<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; adware</title>
	<atom:link href="http://htlogs.com/category/threats/adware/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is mmx.dll, How to remove mmx.dll</title>
		<link>http://htlogs.com/what-is-mmx-dll-how-to-remove-mmx-dll/</link>
		<comments>http://htlogs.com/what-is-mmx-dll-how-to-remove-mmx-dll/#comments</comments>
		<pubDate>Mon, 20 Sep 2010 13:26:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O2]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[adware]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1976</guid>
		<description><![CDATA[mmx.dll is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: mmx Filename: mmx.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629} Command: %WinDir%\$NtUninstallMTF1011$\mmx.dll CLSID: {0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629} Startup Type: BHO [...]]]></description>
			<content:encoded><![CDATA[<h2>mmx.dll is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> mmx<br />
<strong>Filename:</strong> mmx.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629}</p></blockquote>
<p><strong>Command:</strong> %WinDir%\$NtUninstallMTF1011$\mmx.dll<br />
<strong>CLSID:</strong> {0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629}<br />
<strong>Startup Type:</strong> BHO<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629}]<br />
brumaqpyxgrm Object &#8211; C:\WINDOWS\$NtUninstallMTF1011$\mmx.dll [2010-08-17 247296]</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>BHO: brumaqpyxgrm Object : {0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629} &#8211; C:\WINDOWS\$NtUninstallMTF1011$\mmx.dll</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629}]<br />
brumaqpyxgrm Object  &#8211; C:\WINDOWS\$NtUninstallMTF1011$\mmx.dll</p></blockquote>
<p><strong>Description:</strong> variant of Win32/Adware.Lifze</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> or the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EFC03F8-191D-4E6B-8E44-E3B6FEEA3629}]</p>
<p>:files<br />
%WinDir%\$NtUninstallMTF1011$\mmx.dll</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-mmx-dll-how-to-remove-mmx-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AdSubscribe.dll is adware</title>
		<link>http://htlogs.com/adsubscribedll-is-adware/</link>
		<comments>http://htlogs.com/adsubscribedll-is-adware/#comments</comments>
		<pubDate>Sun, 28 Jun 2009 03:55:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ShellIconOverlayIdentifiers]]></category>
		<category><![CDATA[adware]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=596</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: AdSubscribe Filename: AdSubscribe.dll Registry key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AdSubscribe HKEY_CLASSES_ROOT\CLSID\{82C885EE-6B87-4D51-9EF4-0CFE9FADA900} Command: shelliconoverlayidentifiers CLSID: clsid Startup Type: Combofix/RSIT Line: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> AdSubscribe<br />
<strong>Filename:</strong> AdSubscribe.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AdSubscribe<br />
HKEY_CLASSES_ROOT\CLSID\{82C885EE-6B87-4D51-9EF4-0CFE9FADA900}</p></blockquote>
<p><strong>Command:</strong> shelliconoverlayidentifiers<br />
<strong>CLSID:</strong> clsid<br />
<strong>Startup Type:</strong><br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AdSubscribe]<br />
@=&#8221;{82C885EE-6B87-4D51-9EF4-0CFE9FADA900}&#8221;<br />
[HKEY_CLASSES_ROOT\CLSID\{82C885EE-6B87-4D51-9EF4-0CFE9FADA900}]<br />
2009-06-23 21:11 750080 &#8212;-a-w- c:\documents and settings\user\Application Data\AdSubscribe\AdSubscribe.dll<br />
2009-06-23 21:11 . 2009-06-23 21:11 &#8212;&#8212;&#8211; d&#8212;&#8211;w- c:\documents and settings\user\Application Data\AdSubscribe<br />
2009-06-23 21:11 . 2009-06-23 21:11 807424 &#8212;-a-w- c:\documents and settings\user\Application Data\AdSubscribe\Uninstall.exe<br />
2009-06-23 21:11 . 2009-06-23 21:11 750080 &#8212;-a-w- c:\documents and settings\user\Application Data\AdSubscribe\AdSubscribe.dll</p></blockquote>
<p><strong>Description:</strong> adware also known as AdWare.FearAds, Trojan-Downloader.Win32.Adload.fib, Worm.Win32.Malware.gen</p>
<p><strong>How to remove:</strong> ask help at Spyware removal forum.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/adsubscribedll-is-adware/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>wcs.exe a variant of the Adware/Netproject malware</title>
		<link>http://htlogs.com/wcsexe-a-variant-of-the-adwarenetproject-malware/</link>
		<comments>http://htlogs.com/wcsexe-a-variant-of-the-adwarenetproject-malware/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 05:15:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[adware]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=170</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: wcs Filename: wcs.exe Command: %programfiles%\Applications\wcs.exe Startup Type: HKLM->Policies\Explorer\Run: HijackThis Category: O4 HijackThis Line: O4 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> wcs<br />
<strong>Filename:</strong> wcs.exe<br />
<strong>Command:</strong> %programfiles%\Applications\wcs.exe<br />
<strong>Startup Type:</strong> HKLM->Policies\Explorer\Run:<br />
<strong>HijackThis Category:</strong> O4<br />
<strong>HijackThis Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Policies\Explorer\Run: [smile] C:\Program Files\Applications\wcs.exe </p></blockquote>
<p><strong>Description:</strong> variant of the Adware/Netproject malware</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/wcsexe-a-variant-of-the-adwarenetproject-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

