<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Policies\Explorer\Run</title>
	<atom:link href="http://htlogs.com/category/startup-type/policiesexplorerrun/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is tskmgr.exe, How to remove tskmgr.exe</title>
		<link>http://htlogs.com/what-is-tskmgr-exe-how-to-remove-tskmgr-exe/</link>
		<comments>http://htlogs.com/what-is-tskmgr-exe-how-to-remove-tskmgr-exe/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 13:54:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1996</guid>
		<description><![CDATA[tskmgr.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: tskmgr Filename: tskmgr.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; waults Command: %AppData%\tskmgr.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>tskmgr.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> tskmgr<br />
<strong>Filename:</strong> tskmgr.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | waults</p></blockquote>
<p><strong>Command:</strong> %AppData%\tskmgr.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Policies\Explorer\Run: [waults] C:\Documents and Settings\Username\Application Data\tskmgr.exe</p></blockquote>
<p><strong>Description:</strong> a trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-tskmgr-exe-how-to-remove-tskmgr-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is l84alx.exe, How to remove l84alx.exe</title>
		<link>http://htlogs.com/what-is-l84alx-exe-how-to-remove-l84alx-exe/</link>
		<comments>http://htlogs.com/what-is-l84alx-exe-how-to-remove-l84alx-exe/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 13:10:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1846</guid>
		<description><![CDATA[l84alx.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: l84alx Filename: l84alx.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; tcyz46 Command: %Temp%\l84alx.exe Startup Type: HKLM->Policies\Explorer\Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>l84alx.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> l84alx<br />
<strong>Filename:</strong> l84alx.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | tcyz46</p></blockquote>
<p><strong>Command:</strong> %Temp%\l84alx.exe<br />
<strong>Startup Type:</strong> HKLM->Policies\Explorer\Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Policies\Explorer\Run: [tcyz46] C:\DOCUME~1\User\LOCALS~1\Temp\l84alx.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]<br />
&#8220;tcyz46&#8243;=C:\DOCUME~1\User\LOCALS~1\Temp\l84alx.exe</p></blockquote>
<p><strong>Description:</strong> trojan also known as Trojan.Gen [PCTools], Trojan.Gen [Symantec], Backdoor.Win32.VB.lvn [Kaspersky Lab], Mal/VB-CF [Sophos], Trojan:Win32/Neop [Microsoft], Backdoor.Win32.VB [Ikarus]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-l84alx-exe-how-to-remove-l84alx-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is jjdrive32.exe, How to remove jjdrive32.exe</title>
		<link>http://htlogs.com/what-is-jjdrive32-exe-how-to-remove-jjdrive32-exe/</link>
		<comments>http://htlogs.com/what-is-jjdrive32-exe-how-to-remove-jjdrive32-exe/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 14:50:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1472</guid>
		<description><![CDATA[jjdrive32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: jjdrive32 Filename: jjdrive32.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; Microsoft Update Setup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run &#124; Microsoft Update Setup [...]]]></description>
			<content:encoded><![CDATA[<h2>jjdrive32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> jjdrive32<br />
<strong>Filename:</strong> jjdrive32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Microsoft Update Setup<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run | Microsoft Update Setup</p></blockquote>
<p><strong>Command:</strong> %Windir%\jjdrive32.exe<br />
<strong>Startup Type:</strong> HKLM->Run, HKLM->Policies\Explorer\Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [Microsoft Update Setup] C:\Windows\jjdrive32.exe<br />
O4 &#8211; HKLM\..\policies\Explorer\Run: [Microsoft Update Setup] C:\Windows\jjdrive32.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [Microsoft Update Setup] C:\Windows\jjdrive32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Microsoft Update Setup&#8221;=C:\Windows\jjdrive32.exe<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]<br />
&#8220;Microsoft Update Setup&#8221;=C:\Windows\jjdrive32.exe</p></blockquote>
<p><strong>Description:</strong> worm also known as Net-Worm.Spybot [PCTools], W32.Spybot.Worm [Symantec], Net-Worm.Win32.Kolab.fem [Kaspersky Lab], W32/Kolab [McAfee], Mal/Generic-A [Sophos], Worm:Win32/Pushbot.OF [Microsoft]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-jjdrive32-exe-how-to-remove-jjdrive32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is spoo1sv.exe, How to remove spoo1sv.exe</title>
		<link>http://htlogs.com/what-is-spoo1sv-exe-how-to-remove-spoo1sv-exe/</link>
		<comments>http://htlogs.com/what-is-spoo1sv-exe-how-to-remove-spoo1sv-exe/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 12:59:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1468</guid>
		<description><![CDATA[spoo1sv.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: spoo1sv Filename: spoo1sv.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; spoo1sv Startup Type:HKCU->Policies\Explorer\Run HijackThis Category: O4 HijackThis Line: [...]]]></description>
