<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; RunServices</title>
	<atom:link href="http://htlogs.com/category/startup-type/runservices/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is winIogon.exe, How to remove winIogon.exe</title>
		<link>http://htlogs.com/what-is-winiogon-exe-how-to-remove-winiogon-exe/</link>
		<comments>http://htlogs.com/what-is-winiogon-exe-how-to-remove-winiogon-exe/#comments</comments>
		<pubDate>Sun, 17 Jan 2010 18:22:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[RunServices]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1331</guid>
		<description><![CDATA[winIogon.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: winIogon Filename: winIogon.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; Microsoft System Service HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices &#124; Microsoft System Service [...]]]></description>
			<content:encoded><![CDATA[<h2>winIogon.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> winIogon<br />
<strong>Filename:</strong> winIogon.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Microsoft System Service<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices | Microsoft System Service<br />
HKEY_CURRENT_USER\Software\Microsoft\OLE | Microsoft System Service</p></blockquote>
<p><strong>Command:</strong> C:\Windows\System32\winIogon.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [Microsoft System Service] winIogon.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [Microsoft System Service] winIogon.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Microsoft System Service&#8221;=winIogon.exe</p></blockquote>
<p><strong>Description:</strong> trojan also known as W32/Virut.gen.a [McAfee], Backdoor:Win32/Poebot.gen [Microsoft], W32.IRCBot [Symantec], PE_VIRUT.AV [Trend Micro], W32.Virut.W [Symantec]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-winiogon-exe-how-to-remove-winiogon-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>lockx.exe is a W32/Sdbot-ADD worm</title>
		<link>http://htlogs.com/lockxexe-is-a-w32sdbot-add-worm/</link>
		<comments>http://htlogs.com/lockxexe-is-a-w32sdbot-add-worm/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 04:24:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[RunServices]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=162</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: lockx Filename: lockx.exe Command: %windir%\system32\lockx.exe Startup Type: HKLM->RunServices, HKCU->Run HijackThis Category: O4 HijackThis Line: O4 [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> lockx<br />
<strong>Filename:</strong> lockx.exe<br />
<strong>Command:</strong> %windir%\system32\lockx.exe<br />
<strong>Startup Type:</strong> HKLM->RunServices, HKCU->Run<br />
<strong>HijackThis Category:</strong> O4<br />
<strong>HijackThis Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\RunServices: [strtas] lockx.exe<br />
O4 &#8211; HKCU\..\Run: [strtas] lockx.exe</p></blockquote>
<p><strong>Description:</strong> W32/Sdbot-ADD worm</p>
<p><strong>How to remove:</strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/"> Use HijackThis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/lockxexe-is-a-w32sdbot-add-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

