<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; ShellServiceObjectDelayLoad</title>
	<atom:link href="http://htlogs.com/category/startup-type/shellserviceobjectdelayload/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is overlapp32.dll, How to remove overlapp32.dll</title>
		<link>http://htlogs.com/what-is-overlapp32-dll-how-to-remove-overlapp32-dll/</link>
		<comments>http://htlogs.com/what-is-overlapp32-dll-how-to-remove-overlapp32-dll/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 19:21:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1507</guid>
		<description><![CDATA[overlapp32.dll is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: overlapp32 Filename: overlapp32.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; WebCheck Command: %Windir%\System32\overlapp32.dll CLSID: {FF4EC53A-CA51-9A39-6CDD-5FFB26FB445C} Startup Type: ShellServiceObjectDelayLoad [...]]]></description>
			<content:encoded><![CDATA[<h2>overlapp32.dll is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> overlapp32<br />
<strong>Filename:</strong> overlapp32.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck</p></blockquote>
<p><strong>Command:</strong> %Windir%\System32\overlapp32.dll<br />
<strong>CLSID:</strong> {FF4EC53A-CA51-9A39-6CDD-5FFB26FB445C}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O21 &#8211; SSODL: WebCheck &#8211; {FF4EC53A-CA51-9A39-6CDD-5FFB26FB445C} &#8211; overlapp32.dll</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>SSODL: WebCheck &#8211; {FF4EC53A-CA51-9A39-6CDD-5FFB26FB445C} &#8211; overlapp32.dll</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
WebCheck &#8211; {FF4EC53A-CA51-9A39-6CDD-5FFB26FB445C} &#8211; overlapp32.dll </p></blockquote>
<p><strong>Description:</strong> trojan also known as Trojan-PSW.Generic [PCTools], Infostealer [Symantec], Downloader-BZS [McAfee], Trojan.KeyLogger.4260 [DrWEB], Win32:Malware-gen [AVAST]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> +<a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-overlapp32-dll-how-to-remove-overlapp32-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is inetprovider.dll, How to remove inetprovider.dll</title>
		<link>http://htlogs.com/what-is-inetprovider-dll-how-to-remove-inetprovider-dll/</link>
		<comments>http://htlogs.com/what-is-inetprovider-dll-how-to-remove-inetprovider-dll/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 15:56:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1094</guid>
		<description><![CDATA[inetprovider.dll is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: inetprovider Filename: inetprovider.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; InternetProvider Command: C:\Documents and Settings\All Users\Microsoft PData\inetprovider.dll CLSID: [...]]]></description>
			<content:encoded><![CDATA[<h2>inetprovider.dll is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> inetprovider<br />
<strong>Filename:</strong> inetprovider.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | InternetProvider</p></blockquote>
<p><strong>Command:</strong> C:\Documents and Settings\All Users\Microsoft PData\inetprovider.dll<br />
<strong>CLSID:</strong> {76377D16-FC8D-4505-B8E1-237EA19C401A}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O21 &#8211; SSODL: InternetProvider &#8211; {76377D16-FC8D-4505-B8E1-237EA19C401A} &#8211; C:\Documents and Settings\All Users\Microsoft PData\inetprovider.dll</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>SSODL: InternetProvider &#8211; {76377D16-FC8D-4505-B8E1-237EA19C401A} &#8211; C:\Documents and Settings\All Users\Microsoft PData\inetprovider.dll</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
InternetProvider &#8211; {76377D16-FC8D-4505-B8E1-237EA19C401A} &#8211; C:\Documents and Settings\All Users\Microsoft PData\inetprovider.dll</p></blockquote>
<p><strong>Description:</strong> trojan that installed with Personal Protector. <a href="http://progssecurityblog.blogspot.com/2009/11/personal-protector-is-rogue-antispyware.html">Personal Protector</a> is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + these <a href="http://www.myantispyware.com/2009/11/17/how-to-remove-personal-protector-uninstall-instructions/">Personal Protector removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-inetprovider-dll-how-to-remove-inetprovider-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is swupdate.dll, How to remove swupdate.dll</title>
		<link>http://htlogs.com/what-is-swupdate-dll-how-to-remove-swupdate-dll/</link>
		<comments>http://htlogs.com/what-is-swupdate-dll-how-to-remove-swupdate-dll/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 15:44:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1092</guid>
		<description><![CDATA[swupdate.dll is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: swupdate Filename: swupdate.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; SwUpdate Command: C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll CLSID: [...]]]></description>
			<content:encoded><![CDATA[<h2>swupdate.dll is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> swupdate<br />
<strong>Filename:</strong> swupdate.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | SwUpdate</p></blockquote>
<p><strong>Command:</strong> C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll<br />
<strong>CLSID:</strong> {009541A0-3B00-1F1C-00F3-040224001C01}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O21 &#8211; SSODL: SwUpdate &#8211; {009541A0-3B00-1F1C-00F3-040224001C01} &#8211; C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>SSODL: SwUpdate &#8211; {009541A0-3B00-1F1C-00F3-040224001C01} &#8211; C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll</p></blockquote>
<p><strong>RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
SwUpdate &#8211; {009541A0-3B00-1F1C-00F3-040224001C01} &#8211; C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll</p></blockquote>
