<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Sound drivers</title>
	<atom:link href="http://htlogs.com/category/startup-type/sound-drivers/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>wdmaud.sys is a trojan/google redirect</title>
		<link>http://htlogs.com/wdmaudsys-is-a-trojangoogle-redirect/</link>
		<comments>http://htlogs.com/wdmaudsys-is-a-trojangoogle-redirect/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 16:24:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sound drivers]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=278</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: wdmaud Filename: wdmaud.sys Registry key: [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] &#8220;aux2&#8243;=&#8221;wdmaud.sys&#8221; Command: C:\Windows\system32\wdmaud.sys Startup Type: Sound drivers Description: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> wdmaud<br />
<strong>Filename:</strong> wdmaud.sys<br />
<strong>Registry key:</strong> </p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br />
&#8220;aux2&#8243;=&#8221;wdmaud.sys&#8221;</p></blockquote>
<p><strong>Command:</strong> C:\Windows\system32\wdmaud.sys<br />
<strong>Startup Type:</strong> Sound drivers<br />
<strong>Description:</strong> C:\Windows\system32\wdmaud.sys is a trojan/Google redirect also known as Rootkit.Win32.Agent.fwt. The legitimate wdmaud.sys actually exists at C:\Windows\system32\drivers\</p>
<p><strong>How to remove:</strong> use the instructions <a href="http://www.myantispyware.com/2009/02/19/how-to-remove-google-searches-redirect-via-7770-remove-rootkitwin32agentfwt/">How to remove Google searches redirect virus 7.7.7.0 (remove Rootkit.Win32.Agent.fwt)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/wdmaudsys-is-a-trojangoogle-redirect/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