			<content:encoded><![CDATA[<h2>spoo1sv.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> spoo1sv<br />
<strong>Filename:</strong> spoo1sv.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | spoo1sv</p></blockquote>
<p><strong>Startup Type:</strong>HKCU->Policies\Explorer\Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Policies\Explorer\Run: [spoo1sv] spoo1sv.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]<br />
&#8220;spoo1sv&#8221;=spoo1sv.exe</p></blockquote>
<p><strong>Description:</strong> trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-spoo1sv-exe-how-to-remove-spoo1sv-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is msdrv32.exe, How to remove msdrv32.exe</title>
		<link>http://htlogs.com/what-is-msdrv32-exe-how-to-remove-msdrv32-exe/</link>
		<comments>http://htlogs.com/what-is-msdrv32-exe-how-to-remove-msdrv32-exe/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 16:42:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1361</guid>
		<description><![CDATA[msdrv32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: msdrv32 Filename: msdrv32.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; Microsoft Driver Setup HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run &#124; Microsoft Driver Setup [...]]]></description>
			<content:encoded><![CDATA[<h2>msdrv32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> msdrv32<br />
<strong>Filename:</strong> msdrv32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Microsoft Driver Setup<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run | Microsoft Driver Setup</p></blockquote>
<p><strong>Command:</strong> %WinDir%\msdrv32.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKLM\..\Run: [Microsoft Driver Setup] C:\Windows\msdrv32.exe<br />
O4 – HKLM\..\policies\Explorer\Run: [Microsoft Driver Setup] C:\Windows\msdrv32.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [Microsoft Driver Setup] C:\Windows\msdrv32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\Windows\msdrv32.exe<br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\Windows\msdrv32.exe</p></blockquote>
<p><strong>Description:</strong> worm also known  as Worm:Win32/Pushbot.gen [Microsoft], Backdoor.Win32.IRCBot.gen [Kaspersky Lab], Exploit-DcomRpc.gen [McAfee], Mal/Behav-134, Mal/IRCBot-B [Sophos]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-msdrv32-exe-how-to-remove-msdrv32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ccdrive32.exe, How to remove ccdrive32.exe</title>
		<link>http://htlogs.com/what-is-ccdrive32-exe-how-to-remove-ccdrive32-exe/</link>
		<comments>http://htlogs.com/what-is-ccdrive32-exe-how-to-remove-ccdrive32-exe/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 05:02:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1148</guid>
		<description><![CDATA[ccdrive32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ccdrive32 Filename: ccdrive32.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; Microsoft Driver Setup HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run &#124; Microsoft Driver Setup [...]]]></description>
			<content:encoded><![CDATA[<h2>ccdrive32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ccdrive32<br />
<strong>Filename:</strong> ccdrive32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Microsoft Driver Setup<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run | Microsoft Driver Setup</p></blockquote>
<p><strong>Command:</strong> C:\Windows\ccdrive32.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [Microsoft Driver Setup] C:\Windows\ccdrive32.exe<br />
O4 &#8211; HKLM\..\policies\Explorer\Run: [Microsoft Driver Setup] C:\Windows\ccdrive32.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [Microsoft Driver Setup] C:\Windows\ccdrive32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\Windows\ccdrive32.exe<br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\Windows\ccdrive32.exe</p></blockquote>
<p><strong>Description:</strong> trojan also known as Trojan.Win32.Buzus.crty [Kaspersky Lab], Worm:Win32/Pushbot.gen [Microsoft]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ccdrive32-exe-how-to-remove-ccdrive32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is wind7upd.exe, How to remove wind7upd.exe</title>
		<link>http://htlogs.com/what-is-wind7upd-exe-how-to-remove-wind7upd-exe/</link>
		<comments>http://htlogs.com/what-is-wind7upd-exe-how-to-remove-wind7upd-exe/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 11:31:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1076</guid>
		<description><![CDATA[wind7upd.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: wind7upd Filename: wind7upd.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run &#124; Microsoft Driver Setup HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; Microsoft Driver Setup [...]]]></description>
			<content:encoded><![CDATA[<h2>wind7upd.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> wind7upd<br />
<strong>Filename:</strong> wind7upd.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run | Microsoft Driver Setup<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Microsoft Driver Setup</p></blockquote>
<p><strong>Command:</strong> C:\Windows\wind7upd.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4:HKLM\..\Run: [Microsoft Driver Setup] C:\Windows\wind7upd.exe<br />
O4:HKLM\..\policies\Explorer\Run: [Microsoft Driver Setup] C:\Windows\wind7upd.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [Microsoft Driver Setup] C:\Windows\wind7upd.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\Windows\wind7upd.exe<br />
