<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; system.ini</title>
	<atom:link href="http://htlogs.com/category/startup-type/systemini/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is winlogon86.exe, How to remove winlogon86.exe</title>
		<link>http://htlogs.com/what-is-winlogon86-exe-how-to-remove-winlogon86-exe/</link>
		<comments>http://htlogs.com/what-is-winlogon86-exe-how-to-remove-winlogon86-exe/#comments</comments>
		<pubDate>Sat, 28 Nov 2009 17:49:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[system.ini]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1064</guid>
		<description><![CDATA[winlogon86.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: winlogon86 Filename: winlogon86.exe Command: C:\WINDOWS\system32\winlogon86.exe Startup Type: System.ini HijackThis Category: F2 HijackThis Line: F2 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>winlogon86.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> winlogon86<br />
<strong>Filename:</strong> winlogon86.exe<br />
<strong>Command:</strong> C:\WINDOWS\system32\winlogon86.exe<br />
<strong>Startup Type:</strong> System.ini<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe</p></blockquote>
<p><strong>Description:</strong> trojan  that installed with rogue antispyware program.</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-winlogon86-exe-how-to-remove-winlogon86-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is logon.exe, How to remove logon.exe</title>
		<link>http://htlogs.com/what-is-logon-exe-how-to-remove-logon-exe/</link>
		<comments>http://htlogs.com/what-is-logon-exe-how-to-remove-logon-exe/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 15:59:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[system.ini]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=960</guid>
		<description><![CDATA[logon.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: logon Filename: logon.exe Startup Type: system.ini HijackThis Category: F2 HijackThis Line: F2 &#8211; REG:system.ini: Shell=Explorer.exe [...]]]></description>
			<content:encoded><![CDATA[<h2>logon.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> logon<br />
<strong>Filename:</strong> logon.exe<br />
<strong>Startup Type:</strong> system.ini<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe logon.exe</p></blockquote>
<p><strong>Description:</strong> trojan that installed with a rogue antispyware program</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-logon-exe-how-to-remove-logon-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>twext.exe is trojan [Zbot.gen, Infostealer.Banker]</title>
		<link>http://htlogs.com/twextexe-is-trojan-zbotgen-infostealerbanker/</link>
		<comments>http://htlogs.com/twextexe-is-trojan-zbotgen-infostealerbanker/#comments</comments>
		<pubDate>Sat, 04 Jul 2009 13:15:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[system.ini]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=606</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: twext Filename: twext.exe Command: C:\WINDOWS\system32\twext.exe Startup Type: system.ini HijackThis Category: F2 HijackThis Line: F2 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> twext<br />
<strong>Filename:</strong> twext.exe<br />
<strong>Command:</strong> C:\WINDOWS\system32\twext.exe<br />
<strong>Startup Type:</strong> system.ini<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: UserInit=c:\windows\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,</p></blockquote>
<p><strong>Description:</strong> trojan Infostealer.Banker, also known as Zbot, PWS-Zbot.gen.c, Mal/EncPk-CZ</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Antimalware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/twextexe-is-trojan-zbotgen-infostealerbanker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>regsvr.exe is a trojan</title>
		<link>http://htlogs.com/regsvrexe-is-a-trojan/</link>
		<comments>http://htlogs.com/regsvrexe-is-a-trojan/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 14:29:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[system.ini]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=337</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: regsvr Filename: regsvr.exe Startup Type: system.ini HijackThis Category: F2 HijackThis Line: F2 &#8211; REG:system.ini: Shell=Explorer.exe [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> regsvr<br />
<strong>Filename:</strong> regsvr.exe<br />
<strong>Startup Type:</strong> system.ini<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe regsvr.exe </p></blockquote>
<p><strong>Description:</strong> regsvr.exe is a trojan</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Use Malwarebytes Antimalware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/regsvrexe-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

