<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; SvcHost</title>
	<atom:link href="http://htlogs.com/category/startup-type/svchost/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>fioo32 is trojan dropper</title>
		<link>http://htlogs.com/fioo32-is-trojan-dropper/</link>
		<comments>http://htlogs.com/fioo32-is-trojan-dropper/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 11:27:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SvcHost]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=829</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: fioo32 Startup Type: SvcHost Combofix/RSIT Line: R2 fioo32;fioo32; C:\Windows\sYSteM32\SvchOst.eXE [2008-01-19 21504] Description: trojan dropper that [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> fioo32<br />
<strong>Startup Type:</strong> SvcHost<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>R2 fioo32;fioo32; C:\Windows\sYSteM32\SvchOst.eXE [2008-01-19 21504]</p></blockquote>
<p><strong>Description:</strong> trojan dropper that installed by worm koobface</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/fioo32-is-trojan-dropper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DnsFilter.sys is a trojan (Trojan.DNSChanger)</title>
		<link>http://htlogs.com/dnsfilter-sys-is-a-trojan/</link>
		<comments>http://htlogs.com/dnsfilter-sys-is-a-trojan/#comments</comments>
		<pubDate>Sat, 29 Aug 2009 02:41:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[SvcHost]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=708</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: DnsFilter Filename: DnsFilter.sys Command: c:\windows\system32\drivers\DnsFilter.sys Startup Type: driver, svchost Combofix/RSIT Line: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] &#8220;8085:TCP&#8221;= 8085:TCP:ddnsfilter R2 [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> DnsFilter<br />
<strong>Filename:</strong> DnsFilter.sys<br />
<strong>Command:</strong> c:\windows\system32\drivers\DnsFilter.sys<br />
<strong>Startup Type:</strong> driver, svchost<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br />
&#8220;8085:TCP&#8221;= 8085:TCP:ddnsfilter<br />
R2 ddnsfilter;ddnsfilter;c:\windows\sySTEM32\SvchoSt.ExE -k ddnsfilter [7/16/2003 11:41 AM 14336]<br />
R1 DnsFilter;DnsFilter;c:\windows\system32\drivers\DnsFilter.sys [8/23/2009 8:43 AM 38016]<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br />
ddnsfilter REG_MULTI_SZ ddnsfilter</p></blockquote>
<p><strong>Description:</strong> trojan also known as Trojan.DNSChanger, Trojan.Dropper [Symantec], Trojan.Win32.Agent.cupu, [Kaspersky Lab], Trojan-Dropper [Ikarus]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a> + use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/ ">Kaspersky virus removal tool</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/dnsfilter-sys-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>drv.sys is worm Koobface</title>
		<link>http://htlogs.com/drvsys-is-worm-koobface/</link>
		<comments>http://htlogs.com/drvsys-is-worm-koobface/#comments</comments>
		<pubDate>Sat, 04 Jul 2009 14:37:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[SvcHost]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=608</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: drv Filename: drv.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DRV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\drv HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost &#124; drv Command: c:\program files\drv\drv.sys Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> drv<br />
<strong>Filename:</strong> drv.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DRV<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\drv<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost | drv</p></blockquote>
<p><strong>Command:</strong> c:\program files\drv\drv.sys<br />
<strong>Startup Type:</strong> driver, svchost<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>R1 drvdrv;drvdrv;c:\program files\drv\drv.sys [7/1/2009 2:55 PM 9344]<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br />
drv	REG_MULTI_SZ   	drv</p></blockquote>
<p><strong>Description:</strong> worm Koobface also known as Win32.Agent.auoy, Trojan-Dropper.Agent</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Antimalware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/drvsys-is-worm-koobface/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>msncache is a trojan component</title>
		<link>http://htlogs.com/msncache-is-a-trojan-component/</link>
		<comments>http://htlogs.com/msncache-is-a-trojan-component/#comments</comments>
		<pubDate>Sun, 28 Jun 2009 03:09:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Service]]></category>
		<category><![CDATA[SvcHost]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=578</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: msncache Startup Type: Service (svchost) Combofix/RSIT Line: R2 msncache;msncache; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336] Description: Unknown trojan [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> msncache<br />
<strong>Startup Type:</strong> Service (svchost)<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>R2 msncache;msncache; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]</p></blockquote>
<p><strong>Description:</strong> Unknown trojan component</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/msncache-is-a-trojan-component/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>podmena.sys is a Trojan.Downloader</title>
		<link>http://htlogs.com/podmenasys-is-a-trojandownloader/</link>
		<comments>http://htlogs.com/podmenasys-is-a-trojandownloader/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 02:37:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[SvcHost]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=551</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: podmena Filename: podmena.sys Command: c:\program files\podmena\podmena.sys Startup Type: driver R1 podmenadrv;podmenadrv;c:\program files\podmena\podmena.sys [6/8/2009 11:31 AM [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> podmena<br />
<strong>Filename:</strong> podmena.sys<br />
<strong>Command:</strong> c:\program files\podmena\podmena.sys<br />
<strong>Startup Type:</strong> driver</p>
<blockquote><p>R1 podmenadrv;podmenadrv;c:\program files\podmena\podmena.sys [6/8/2009 11:31 AM 9472]<br />
R2 podmena;podmena;c:\windows\system32\svchost.exe -k podmena [8/10/2004 14336]<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br />
podmena REG_MULTI_SZ podmena
</p></blockquote>
<p><strong>Description:</strong> Trojan.Downloader</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2009/06/12/remove-google-redirect-to-ix-findcom/">podmena.sys removal instructions</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/podmenasys-is-a-trojandownloader/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>wjfvju is a malware</title>
		<link>http://htlogs.com/wjfvju-is-a-malware/</link>
		<comments>http://htlogs.com/wjfvju-is-a-malware/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 12:51:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[SvcHost]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=143</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: wjfvju Startup Type:svchost Combofix/RSIT Line: R4 wjfvju;wjfvju;c:\windows\system32\SVCHOST.EXE -k wjfvju [2004-08-18 14336] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] wjfvju REG_MULTI_SZ [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> wjfvju<br />
<strong>Startup Type:</strong>svchost<br />
<strong>Combofix/RSIT Line:</strong></p>
<blockquote><p>R4 wjfvju;wjfvju;c:\windows\system32\SVCHOST.EXE -k wjfvju [2004-08-18 14336]<br />
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]<br />
wjfvju	REG_MULTI_SZ   	wjfvju</p></blockquote>
<p><strong>Description:</strong> unknown malware component</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/wjfvju-is-a-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

