<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; File associations</title>
	<atom:link href="http://htlogs.com/category/startup-type/file-associations/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is vz.exe, How to remove vz.exe</title>
		<link>http://htlogs.com/what-is-vz-exe-how-to-remove-vz-exe/</link>
		<comments>http://htlogs.com/what-is-vz-exe-how-to-remove-vz-exe/#comments</comments>
		<pubDate>Mon, 22 Nov 2010 20:28:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2045</guid>
		<description><![CDATA[vz.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: vz Filename: vz.exe Registry key: HKEY_CURRENT_USER\Software\Classes\.exe HKEY_CURRENT_USER\Software\Classes\pezfile HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command &#124; @ = “”%AppData%\vz.exe” /START “%1″ %*” [...]]]></description>
			<content:encoded><![CDATA[<h2>vz.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> vz<br />
<strong>Filename:</strong> vz.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Classes\.exe<br />
HKEY_CURRENT_USER\Software\Classes\pezfile<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = “”%AppData%\vz.exe” /START “%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = “”%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\.exe | @ = “pezfile”<br />
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = “application/x-msdownload”<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | @ = “”%AppData%\vz.exe” /START “%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | IsolatedCommand = “”%1″ %*”</p></blockquote>
<p><strong>Command:</strong> %Appdata%\vz.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong>Description:</strong> main executable file of XP Antispyware 2011, Vista Antispyware 2011, Win 7 Antispyware 2011, XP Security 2011, Vista Security 2011, Win 7 Security 2011, XP Internet Security 2011, Vista Internet Security 2011, Win 7 Internet Security 2011, XP Antimalware 2011, Vista Antimalware 2011, Win 7 Antimalware 2011, XP Guard Vista Guard, Win 7 Guard. All programs are rogue antispyware.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/11/22/how-to-remove-vz-exe-malware/-malware/">vz.exe removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-vz-exe-how-to-remove-vz-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is pw.exe, How to remove pw.exe</title>
		<link>http://htlogs.com/what-is-pw-exe-how-to-remove-pw-exe/</link>
		<comments>http://htlogs.com/what-is-pw-exe-how-to-remove-pw-exe/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 01:51:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2042</guid>
		<description><![CDATA[pw.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: pw Filename: pw.exe Registry key: HKEY_CURRENT_USER\Software\Classes\.exe HKEY_CURRENT_USER\Software\Classes\pezfile HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command &#124; @ = “”%AppData%\pw.exe” /START “%1″ %*” [...]]]></description>
			<content:encoded><![CDATA[<h2>pw.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> pw<br />
<strong>Filename:</strong> pw.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Classes\.exe<br />
HKEY_CURRENT_USER\Software\Classes\pezfile<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = “”%AppData%\pw.exe” /START “%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = “”%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\.exe | @ = “pezfile”<br />
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = “application/x-msdownload”<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | @ = “”%AppData%\pw.exe” /START “%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | IsolatedCommand = “”%1″ %*”</p></blockquote>
<p><strong>Command:</strong> %Appdata%\pw.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong>Description:</strong> main file of XP Antispyware 2011, Vista Antispyware 2011, Win 7 Antispyware 2011, XP Security 2011, Vista Security 2011, Win 7 Security 2011, XP Internet Security 2011, Vista Internet Security 2011, Win 7 Internet Security 2011, XP Antimalware 2011, Vista Antimalware 2011, Win 7 Antimalware 2011, XP Guard Vista Guard, Win 7 Guard. All programs are rogue antispyware.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/11/18/how-to-remove-pw-exe-malware/">pw.exe removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-pw-exe-how-to-remove-pw-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is wmsdk64_32.exe, How to remove wmsdk64_32.exe</title>
