<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Winlogon\UserInit</title>
	<atom:link href="http://htlogs.com/category/startup-type/winlogonuserinit/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is desktoplayer.exe, How to remove desktoplayer.exe</title>
		<link>http://htlogs.com/what-is-desktoplayer-exe-how-to-remove-desktoplayer-exe/</link>
		<comments>http://htlogs.com/what-is-desktoplayer-exe-how-to-remove-desktoplayer-exe/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 16:05:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\UserInit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2020</guid>
		<description><![CDATA[desktoplayer.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: desktoplayer Filename: desktoplayer.exe Registry key: HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon &#124; Userinit Command: c:\program files\microsoft\desktoplayer.exe Startup Type: HKLM->Winlogon->Userinit [...]]]></description>
			<content:encoded><![CDATA[<h2>desktoplayer.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> desktoplayer<br />
<strong>Filename:</strong> desktoplayer.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon  | Userinit</p></blockquote>
<p><strong>Command:</strong> c:\program files\microsoft\desktoplayer.exe<br />
<strong>Startup Type:</strong> HKLM->Winlogon->Userinit<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: UserInit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]<br />
&#8220;Userinit&#8221;=&#8221;c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe&#8221;</p></blockquote>
<p><strong>Description:</strong> component of Win32.ramnit trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-desktoplayer-exe-how-to-remove-desktoplayer-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Antispyware.exe, How to remove Antispyware.exe</title>
		<link>http://htlogs.com/what-is-antispyware-exe-how-to-remove-antispyware-exe/</link>
		<comments>http://htlogs.com/what-is-antispyware-exe-how-to-remove-antispyware-exe/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 14:53:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Winlogon\UserInit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1461</guid>
		<description><![CDATA[Antispyware.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: Antispyware.exe Filename: Antispyware.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Userinit Command: C:\Program Files\Def Group\PC Defender\Antispyware.exe Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>Antispyware.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> Antispyware.exe<br />
<strong>Filename:</strong> Antispyware.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Userinit</p></blockquote>
<p><strong>Command:</strong> C:\Program Files\Def Group\PC Defender\Antispyware.exe<br />
<strong>Startup Type:</strong> Winlogon\UserInit<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,”C:\Program Files\Def Group\PC Defender\Antispyware.exe”</p></blockquote>
<p><strong>Description:</strong> core component of PC Defender. PC Defender is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/02/20/how-to-remove-pc-defender-uninstall-instructions/">PC Defender removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-antispyware-exe-how-to-remove-antispyware-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is sdra64.exe, How to remove sdra64.exe</title>
		<link>http://htlogs.com/what-is-sdra64-exe-how-to-remove-sdra64-exe/</link>
		<comments>http://htlogs.com/what-is-sdra64-exe-how-to-remove-sdra64-exe/#comments</comments>
		<pubDate>Sun, 17 Jan 2010 18:32:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\UserInit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1333</guid>
		<description><![CDATA[sdra64.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: sdra64 Filename: sdra64.exe Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Userinit Command: C:\WINDOWS\system32\sdra64.exe Startup Type: Winlogon\UserInit HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>sdra64.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> sdra64<br />
<strong>Filename:</strong> sdra64.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Userinit</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\sdra64.exe<br />
<strong>Startup Type:</strong> Winlogon\UserInit<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,</p></blockquote>
<p><strong>Description:</strong> core component of trojan ZBot also known  as Trojan-Spy.Win32.Zbot.gen [Kaspersky Lab], PWS:Win32/Zbot.gen!R [Microsoft], Mal/Zbot-O [Sophos], Infostealer.Banker.C [Symantec]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-sdra64-exe-how-to-remove-sdra64-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is winlogon32.exe, How to remove winlogon32.exe</title>
		<link>http://htlogs.com/what-is-winlogon32-exe-how-to-remove-winlogon32-exe/</link>
		<comments>http://htlogs.com/what-is-winlogon32-exe-how-to-remove-winlogon32-exe/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 16:15:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\UserInit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1280</guid>
		<description><![CDATA[winlogon32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: winlogon32 Filename: winlogon32.exe Registry key&#124;value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon &#124; Userinit = “C:\WINDOWS\system32\winlogon32.exe” Command: C:\WINDOWS\system32\winlogon32.exe Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>winlogon32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> winlogon32<br />
<strong>Filename:</strong> winlogon32.exe<br />
<strong>Registry key|value:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | Userinit = “C:\WINDOWS\system32\winlogon32.exe”</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\winlogon32.exe<br />
<strong>Startup Type:</strong> WinLogon->UserInit<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 – REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe</p></blockquote>
<p><strong>Description:</strong> component of trojan FakeAlert</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/01/07/how-to-remove-smss32-exe-winlogon32-exe-helper32-dll-fake-worm-win32-netsky-spyware-alert/">winlogon32.exe removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-winlogon32-exe-how-to-remove-winlogon32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

