<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; SafeBoot</title>
	<atom:link href="http://htlogs.com/category/startup-type/safeboot/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Fri, 10 Sep 2010 15:36:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>ati3xmxx.sys is a trojan</title>
		<link>http://htlogs.com/ati3xmxxsys-is-a-trojan/</link>
		<comments>http://htlogs.com/ati3xmxxsys-is-a-trojan/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 02:20:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SafeBoot]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=543</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ati3xmxx Filename: ati3xmxx.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3xmxx.sys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati3xmxx.sys Startup Type: SafeBoot Combofix/RSIT Line: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3xmxx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati3xmxx.sys] Description: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ati3xmxx<br />
<strong>Filename:</strong> ati3xmxx.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3xmxx.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati3xmxx.sys</p></blockquote>
<p><strong>Startup Type:</strong> SafeBoot<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3xmxx.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati3xmxx.sys]</p></blockquote>
<p><strong>Description:</strong> unknown trojan</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/ati3xmxxsys-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WinXX00.sys is a trojan</title>
		<link>http://htlogs.com/winxx00sys-is-a-trojan/</link>
		<comments>http://htlogs.com/winxx00sys-is-a-trojan/#comments</comments>
		<pubDate>Sun, 31 May 2009 08:21:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[SafeBoot]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=506</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: WinXX00 Filename: WinXX00.sys Command: %windir%\System32\drivers\Winsa06.sys Startup Type: Driver Combofix/RSIT Line: Registry section: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winag75.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winah28.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winah30.sys] [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> WinXX00<br />
<strong>Filename:</strong> WinXX00.sys<br />
<strong>Command:</strong> %windir%\System32\drivers\Winsa06.sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>Registry section:<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winag75.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winah28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winah30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winah63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winbi63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winbi85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winci06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winci31.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winci63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wincj06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wincj17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wincj30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wincj41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winck06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windj30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windj52.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windk17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windk63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winek86.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winel52.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winfl53.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winhn20.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winho63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winip30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winip41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winjq63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkq18.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkq28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkr30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkr74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winlr85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winls17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winms41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winnu74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winov85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winpv63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winpw06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winqw07.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winqx06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winqx85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winrx18.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winrx30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winrx41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winry63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winry85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winsa06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winsa74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winsy17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winsy74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winta30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wintb06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wintb28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winub74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winub85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winuc74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwd17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwe06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwf28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winxe06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winxe52.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winyg63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winyh28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winyh85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winag75.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winah28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winah30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winah63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winbi63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winbi85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winci06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winci31.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winci63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wincj06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wincj17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wincj30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wincj41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winck06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Windj30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Windj52.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Windk17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Windk63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winek86.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winel52.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winfl53.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winhn20.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winho63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winip30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winip41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winjq63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winkq18.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winkq28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winkr30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winkr74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winlr85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winls17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winms41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winnu74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winov85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winpv63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winpw06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winqw07.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winqx06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winqx85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winrx18.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winrx30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winrx41.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winry63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winry85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winsa06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winsa74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winsy17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winsy74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winta30.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wintb06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wintb28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winub74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winub85.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winuc74.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winwd17.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winwe06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winwf28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winxe06.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winxe52.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winyg63.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winyh28.sys]<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winyh85.sys]</p>
<p>Drivers section:<br />
S3 Winag75;Winag75; \??\C:\WINDOWS\System32\drivers\Winag75.sys []<br />
S3 Winah63;Winah63; \??\C:\WINDOWS\System32\drivers\Winah63.sys []<br />
S3 Winjq63;Winjq63; \??\C:\WINDOWS\System32\drivers\Winjq63.sys []<br />
S3 Winov85;Winov85; \??\C:\WINDOWS\System32\drivers\Winov85.sys []<br />
S3 Winrx41;Winrx41; \??\C:\WINDOWS\System32\drivers\Winrx41.sys []<br />
S3 Winsa06;Winsa06; \??\C:\WINDOWS\System32\drivers\Winsa06.sys []<br />
S3 Winuc74;Winuc74; \??\C:\WINDOWS\System32\drivers\Winuc74.sys []<br />
S3 Winwd17;Winwd17; \??\C:\WINDOWS\System32\drivers\Winwd17.sys []</p></blockquote>
<p><strong>Description:</strong> trojan downloader, uses random names for hide itself. Name pattern: WinXX00.sys, where XX &#8211; two chars, 00 &#8211; two digits.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/winxx00sys-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>java2.sys is a trojan</title>
		<link>http://htlogs.com/java2sys-is-a-trojan/</link>
		<comments>http://htlogs.com/java2sys-is-a-trojan/#comments</comments>
		<pubDate>Mon, 02 Feb 2009 12:26:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SafeBoot]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=111</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: java2 Filename: java2.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\java2.sys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\java2.sys Command: C:\Windows\System32\java2.sys Startup Type: SafeBoot registry key Description: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> java2<br />
<strong>Filename:</strong> java2.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\java2.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\java2.sys</p></blockquote>
<p><strong>Command:</strong> C:\Windows\System32\java2.sys<br />
<strong>Startup Type:</strong> SafeBoot registry key<br />
<strong>Description:</strong> Backdoor:Win32/Haxdoor [Microsoft], Trojan-Spy.Win32.Goldun [Ikarus]</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/java2sys-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sws05.sys</title>
		<link>http://htlogs.com/sws05sys/</link>
		<comments>http://htlogs.com/sws05sys/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 04:31:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SafeBoot]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=23</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: Sws05 Filename: Sws05.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sws05.sys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Sws05.sys Description: trojan component]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> Sws05<br />
<strong>Filename:</strong> Sws05.sys<br />
<strong>Registry key:</strong> </p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sws05.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Sws05.sys
</p></blockquote>
<p><strong>Description:</strong> trojan component</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/sws05sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
