOID[random].sys Startup Type: Hidden driver RootRepeal log line: [...]]]></description>
			<content:encoded><![CDATA[<h2>_VOIDd.sys is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> _VOID[random]<br />
<strong>Filename:</strong> _VOID[random].sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\_VOIDd.sys</p></blockquote>
<p><strong>Command:</strong> %WinDir%\system32\drivers\_VOID[random].sys<br />
<strong>Startup Type:</strong> Hidden driver<br />
<strong>RootRepeal log line:</strong></p>
<blockquote><p>Service Name: _VOIDd.sys<br />
Image Path: C:\WINDOWS\system32\drivers\_VOIDaabmetnqbf.sys</p></blockquote>
<p><strong>Description:</strong> variant of TDSS trojan</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2008/11/05/how-to-remove-trojan-tdsserv/">TDSS trojan removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-_voidd-sys-how-to-remove-_voidd-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ndisdrv.sys, How to remove ndisdrv.sys</title>
		<link>http://htlogs.com/what-is-ndisdrv-sys-how-to-remove-ndisdrv-sys/</link>
		<comments>http://htlogs.com/what-is-ndisdrv-sys-how-to-remove-ndisdrv-sys/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 15:18:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1304</guid>
		<description><![CDATA[ndisdrv.sys is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ndisdrv Filename: ndisdrv.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISDRV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ndisdrv HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISDRV HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ndisdrv Command: c:\windows\system32\ndisdrv.sys Startup Type: Driver DDS/Combofix/RSIT [...]]]></description>
			<content:encoded><![CDATA[<h2>ndisdrv.sys is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ndisdrv<br />
<strong>Filename:</strong> ndisdrv.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISDRV<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ndisdrv<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISDRV<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ndisdrv</p></blockquote>
<p><strong>Command:</strong> c:\windows\system32\ndisdrv.sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong>DDS/<a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>S3 ndisdrv;ndisdrv;\??\c:\windows\system32\ndisdrv.sys &#8211;> c:\windows\system32\ndisdrv.sys [?]</p></blockquote>
<p><strong>Description:</strong> trojan-rootkit also known as Mal/Rootkit-Q [Sophos]</p>
<p><strong>How to remove:</strong></p>
<blockquote><p>Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a><br />
Run OTM.<br />
Copy, then paste the following text in &#8220;Paste Instructions for Items to be Moved&#8221; window (under the yellow bar):</p>
<p><font color=blue>:services<br />
ndisdrv</p>
<p>:files<br />
c:\windows\system32\ndisdrv.sys</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. When the tool is finished, it will produce a report for you.<br />
Download and run <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ndisdrv-sys-how-to-remove-ndisdrv-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is H8SRT.sys, How to remove H8SRT.sys</title>
		<link>http://htlogs.com/what-is-h8srt-sys-how-to-remove-h8srt-sys/</link>
		<comments>http://htlogs.com/what-is-h8srt-sys-how-to-remove-h8srt-sys/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 14:48:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1239</guid>
		<description><![CDATA[H8SRT.sys is a harmful driver. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Driver name: H8SRT.sys Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\H8SRTd.sys Command: C:\WINDOWS\system32\drivers\H8SRT[random].sys Startup Type: Driver Description: trojan-rootkit also known [...]]]></description>
			<content:encoded><![CDATA[<h2>H8SRT.sys is a harmful driver.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Driver name:</strong> H8SRT.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\H8SRTd.sys</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\drivers\H8SRT[random].sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong>Description:</strong> trojan-rootkit also known as Rootkit.TDSS.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2009/12/22/how-to-remove-h8srt-trojan-remove-rootkit-tdss/">H8SRT trojan removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-h8srt-sys-how-to-remove-h8srt-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is tdidis32.sys, How to remove tdidis32.sys</title>
		<link>http://htlogs.com/what-is-tdidis32-sys-how-to-remove-tdidis32-sys/</link>
