<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; RunOnce</title>
	<atom:link href="http://htlogs.com/category/startup-type/runonce/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is upd_debug.exe, How to remove upd_debug.exe</title>
		<link>http://htlogs.com/what-is-upd_debug-exe-how-to-remove-upd_debug-exe/</link>
		<comments>http://htlogs.com/what-is-upd_debug-exe-how-to-remove-upd_debug-exe/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 17:23:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[RunOnce]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1862</guid>
		<description><![CDATA[upd_debug.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: upd_debug Filename: upd_debug.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce &#124; *upd_debug.exe Command: %AppData%\{RANDOM}\upd_debug.exe Startup Type: HKLM->RunOnce HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>upd_debug.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> upd_debug<br />
<strong>Filename:</strong> upd_debug.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | *upd_debug.exe</p></blockquote>
<p><strong>Command:</strong> %AppData%\{RANDOM}\upd_debug.exe<br />
<strong>Startup Type:</strong> HKLM->RunOnce<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\RunOnce: [*upd_debug.exe] &#8220;C:\Documents and Settings\user\Application Data\5E61DD380A45D30866E01CB0F8ECDE89\upd_debug.exe&#8221;</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRunOnce: [*upd_debug.exe] &#8220;C:\Documents and Settings\user\Application Data\5E61DD380A45D30866E01CB0F8ECDE89\upd_debug.exe&#8221;</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]<br />
&#8220;*upd_debug.exe&#8221;=C:\Documents and Settings\user\Application Data\5E61DD380A45D30866E01CB0F8ECDE89\upd_debug.exe</p></blockquote>
<p><strong>Description:</strong> core component of Antimalware Doctor (rogue antispyware)</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> +  <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-upd_debug-exe-how-to-remove-upd_debug-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is livemessenger.exe, How to remove livemessenger.exe</title>
		<link>http://htlogs.com/what-is-livemessenger-exe-how-to-remove-livemessenger-exe/</link>
		<comments>http://htlogs.com/what-is-livemessenger-exe-how-to-remove-livemessenger-exe/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 16:55:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[RunOnce]]></category>
		<category><![CDATA[RunOnceEx]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1363</guid>
		<description><![CDATA[livemessenger.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: livemessenger Filename: livemessenger.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run &#124; Microsoft Update HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce &#124; Microsoft Update HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx &#124; [...]]]></description>
			<content:encoded><![CDATA[<h2>livemessenger.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> livemessenger<br />
<strong>Filename:</strong> livemessenger.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Microsoft Update<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce | Microsoft Update<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx | Microsoft Update</p></blockquote>
<p><strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKLM\..\Run: [Microsoft Update] livemessenger.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [Microsoft Update] livemessenger.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Microsoft Update&#8221;=livemessenger.exe</p></blockquote>
<p><strong>Description:</strong> Backdoor.Win32.Rbot.bll [Kaspersky Lab], W32.IRCBot [Symantec], W32/Sdbot.worm.gen.t [McAfee]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-livemessenger-exe-how-to-remove-livemessenger-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>rkgnd.exe is component of ANG AntiVirus 09</title>
		<link>http://htlogs.com/rkgndexe-is-component-of-ang-antivirus-09/</link>
		<comments>http://htlogs.com/rkgndexe-is-component-of-ang-antivirus-09/#comments</comments>
		<pubDate>Mon, 02 Mar 2009 05:39:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[RunOnce]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=265</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: rkgnd Filename: rkgnd.exe Command: C:\Program Files\Common Files\System\mgnc\rkgnd.exe Startup Type:HKLM->RunOnce HijackThis Category: O4 HijackThis Line: O4 [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> rkgnd<br />
<strong>Filename:</strong> rkgnd.exe<br />
<strong>Command:</strong> C:\Program Files\Common Files\System\mgnc\rkgnd.exe<br />
<strong>Startup Type:</strong>HKLM->RunOnce<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\RunOnce: [39173992539183281] C:\Program Files\Common Files\System\mgnc\rkgnd.exe</p></blockquote>
<p><strong>Description:</strong> component of ANG AntiVirus 09</p>
<p><strong>How to remove:</strong> use these instructions <a href="http://www.myantispyware.com/2009/03/01/how-to-remove-ang-antivirus-09-delete-instructions/">How to remove ANG AntiVirus 09</a> or <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">use HijackThis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/rkgndexe-is-component-of-ang-antivirus-09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

