<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Winlogon\Shell</title>
	<atom:link href="http://htlogs.com/category/startup-type/winlogonshell/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is palladium.exe, How to remove palladium.exe</title>
		<link>http://htlogs.com/what-is-palladium-exe-how-to-remove-palladium-exe/</link>
		<comments>http://htlogs.com/what-is-palladium-exe-how-to-remove-palladium-exe/#comments</comments>
		<pubDate>Tue, 04 Jan 2011 15:38:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2103</guid>
		<description><![CDATA[palladium.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: palladium Filename: palladium.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; “Shell” = “%AppData%\palladium.exe” Command: %AppData%\palladium.exe Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>palladium.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> palladium<br />
<strong>Filename:</strong> palladium.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | “Shell” = “%AppData%\palladium.exe”</p></blockquote>
<p><strong>Command:</strong> %AppData%\palladium.exe<br />
<strong>Startup Type:</strong> HKCU->Winlogon->Shell<br />
<strong>Description:</strong> core component of Palladium Pro. Palladium Pro is a fake security program (rogue antispyware).</p>
<p><strong>How to remove:</strong> use the fake <a href="http://www.myantispyware.com/2011/01/04/how-to-remove-palladium-pro-virus-uninstall-instructions/">Palladium Pro removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-palladium-exe-how-to-remove-palladium-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is hotfix.exe, How to remove hotfix.exe</title>
		<link>http://htlogs.com/what-is-hotfix-exe-how-to-remove-hotfix-exe/</link>
		<comments>http://htlogs.com/what-is-hotfix-exe-how-to-remove-hotfix-exe/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 06:00:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1979</guid>
		<description><![CDATA[hotfix.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: hotfix Filename: hotfix.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; “Shell” = “%UserProfile%\Application Data\hotfix.exe” Command: %AppData%\hotfix.exe Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>hotfix.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> hotfix<br />
<strong>Filename:</strong> hotfix.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | “Shell” = “%UserProfile%\Application Data\hotfix.exe”</p></blockquote>
<p><strong>Command:</strong> %AppData%\hotfix.exe<br />
<strong>Startup Type:</strong> HKCU->Winlogon->Shell<br />
<strong>Description:</strong> core component of Microsoft Security Essentials FakeAlert trojan</p>
<p><strong>How to remove:</strong> use the fake <a href="http://www.myantispyware.com/2010/08/26/how-to-remove-fake-microsoft-security-essentials-alert/">Microsoft Security Essentials Alert removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-hotfix-exe-how-to-remove-hotfix-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ntload.exe, How to remove ntload.exe</title>
		<link>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/</link>
		<comments>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 14:56:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1925</guid>
		<description><![CDATA[ntload.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ntload Filename: ntload.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run &#124; rundll32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: %Windir%\system32\ntload.exe Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>ntload.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ntload<br />
<strong>Filename:</strong> ntload.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | rundll32<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> %Windir%\system32\ntload.exe<br />
<strong>Startup Type:</strong> Winlogon->Shell, HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2, O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\ntload.exe<br />
O4 – HKLM\..\Run: [rundll32] C:\WINDOWS\system32\ntload.exe</p></blockquote>
<p><strong>Description:</strong> component of Advanced Security Tool 2010 (rogue antispyware)</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/27/how-to-remove-advanced-security-tool-2010-uninstall-instructions/">Advanced Security Tool 2010 removal</a> guide or or the steps below.</p>
<p>1. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop. Most important, in the Save dialog, rename HijackThis.exe to iexplore.exe !!!<br />
2. Run HijackThis. Main menu opens. Click to “Do a system scan only” button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>F2 – REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\ntload.exe<br />
O4 – HKLM\..\Run: [rundll32] C:\WINDOWS\system32\ntload.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.<br />
3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ntload-exe-how-to-remove-ntload-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is AVDefender 2011, How to remove AVDefender 2011</title>
		<link>http://htlogs.com/what-is-avdefender-2011-how-to-remove-avdefender-2011/</link>
		<comments>http://htlogs.com/what-is-avdefender-2011-how-to-remove-avdefender-2011/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 05:37:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1922</guid>
		<description><![CDATA[AVDefender 2011 is a malicious program. It is a malware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Filename: {RANDOM}.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell = “%AppData%\{RANDOM}\{RANDOM}.exe” Command: %AppData%\{RANDOM}\{RANDOM}.exe Startup Type: Winlogon->Shell Description: rogue antivirus program [...]]]></description>
			<content:encoded><![CDATA[<h2>AVDefender 2011 is a malicious program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a malware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Filename:</strong> {RANDOM}.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell = “%AppData%\{RANDOM}\{RANDOM}.exe”</p></blockquote>
<p><strong>Command:</strong> %AppData%\{RANDOM}\{RANDOM}.exe<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong>Description:</strong> rogue antivirus program</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/26/how-to-remove-avdefender-2011-uninstall-instructions/">AVDefender 2011 removal</a> instructions</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-avdefender-2011-how-to-remove-avdefender-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is antispy.exe, How to remove antispy.exe</title>
		<link>http://htlogs.com/what-is-antispy-exe-how-to-remove-antispy-exe/</link>
		<comments>http://htlogs.com/what-is-antispy-exe-how-to-remove-antispy-exe/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 18:36:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1920</guid>
		<description><![CDATA[antispy.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: antispy Filename: antispy.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shel” Command: %UserProfile%\Application Data\antispy.exe Startup Type: HKCU->Winlogon->Shell [...]]]></description>