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\Windows\wind7upd.exe</p></blockquote>
<p><strong>Description:</strong> trojan downloader</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-wind7upd-exe-how-to-remove-wind7upd-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is servises.Exe, How to remove servises.Exe</title>
		<link>http://htlogs.com/what-is-servises-exe-how-to-remove-servises-exe/</link>
		<comments>http://htlogs.com/what-is-servises-exe-how-to-remove-servises-exe/#comments</comments>
		<pubDate>Sat, 24 Oct 2009 15:30:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=896</guid>
		<description><![CDATA[servises.Exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: servises Filename: servises.Exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; servises HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; servises HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; servises HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run [...]]]></description>
			<content:encoded><![CDATA[<h2>servises.Exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> servises<br />
<strong>Filename:</strong> servises.Exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | servises<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | servises<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | servises<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | servises</p></blockquote>
<p><strong>Command:</strong> C:\Windows\system32\servises.Exe<br />
<strong>Startup Type:</strong> HKCU->Run, HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [servises] C:\Windows\system32\servises.Exe<br />
O4 &#8211; HKCU\..\Run: [servises] C:\Windows\system32\servises.Exe<br />
O4 &#8211; HKLM\..\Policies\Explorer\Run: [servises] C:\Windows\system32\servises.Exe<br />
O4 &#8211; HKCU\..\Policies\Explorer\Run: [servises] C:\Windows\system32\servises.Exe</p></blockquote>
<p><strong>Description:</strong> trojan that installed with <a href="http://progssecurityblog.blogspot.com/2009/11/antivirus-system-pro-is-rogue.html">Antivirus System Pro</a> (rogue antispyware program)</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2009/06/05/how-to-remove-antivirus-system-pro-uninstall-instructions/">Antivirus System Pro removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-servises-exe-how-to-remove-servises-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>avdrive32.exe is Win32.IRCBot worm</title>
		<link>http://htlogs.com/avdrive32-exe-is-win32-ircbot-worm/</link>
		<comments>http://htlogs.com/avdrive32-exe-is-win32-ircbot-worm/#comments</comments>
		<pubDate>Mon, 07 Sep 2009 12:37:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=736</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: avdrive32 Filename: avdrive32.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; Microsoft Driver Setup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Driver Setup Command: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> avdrive32<br />
<strong>Filename:</strong> avdrive32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | Microsoft Driver Setup<br />
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Driver Setup</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\avdrive32.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] C:\WINDOWS\avdrive32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\WINDOWS\avdrive32.exe [2009-09-04 81408]<br />
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Driver Setup]<br />
C:\WINDOWS\avdrive32.exe [2009-09-04 81408]<br />
2009-09-03 21:19:12 &#8212;-RSH&#8212;- C:\WINDOWS\avdrive32.exe</p></blockquote>
<p><strong>Description:</strong> Win32.IRCBot worm also known as Backdoor.Win32.IRCBot.gen, Worm:Win32/Pushbot</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/avdrive32-exe-is-win32-ircbot-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>waw32.exe is trojan-dropper [Worm.Palevo]</title>
		<link>http://htlogs.com/waw32-exe-is-trojan-dropper-worm-palevo/</link>
		<comments>http://htlogs.com/waw32-exe-is-trojan-dropper-worm-palevo/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 03:36:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=687</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: waw32 Filename: waw32.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; Microsoft Driver Setup HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; Microsoft Driver Setup [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> waw32<br />
<strong>Filename:</strong> waw32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Microsoft Driver Setup<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | Microsoft Driver Setup</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\waw32.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [Microsoft Driver Setup] C:\WINDOWS\waw32.exe<br />
O4 &#8211; HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] C:\WINDOWS\waw32.exe
</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\WINDOWS\waw32.exe [2009-08-20 84992]</p>
<p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]<br />
&#8220;Microsoft Driver Setup&#8221;=C:\WINDOWS\waw32.exe [2009-08-20 84992]</p></blockquote>
<p><strong>Description:</strong> trojan-dropper, also known as Worm.Palevo</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/waw32-exe-is-trojan-dropper-worm-palevo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