		<link>http://htlogs.com/what-is-wmsdk64_32-exe-how-to-remove-wmsdk64_32-exe/</link>
		<comments>http://htlogs.com/what-is-wmsdk64_32-exe-how-to-remove-wmsdk64_32-exe/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 19:00:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1884</guid>
		<description><![CDATA[wmsdk64_32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: wmsdk64_32 Filename: wmsdk64_32.exe Registry key: HKEY_CLASSES_ROOT\exefile\shell\open\command &#124; @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\wmsdk64_32.EXE\” /START \”%1\” %*” Command: %Temp%\wmsdk64_32.exe Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>wmsdk64_32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> wmsdk64_32<br />
<strong>Filename:</strong> wmsdk64_32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CLASSES_ROOT\exefile\shell\open\command | @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\wmsdk64_32.EXE\” /START \”%1\” %*”</p></blockquote>
<p><strong>Command:</strong> %Temp%\wmsdk64_32.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>.exe – open – “C:\DOCUME~1\comp\LOCALS~1\Temp\wmsdk64_32.exe” /START “%1″ %*</p></blockquote>
<p><strong>Description:</strong> trojan FakeAlert that uses to install Antivirus (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/03/how-to-remove-antivirus-uninstall-instructions-2/">Antivirus removal</a> guide or the steps below.</p>
<p>1. Download fix.zip from <a href="http://www.myantispyware.com/wp-content/uploads/2010/06/fix.zip">here</a>, unzip it. Double Click fix.reg and click YES for confirm.</p>
<p>2. Download TDSSKiller from <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip">here</a> and unzip to your desktop. Open tdsskiller folder and right click to TDSSKiller, select Rename. Type something like 123myname and press Enter. Double click it and follow the prompts.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install and perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-wmsdk64_32-exe-how-to-remove-wmsdk64_32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is MSDERUN.EXE, How to remove MSDERUN.EXE</title>
		<link>http://htlogs.com/what-is-msderun-exe-how-to-remove-msderun-exe/</link>
		<comments>http://htlogs.com/what-is-msderun-exe-how-to-remove-msderun-exe/#comments</comments>
		<pubDate>Sat, 17 Jul 2010 15:05:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1830</guid>
		<description><![CDATA[MSDERUN.EXE is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: MSDERUN Filename: MSDERUN.EXE Registry key: HKEY_CLASSES_ROOT\exefile\shell\open\command &#124; @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\MSDERUN.EXE\” /START \”%1\” %*” Command: %Temp%\MSDERUN.EXE Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>MSDERUN.EXE is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> MSDERUN<br />
<strong>Filename:</strong> MSDERUN.EXE<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CLASSES_ROOT\exefile\shell\open\command | @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\MSDERUN.EXE\” /START \”%1\” %*”</p></blockquote>
<p><strong>Command:</strong> %Temp%\MSDERUN.EXE<br />
<strong>Startup Type:</strong> File associations<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>.exe – open – “C:\DOCUME~1\comp\LOCALS~1\Temp\MSDERUN.EXE” /START “%1″ %*</p></blockquote>
<p><strong>Description:</strong> trojan FakeAlert that uses to install Defense Center (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/06/12/how-to-remove-defense-center-uninstall-instructions/">Defense center removal</a> guide or the steps below.</p>
<p>1. Download fix.zip from <a href="http://www.myantispyware.com/wp-content/uploads/2010/06/fix.zip">here</a>, unzip it. Double Click fix.reg and click YES for confirm.</p>
<p>2. Download TDSSKiller from <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip">here</a> and unzip to your desktop. Open tdsskiller folder and right click to TDSSKiller, select Rename. Type something like 123myname and press Enter. Double click it and follow the prompts.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install and perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-msderun-exe-how-to-remove-msderun-exe/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>What is autmgr32.exe, How to remove autmgr32.exe</title>
		<link>http://htlogs.com/what-is-autmgr32-exe-how-to-remove-autmgr32-exe/</link>
