<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; startupreg</title>
	<atom:link href="http://htlogs.com/category/startup-type/startupreg/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Tue, 07 Sep 2010 14:14:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>winupdate.exe is a trojan</title>
		<link>http://htlogs.com/winupdate-exe-is-a-trojan/</link>
		<comments>http://htlogs.com/winupdate-exe-is-a-trojan/#comments</comments>
		<pubDate>Mon, 07 Sep 2009 12:43:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[startupreg]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=738</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: winupdate Filename: winupdate.exe Registry key: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdate.exe Command: C:\WINDOWS\system32\winupdate.exe Startup Type: startupreg Combofix/RSIT Line: [HKEY_LOCAL_MACHINE\software\microsoft\shared [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> winupdate<br />
<strong>Filename:</strong> winupdate.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdate.exe</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\winupdate.exe<br />
<strong>Startup Type:</strong> startupreg<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdate.exe]<br />
C:\WINDOWS\system32\winupdate.exe [2009-08-07 46080]<br />
2009-09-04 12:23:26 &#8212;-A&#8212;- C:\WINDOWS\system32\winupdate.exe</p></blockquote>
<p><strong>Description:</strong> Backdoor.Trojan also known as W32.Spybot.Worm, Backdoor.Win32.Rbot.</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/winupdate-exe-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sysmonnt &#8211; sysmonnt.exe is a spyware component</title>
		<link>http://htlogs.com/sysmonnt-sysmonntexe-is-a-spyware-component/</link>
		<comments>http://htlogs.com/sysmonnt-sysmonntexe-is-a-spyware-component/#comments</comments>
		<pubDate>Sun, 28 Jun 2009 03:46:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[startupreg]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=594</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: sysmonnt Filename: sysmonnt.exe Registry key: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysmonnt Command: C:\WINDOWS\System32\sysmonnt Startup Type: startupreg Combofix/RSIT Line: [HKEY_LOCAL_MACHINE\software\microsoft\shared [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> sysmonnt<br />
<strong>Filename:</strong> sysmonnt.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysmonnt</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\System32\sysmonnt<br />
<strong>Startup Type:</strong> startupreg<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysmonnt]<br />
C:\WINDOWS\System32\sysmonnt</p></blockquote>
<p><strong>Description:</strong> spyware component</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/sysmonnt-sysmonntexe-is-a-spyware-component/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>paumrt32.exe is a trojan</title>
		<link>http://htlogs.com/paumrt32exe-is-a-trojan/</link>
		<comments>http://htlogs.com/paumrt32exe-is-a-trojan/#comments</comments>
		<pubDate>Sun, 28 Jun 2009 03:37:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Trojan]]></category>
		<category><![CDATA[startupreg]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=590</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: paumrt32 Filename: paumrt32.exe Registry key: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ho29RhH5e CLSID: startupreg Startup Type: Combofix/RSIT Line: [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ho29RhH5e] [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> paumrt32<br />
<strong>Filename:</strong> paumrt32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ho29RhH5e</p></blockquote>
<p><strong>CLSID:</strong> startupreg<br />
<strong>Startup Type:</strong><br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ho29RhH5e]<br />
paumrt32.exe</p></blockquote>
<p><strong>Description:</strong> Unknown trojan</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/paumrt32exe-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