			<content:encoded><![CDATA[<h2>antispy.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> antispy<br />
<strong>Filename:</strong> antispy.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shel”</p></blockquote>
<p><strong>Command:</strong> %UserProfile%\Application Data\antispy.exe<br />
<strong>Startup Type:</strong> HKCU->Winlogon->Shell<br />
<strong>Description:</strong> core component of one of Red Cross Antivirus, Peak Protection 2010, Pest Detector 4.1, Major Defense Kit, AntiSpySafeguard (rogue antivirus programs). It is installed by Microsoft Security Essentials Alert trojan.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/26/how-to-remove-fake-microsoft-security-essentials-alert/">Microsoft Security Essentials Alert trojan removal</a> instructions</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-antispy-exe-how-to-remove-antispy-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is srnh.lto, How to remove srnh.lto</title>
		<link>http://htlogs.com/what-is-srnh-lto-how-to-remove-srnh-lto/</link>
		<comments>http://htlogs.com/what-is-srnh-lto-how-to-remove-srnh-lto/#comments</comments>
		<pubDate>Wed, 19 May 2010 13:19:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1720</guid>
		<description><![CDATA[srnh.lto is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: srnh Filename: srnh.lto Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe srnh.lto iqfnr CLSID: [...]]]></description>
			<content:encoded><![CDATA[<h2>srnh.lto is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> srnh<br />
<strong>Filename:</strong> srnh.lto<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe srnh.lto iqfnr<br />
<strong>CLSID:</strong> clsid<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe rundll32.exe srnh.lto iqfnr</p></blockquote>
<p><strong>Description:</strong> component of Win32/Oficla trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-srnh-lto-how-to-remove-srnh-lto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is hspe.uvo, How to remove hspe.uvo</title>
		<link>http://htlogs.com/what-is-hspe-uvo-how-to-remove-hspe-uvo/</link>
		<comments>http://htlogs.com/what-is-hspe-uvo-how-to-remove-hspe-uvo/#comments</comments>
		<pubDate>Wed, 21 Apr 2010 17:11:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1652</guid>
		<description><![CDATA[hspe.uvo is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: hspe Filename: hspe.uvo Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe, rundll32.exe hspe.uvo bnjpid Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>hspe.uvo is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> hspe<br />
<strong>Filename:</strong> hspe.uvo<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe, rundll32.exe hspe.uvo bnjpid<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe, rundll32.exe hspe.uvo bnjpid</p></blockquote>
<p><strong>Description:</strong> component of a trojan that also known as Backdoor.Bredolab [PCTools], Mal/EncPk-NS, Mal/FakeAV-BW, Mal/FakeAV-DF, Mal/FakeAV-BW [Sophos], packed with: PE_Patch.UPX [Kaspersky Lab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-hspe-uvo-how-to-remove-hspe-uvo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is awxm.vho, How to remove awxm.vho</title>
		<link>http://htlogs.com/what-is-awxm-vho-how-to-remove-awxm-vho/</link>
		<comments>http://htlogs.com/what-is-awxm-vho-how-to-remove-awxm-vho/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 14:20:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1643</guid>
		<description><![CDATA[awxm.vho is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: awxm Filename: awxm.vho Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe awxm.vho rlvgf Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>awxm.vho is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> awxm<br />
<strong>Filename:</strong> awxm.vho<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe awxm.vho rlvgf<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe rundll32.exe awxm.vho rlvgf</p></blockquote>
<p><strong>Description:</strong> component of a trojan that also known as Backdoor.Bredolab [PCTools], Mal/EncPk-NS, Mal/FakeAV-BW, Mal/FakeAV-DF, Mal/FakeAV-BW [Sophos], packed with: PE_Patch.UPX [Kaspersky Lab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-awxm-vho-how-to-remove-awxm-vho/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ngts.vao, How to remove ngts.vao</title>
		<link>http://htlogs.com/what-is-ngts-vao-how-to-remove-ngts-vao/</link>
		<comments>http://htlogs.com/what-is-ngts-vao-how-to-remove-ngts-vao/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 08:39:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1634</guid>
		<description><![CDATA[ngts.vao is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ngts Filename: ngts.vao Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe rundll32.exe ngts.vao uvibls Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>ngts.vao is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ngts<br />
<strong>Filename:</strong> ngts.vao<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe rundll32.exe ngts.vao uvibls<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe rundll32.exe ngts.vao uvibls</p></blockquote>
<p><strong>Description:</strong> component of a trojan that also known as Backdoor.Bredolab [PCTools], Mal/EncPk-NS, Mal/FakeAV-BW, Mal/FakeAV-DF, Mal/FakeAV-BW [Sophos], packed with: PE_Patch.UPX [Kaspersky Lab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> +  <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ngts-vao-how-to-remove-ngts-vao/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is rihd.pno, How to remove rihd.pno</title>
		<link>http://htlogs.com/what-is-rihd-pno-how-to-remove-rihd-pno/</link>
		<comments>http://htlogs.com/what-is-rihd-pno-how-to-remove-rihd-pno/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 18:08:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Shell]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1628</guid>
		<description><![CDATA[rihd.pno is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: rihd Filename: rihd.pno Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Shell Command: Explorer.exe, rundll32.exe rihd.pno eaoydsi Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>rihd.pno is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> rihd<br />
<strong>Filename:</strong> rihd.pno<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell</p></blockquote>
<p><strong>Command:</strong> Explorer.exe, rundll32.exe rihd.pno eaoydsi<br />
<strong>Startup Type:</strong> Winlogon->Shell<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: Shell=Explorer.exe, rundll32.exe rihd.pno eaoydsi</p></blockquote>
<p><strong>Description:</strong> component of Bredolab trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-rihd-pno-how-to-remove-rihd-pno/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