		<comments>http://htlogs.com/what-is-autmgr32-exe-how-to-remove-autmgr32-exe/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 15:27:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1806</guid>
		<description><![CDATA[autmgr32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: autmgr32 Filename: autmgr32.exe Registry key: HKEY_CLASSES_ROOT\exefile\shell\open\command &#124; @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\autmgr32.exe\” /START \”%1\” %*” Command: %Temp%\autmgr32.exe Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>autmgr32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> autmgr32<br />
<strong>Filename:</strong> autmgr32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CLASSES_ROOT\exefile\shell\open\command | @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\autmgr32.exe\” /START \”%1\” %*”</p></blockquote>
<p><strong>Command:</strong> %Temp%\autmgr32.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>.exe – open – “C:\DOCUME~1\comp\LOCALS~1\Temp\autmgr32.exe” /START “%1″ %*</p></blockquote>
<p><strong>Description:</strong> autmgr32.exe (located in Temp folder) is a trojan FakeAlert that uses to install Defense Center (rogue antispyware). Legitimate autmgr32.exe located in C:\WINDOWS\system32\ folder.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/06/28/remove-defcnt-exe-autmgr32-exe-wscsvc32-exe/">defcnt.exe, autmgr32.exe, wscsvc32.exe malware removal</a> instructions or the steps below.</p>
<p>1. Download fix.zip from <a href="http://www.myantispyware.com/wp-content/uploads/2010/06/fix.zip">here</a>, unzip it. Double Click fix.reg and click YES for confirm.</p>
<p>2. Download TDSSKiller from <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip">here</a> and unzip to your desktop. Open tdsskiller folder and right click to TDSSKiller, select Rename. Type something like 123myname and press Enter. Double click it and follow the prompts.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install and perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-autmgr32-exe-how-to-remove-autmgr32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is esentutl64.exe, How to remove esentutl64.exe</title>
		<link>http://htlogs.com/what-is-esentutl64-exe-how-to-remove-esentutl64-exe/</link>
		<comments>http://htlogs.com/what-is-esentutl64-exe-how-to-remove-esentutl64-exe/#comments</comments>
		<pubDate>Sat, 12 Jun 2010 14:13:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1787</guid>
		<description><![CDATA[esentutl64.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: esentutl64 Filename: esentutl64.exe Registry key: HKEY_CLASSES_ROOT\exefile\shell\open\command &#124; @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\esentutl64.exe\” /START \”%1\” %*” Command: %Temp%\esentutl64.exe Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>esentutl64.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> esentutl64<br />
<strong>Filename:</strong> esentutl64.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CLASSES_ROOT\exefile\shell\open\command | @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\esentutl64.exe\” /START \”%1\” %*”</p></blockquote>
<p><strong>Command:</strong> %Temp%\esentutl64.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>.exe &#8211; open &#8211; &#8220;C:\DOCUME~1\comp\LOCALS~1\Temp\esentutl64.exe&#8221; /START &#8220;%1&#8243; %*</p></blockquote>
<p><strong>Description:</strong> trojan FakeAlert that installed with Defense Center. Defense Center is a rogue (fake) antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/06/12/how-to-remove-defense-center-uninstall-instructions/">Defense Center removal</a> instructions or the steps below.</p>
<p>1. Download fix.zip from <a href="http://www.myantispyware.com/wp-content/uploads/2010/06/fix.zip">here</a>, unzip it. Double Click fix.reg and click YES for confirm.</p>
<p>2. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="blue">:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Defense Center&#8221;=-</p>
<p>:files<br />
C:\Program Files\Defense Center</font></p>
<p>Click the red Moveit! button. Close OTM.</p>
<p>3. Download TDSSKiller from <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip">here</a> and unzip to your desktop. Open tdsskiller folder and right click to TDSSKiller, select Rename. Type something like 123myname and press Enter. Double click it and follow the prompts.</p>
<p>4. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install and perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-esentutl64-exe-how-to-remove-esentutl64-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is mscdexnt.exe, How to remove mscdexnt.exe</title>