<p><strong>Description:</strong> trojan AdClick</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-swupdate-dll-how-to-remove-swupdate-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is sysnet.dll, How to remove sysnet.dll</title>
		<link>http://htlogs.com/what-is-sysnet-dll-how-to-remove-sysnet-dll/</link>
		<comments>http://htlogs.com/what-is-sysnet-dll-how-to-remove-sysnet-dll/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 15:55:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=958</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: sysnet Filename: sysnet.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; SysNet Command: C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll CLSID: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> sysnet<br />
<strong>Filename:</strong> sysnet.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | SysNet</p></blockquote>
<p><strong>Command:</strong> C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll<br />
<strong>CLSID:</strong> {13E9115E-2CB0-4CAB-91D0-507E9368ED1B}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O21 &#8211; SSODL: SysNet &#8211; {13E9115E-2CB0-4CAB-91D0-507E9368ED1B} &#8211; C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll</p></blockquote>
<p><strong>RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
SysNet &#8211; {13E9115E-2CB0-4CAB-91D0-507E9368ED1B} &#8211; C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll </p></blockquote>
<p><strong>Description:</strong> trojan agent that installed with a rogue antispyware program</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> +  <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-sysnet-dll-how-to-remove-sysnet-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is mstmdm.dll, How to remove mstmdm.dll</title>
		<link>http://htlogs.com/what-is-mstmdm-dll-how-to-remove-mstmdm-dll/</link>
		<comments>http://htlogs.com/what-is-mstmdm-dll-how-to-remove-mstmdm-dll/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 04:29:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=914</guid>
		<description><![CDATA[mstmdm.dll is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: mstmdm Filename: mstmdm.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; UpdateCheck Command: C:\WINDOWS\system32\mstmdm.dll CLSID: {3D232827-DCDB-455D-9B12-8F8C7DE41935} Startup Type: ShellServiceObjectDelayLoad [...]]]></description>
			<content:encoded><![CDATA[<h2>mstmdm.dll is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> mstmdm<br />
<strong>Filename:</strong> mstmdm.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | UpdateCheck</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\mstmdm.dll<br />
<strong>CLSID:</strong> {3D232827-DCDB-455D-9B12-8F8C7DE41935}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O21 &#8211; SSODL: UpdateCheck &#8211; {3D232827-DCDB-455D-9B12-8F8C7DE41935} &#8211; C:\WINDOWS\system32\mstmdm.dll</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
UpdateCheck &#8211; {3D232827-DCDB-455D-9B12-8F8C7DE41935} &#8211; C:\WINDOWS\system32\mstmdm.dll</p></blockquote>
<p><strong>Description:</strong> a trojans also known as Trojan.Win32.Agent.bve</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-mstmdm-dll-how-to-remove-mstmdm-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>gitabiga.dll is trojan Vundo</title>
		<link>http://htlogs.com/gitabiga-dll-is-trojan-vundo/</link>
		<comments>http://htlogs.com/gitabiga-dll-is-trojan-vundo/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 04:34:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[O22]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[SharedTaskScheduler]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=778</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: gitabiga Filename: gitabiga.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run &#124; derijidob hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler &#124; {e826441e-0920-4e05-9b2c-84189ccd7cba} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; gefiraled Command: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> gitabiga<br />
<strong>Filename:</strong> gitabiga.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | derijidob<br />
hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler | {e826441e-0920-4e05-9b2c-84189ccd7cba}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | gefiraled</p></blockquote>
<p><strong>Command:</strong> c:\windows\system32\gitabiga.dll<br />
<strong>CLSID:</strong> {e826441e-0920-4e05-9b2c-84189ccd7cba}<br />
<strong>Startup Type:</strong> HKLM->Run, SharedTaskScheduler, ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4, O21, O22<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>2009-09-19 01:46 . 2009-06-19 01:46 88576 &#8211;sha-w- c:\windows\system32\gitabiga.dll<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;derijidob&#8221;=&#8221;c:\windows\system32\gitabiga.dll&#8221; [2009-09-19 88576]<br />
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]<br />
&#8220;{e826441e-0920-4e05-9b2c-84189ccd7cba}&#8221;= &#8220;c:\windows\system32\gitabiga.dll&#8221; [2009-09-19 88576]<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
&#8220;gefiraled&#8221;= {e826441e-0920-4e05-9b2c-84189ccd7cba} &#8211; c:\windows\system32\gitabiga.dll [2009-09-19 88576]</p></blockquote>
<p><strong>Description:</strong> trojan Vundo</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/gitabiga-dll-is-trojan-vundo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>wm0dap.dll is a Email-Worm.Win32.Bagle</title>
		<link>http://htlogs.com/wm0dapdll-is-a-email-wormwin32bagle/</link>
		<comments>http://htlogs.com/wm0dapdll-is-a-email-wormwin32bagle/#comments</comments>
		<pubDate>Sun, 31 May 2009 08:39:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=514</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: wm0dap Filename: wm0dap.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; oledll Command: C:\WINDOWS\system32\wm0dap.dll CLSID: {52345B67-1234-1234-D123-7F84D123BC7D} Startup Type: ShellServiceObjectDelayLoad [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> wm0dap<br />