		<comments>http://htlogs.com/what-is-tdidis32-sys-how-to-remove-tdidis32-sys/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 11:46:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1004</guid>
		<description><![CDATA[tdidis32.sys is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: tdidis32 Filename: tdidis32.sys Command: C:\WINDOWS\system32\tdidis32.sys Startup Type: driver Combofix/RSIT Line: S1 tdidis32.sys;tdidis32.sys; \??\C:\WINDOWS\system32\tdidis32.sys [] Description: [...]]]></description>
			<content:encoded><![CDATA[<h2>tdidis32.sys is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> tdidis32<br />
<strong>Filename:</strong> tdidis32.sys<br />
<strong>Command:</strong> C:\WINDOWS\system32\tdidis32.sys<br />
<strong>Startup Type:</strong> driver<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>S1 tdidis32.sys;tdidis32.sys; \??\C:\WINDOWS\system32\tdidis32.sys []</p></blockquote>
<p><strong>Description:</strong> trojan agent also known as Rootkit.Win32.Pakes</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2007/11/06/superantispyware-free-for-home-use/">SUPERAntiSpyware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-tdidis32-sys-how-to-remove-tdidis32-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>fio32.sys is a trojan</title>
		<link>http://htlogs.com/fio32-sys-is-a-trojan/</link>
		<comments>http://htlogs.com/fio32-sys-is-a-trojan/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 11:30:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=831</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: fio32 Filename: fio32.sys Command: C:\Windows\system32\drivers\fio32.sys Startup Type: Driver Combofix/RSIT Line: R1 fio32;fio32; \??\C:\Windows\system32\drivers\fio32.sys [2009-09-23 37632] [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> fio32<br />
<strong>Filename:</strong> fio32.sys<br />
<strong>Command:</strong> C:\Windows\system32\drivers\fio32.sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>R1 fio32;fio32; \??\C:\Windows\system32\drivers\fio32.sys [2009-09-23 37632]</p></blockquote>
<p><strong>Description:</strong> trojan that installed by worm koobface</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/fio32-sys-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NDISRD.sys is trojan</title>
		<link>http://htlogs.com/ndisrd-sys-is-trojan/</link>
		<comments>http://htlogs.com/ndisrd-sys-is-trojan/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 15:56:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=812</guid>
		<description><![CDATA[NDISRD.sys is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: NDISRD Filename: NDISRD.sys Registry key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDISRD Command: C:\WINDOWS\system32\drivers\NDISRD.sys Startup Type: Driver Combofix/RSIT Line: S1 NDISRD;NDISRD; [...]]]></description>
			<content:encoded><![CDATA[<h2>NDISRD.sys is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> NDISRD<br />
<strong>Filename:</strong> NDISRD.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDISRD</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\drivers\NDISRD.sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>S1 NDISRD;NDISRD; C:\WINDOWS\system32\drivers\NDISRD.sys [2009-06-22 24576</p></blockquote>
<p><strong>Description:</strong> trojan also known as TrojanDownloader, it installed with Alpha Antivirus rogue antispyware program</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2009/09/28/remove-alpha-antivirus-uninstall-instructions/">Alpha Antivirus removal instructions</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/ndisrd-sys-is-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>dwshd.sys is trojan Win32.Agent</title>
		<link>http://htlogs.com/dwshd-sys-is-trojan-win32-agent/</link>
		<comments>http://htlogs.com/dwshd-sys-is-trojan-win32-agent/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 04:18:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=772</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: dwshd Filename: dwshd.sys Command: C:\WINDOWS\System32\drivers\dwshd.sys Startup Type: Driver Combofix/RSIT Line: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dwshd.sys] S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys [] [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> dwshd<br />
<strong>Filename:</strong> dwshd.sys<br />
<strong>Command:</strong> C:\WINDOWS\System32\drivers\dwshd.sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dwshd.sys]<br />
S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys []</p></blockquote>
<p><strong>Description:</strong> trojan also known as trojan.Win32Agent.</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/dwshd-sys-is-trojan-win32-agent/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