		<link>http://htlogs.com/what-is-mscdexnt-exe-how-to-remove-mscdexnt-exe/</link>
		<comments>http://htlogs.com/what-is-mscdexnt-exe-how-to-remove-mscdexnt-exe/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 17:23:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1764</guid>
		<description><![CDATA[mscdexnt.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: mscdexnt Filename: mscdexnt.exe Registry key: HKEY_CLASSES_ROOT\exefile\shell\open\command &#124; @=&#8221;\&#8221;C:\DOCUME~1\user\LOCALS~1\Temp\mscdexnt.exe\&#8221; /START \&#8221;%1\&#8221; %*&#8221; Command: %Temp%\mscdexnt.exe Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>mscdexnt.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> mscdexnt<br />
<strong>Filename:</strong> mscdexnt.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CLASSES_ROOT\exefile\shell\open\command | @=&#8221;\&#8221;C:\DOCUME~1\user\LOCALS~1\Temp\mscdexnt.exe\&#8221; /START \&#8221;%1\&#8221; %*&#8221;</p></blockquote>
<p><strong>Command:</strong> %Temp%\mscdexnt.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>.exe &#8211; open &#8211; &#8220;C:\DOCUME~1\user\LOCALS~1\Temp\mscdexnt.exe&#8221; /START &#8220;%1&#8243; %*</p></blockquote>
<p><strong>Description:</strong> trojan FakeAlert that installed with Protection Center. Protection Center is a rogue (fake) antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/06/01/how-to-remove-protection-center-uninstall-instructions/">Protection Center removal</a> instructions or the steps below.</p>
<p>1. Download fix.zip from <a href="http://www.myantispyware.com/wp-content/uploads/2010/05/fix.zip">here</a>, unzip it. Double Click fix.reg and click YES for confirm. Reboot your computer.</p>
<p>2. Download TDSSKiller from <a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip">here</a> and unzip to your desktop. Open tdsskiller folder and right click to TDSSKiller, select Rename. Type something like 123myname and press Enter. Double click it and follow the prompts.</p>
<p>3. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color=blue>:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Protection Center&#8221;=-</p>
<p>:files<br />
C:\Program Files\Protection Center</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font><br />
Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install and perform a scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-mscdexnt-exe-how-to-remove-mscdexnt-exe/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Win Antispyware Center &#8211; av.exe</title>
		<link>http://htlogs.com/win-antispyware-center-av-exe/</link>
		<comments>http://htlogs.com/win-antispyware-center-av-exe/#comments</comments>
		<pubDate>Sun, 23 May 2010 13:36:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1734</guid>
		<description><![CDATA[av.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: av Filename: av.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\shell HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile HKEY_CURRENT_USER\Software\Classes\.exe HKEY_CURRENT_USER\Software\Classes\secfile HKEY_CURRENT_USER\Software\Win Antispyware Center HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Win Antispyware Center [...]]]></description>
			<content:encoded><![CDATA[<h2>av.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> av<br />
<strong>Filename:</strong> av.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\shell<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secfile<br />
HKEY_CURRENT_USER\Software\Classes\.exe<br />
HKEY_CURRENT_USER\Software\Classes\secfile<br />
HKEY_CURRENT_USER\Software\Win Antispyware Center<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Win Antispyware Center<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Win Antispyware Center</p></blockquote>
<p><strong>Command:</strong> command<br />
<strong>Startup Type:</strong> HKLM->Run, HKCU->Run, File associations<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [Win Antispyware Center] C:\Program Files\WinAntispywareCenter\av.exe<br />
O4 &#8211; HKCU\..\Run: [Win Antispyware Center] C:\Program Files\WinAntispywareCenter\av.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [Win Antispyware Center] C:\Program Files\WinAntispywareCenter\av.exe<br />