<strong>Filename:</strong> wm0dap.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | oledll</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\wm0dap.dll<br />
<strong>CLSID:</strong> {52345B67-1234-1234-D123-7F84D123BC7D}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad</p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
oledll &#8211; {52345B67-1234-1234-D123-7F84D123BC7D} &#8211; C:\WINDOWS.0\system32\wm0dap.dll [2009-03-21 73728]</p></blockquote>
<p><strong>Description:</strong> Email-Worm.Bagle is a mass-mailing application.</p>
<p><strong>How to remove:</strong> manually, using Combofix or Registry editor</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/wm0dapdll-is-a-email-wormwin32bagle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eewhptdpyl.dll is a component of System Guard 2009</title>
		<link>http://htlogs.com/eewhptdpyldll-is-a-component-of-system-guard-2009/</link>
		<comments>http://htlogs.com/eewhptdpyldll-is-a-component-of-system-guard-2009/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 10:33:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=399</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: eewhptdpyl Filename: eewhptdpyl.dll Registry key: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] &#124; InternetConnection Command: C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll CLSID: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> eewhptdpyl<br />
<strong>Filename:</strong> eewhptdpyl.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]<br />
 | InternetConnection</p></blockquote>
<p><strong>Command:</strong> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll<br />
<strong>CLSID:</strong> {AB6DAA8C-F726-4FDD-8B06-9537C5878612}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p> O21 &#8211; SSODL: InternetConnection &#8211; {AB6DAA8C-F726-4FDD-8B06-9537C5878612} &#8211; C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll</p></blockquote>
<p><strong>Description:</strong> component of System Guard 2009</p>
<p><strong>How to remove:</strong> use these instructions <a href="http://www.myantispyware.com/2009/01/26/how-to-remove-system-guard-2009-delete-instructions/">How to remove System Guard 2009 (Delete instructions)</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/eewhptdpyldll-is-a-component-of-system-guard-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>bwpbwvxxvw.dll is a trojan, component of rogue antispyware</title>
		<link>http://htlogs.com/bwpbwvxxvwdll-is-a-trojan-component-of-rogue-antispyware/</link>
		<comments>http://htlogs.com/bwpbwvxxvwdll-is-a-trojan-component-of-rogue-antispyware/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 16:26:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=367</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: bwpbwvxxvw Filename: bwpbwvxxvw.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; InternetConnection Command: C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\bwpbwvxxvw.dll CLSID: {D14F8945-CF96-4231-9FA7-4BC630D80D85} Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> bwpbwvxxvw<br />
<strong>Filename:</strong> bwpbwvxxvw.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | InternetConnection</p></blockquote>
<p><strong>Command:</strong> C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\bwpbwvxxvw.dll<br />
<strong>CLSID:</strong> {D14F8945-CF96-4231-9FA7-4BC630D80D85}<br />
<strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O21 &#8211; SSODL: InternetConnection &#8211; {D14F8945-CF96-4231-9FA7-4BC630D80D85} &#8211; C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\bwpbwvxxvw.dll</p></blockquote>
<p><strong>Description:</strong> trojan, component of rogue antispyware</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Use Malwarebytes Antimalware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/bwpbwvxxvwdll-is-a-trojan-component-of-rogue-antispyware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ieModule.dll is a trojan, component of rogue antispyware</title>
		<link>http://htlogs.com/iemoduledll-is-a-trojan-component-of-rogue-antispyware/</link>
		<comments>http://htlogs.com/iemoduledll-is-a-trojan-component-of-rogue-antispyware/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 16:22:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O21]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[ShellServiceObjectDelayLoad]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=365</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ieModule Filename: ieModule.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad &#124; ieModule Command: C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll CLSID: {92CA440D-C81C-4B72-89D0-D2B464E5678B} {77C96E10-FDA7-4AA7-B318-0631C0D27DBB} [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ieModule<br />
<strong>Filename:</strong> ieModule.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | ieModule</p></blockquote>
<p><strong>Command:</strong> C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll<br />
<strong>CLSID:</strong> </p>
<blockquote><p>{92CA440D-C81C-4B72-89D0-D2B464E5678B}<br />
{77C96E10-FDA7-4AA7-B318-0631C0D27DBB}</p></blockquote>
<p><strong>Startup Type:</strong> ShellServiceObjectDelayLoad<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O21<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O21 &#8211; SSODL: ieModule &#8211; {92CA440D-C81C-4B72-89D0-D2B464E5678B} &#8211; C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll</p></blockquote>
<p><strong>Description:</strong> trojan, component of a few rogue antispyware programs</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Use Malwarebytes Antimalware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/iemoduledll-is-a-trojan-component-of-rogue-antispyware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