uRun: [Win Antispyware Center] C:\Program Files\WinAntispywareCenter\av.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Win Antispyware Center&#8221;=C:\Program Files\WinAntispywareCenter\av.exe<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Win Antispyware Center&#8221;=C:\Program Files\WinAntispywareCenter\av.exe</p></blockquote>
<p><strong>Description:</strong> core component of Win Antispyware Center. Win Antispyware Center is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/05/23/how-to-remove-win-antispyware-center-uninstall-instructions/">Win Antispyware Center removal</a> instructions or the steps below.<br />
1. Download fix1.zip from <a href="http://www.myantispyware.com/wp-content/uploads/2010/05/fix1.zip">here</a>, unzip it. Right click fix.inf and select Install.</p>
<p>2. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in &#8220;Paste Instructions for Items to be Moved&#8221; window (under the yellow bar):<br />
<font color=blue><br />
:reg<br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Win Antispyware Center&#8221;=-</p>
<p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Win Antispyware Center&#8221;=-</p>
<p>:files<br />
C:\Program Files\WinAntispywareCenter</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font><br />
Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install and perform a scan.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/win-antispyware-center-av-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ave.exe &#8211; Total Vista Security, Vista Security Tool 2010</title>
		<link>http://htlogs.com/ave-exe-total-vista-security-vista-security-tool-2010/</link>
		<comments>http://htlogs.com/ave-exe-total-vista-security-vista-security-tool-2010/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 17:56:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1536</guid>
		<description><![CDATA[ave.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ave Filename: ave.exe Registry key: HKEY_CURRENT_USER\Software\Classes\.exe HKEY_CURRENT_USER\Software\Classes\secfile Command: %Appdata%\ave.exe Startup Type: File associations Description: core [...]]]></description>
			<content:encoded><![CDATA[<h2>ave.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ave<br />
<strong>Filename:</strong> ave.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Classes\.exe<br />
HKEY_CURRENT_USER\Software\Classes\secfile</p></blockquote>
<p><strong>Command:</strong> %Appdata%\ave.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong>Description:</strong> core component of Total Vista Security (Vista Security Tool 2010). Total Vista Security (Vista Security Tool 2010) is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/03/19/how-to-remove-ave-exe-malware/">ave.exe removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/ave-exe-total-vista-security-vista-security-tool-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XP AntiSpyware 2010, XP Antivirus Pro 2010 &#8211; av.exe</title>
		<link>http://htlogs.com/xp-antispyware-2010-xp-antivirus-pro-2010-av-exe/</link>
		<comments>http://htlogs.com/xp-antispyware-2010-xp-antivirus-pro-2010-av-exe/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 14:29:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1470</guid>
		<description><![CDATA[av.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: av Filename: av.exe Registry key: HKEY_CURRENT_USER\Software\Classes\.exe HKEY_CURRENT_USER\Software\Classes\secfile HKEY_CLASSES_ROOT\secfile HKEY_CLASSES_ROOT\.exe\shell\open\command Command: %Appdata%\av.exe Description: core component of [...]]]></description>
			<content:encoded><![CDATA[<h2>av.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> av<br />
<strong>Filename:</strong> av.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Classes\.exe<br />
HKEY_CURRENT_USER\Software\Classes\secfile<br />
HKEY_CLASSES_ROOT\secfile<br />
HKEY_CLASSES_ROOT\.exe\shell\open\command</p></blockquote>
<p><strong>Command:</strong> %Appdata%\av.exe<br />
<strong>Description:</strong> core component of XP AntiSpyware 2010, XP Antivirus Pro 2010. XP AntiSpyware 2010, XP Antivirus Pro 2010 &#8211; names of one program, that is a rogue antispyware application.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/02/22/how-to-remove-xp-antispyware-2010-xp-antivirus-pro-2010/">XP AntiSpyware 2010, XP Antivirus Pro 2010 removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/xp-antispyware-2010-xp-antivirus-pro-2010-av-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

