<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Threats</title>
	<atom:link href="http://htlogs.com/category/threats/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is winxn.exe, How to remove winxn.exe</title>
		<link>http://htlogs.com/what-is-winxn-exe-how-to-remove-winxn-exe/</link>
		<comments>http://htlogs.com/what-is-winxn-exe-how-to-remove-winxn-exe/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 07:53:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2153</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: winxn Filename: winxn.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; WinXn Command: %Temp%\winxn.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> winxn<br />
<strong>Filename:</strong> winxn.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | WinXn</p></blockquote>
<p><strong>Command:</strong> %Temp%\winxn.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [WinXn] %Temp%\winxn.exe </p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;WinXn&#8221;=%Temp%\winxn.exe</p></blockquote>
<p><strong>Description:</strong> malware</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-winxn-exe-how-to-remove-winxn-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Anti-Malware Lab, How to remove Anti-Malware Lab</title>
		<link>http://htlogs.com/what-is-anti-malware-lab-how-to-remove-anti-malware-lab/</link>
		<comments>http://htlogs.com/what-is-anti-malware-lab-how-to-remove-anti-malware-lab/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 04:01:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2150</guid>
		<description><![CDATA[Anti-Malware Lab is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Anti-Malware Lab associated files and folders: C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe %UserProfile%\Application Data\Anti-Malware Lab %UserProfile%\Application Data\Anti-Malware Lab\cookies.sqlite [...]]]></description>
			<content:encoded><![CDATA[<h2>Anti-Malware Lab is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Anti-Malware Lab associated files and folders:</strong></p>
<blockquote><p>C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe<br />
%UserProfile%\Application Data\Anti-Malware Lab<br />
%UserProfile%\Application Data\Anti-Malware Lab\cookies.sqlite<br />
%UserProfile%\Desktop\Anti-Malware Lab.lnk<br />
%UserProfile%\Start Menu\Anti-Malware Lab.lnk<br />
%UserProfile%\Application Data\Anti-Malware Lab\Instructions.ini<br />
%UserProfile%\Start Menu\Programs\Anti-Malware Lab.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Anti-Malware Lab.lnk</p></blockquote>
<p><strong>Anti-Malware Lab associated registry keys and values:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Anti-Malware Lab</p></blockquote>
<p><strong>Core filename:</strong> AB120_121.exe<br />
<strong>Command:</strong> C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe<br />
<strong>HijackThis shows Anti-Malware Lab:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [Anti-Malware Lab] “C:\Documents and Settings\All Users\Application Data\da2933\AB120_121.exe” /s /d</p></blockquote>
<p><strong>Description:</strong> Anti-Malware Lab is a fake antivirus software that installed through the use of trojans without user knowledge and permission. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, this malware will display numerous fake security alerts and block legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake antivirus! Instead, follow the removal guide below to remove Anti-Malware Lab from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2011/07/06/how-to-remove-anti-malware-lab-uninstall-instructions/">Anti-Malware Lab removal</a>  guide or the steps below.</p>
<p>1. Reboot your computer in Safe mode with networking.</p>
<p>2. Reset proxy settings of your browser (this malware hijacked them) by doing: run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Uncheck “Use a proxy server” box. Click OK and click OK again.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
<p>4. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:Commands<br />
[emptytemp]<br />
[resethosts]</font></p>
<p>Click the red Moveit! button. Close OTM.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-anti-malware-lab-how-to-remove-anti-malware-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is XP Antivirus 2012, How to remove XP Antivirus 2012</title>
		<link>http://htlogs.com/what-is-xp-antivirus-2012-how-to-remove-xp-antivirus-2012/</link>
		<comments>http://htlogs.com/what-is-xp-antivirus-2012-how-to-remove-xp-antivirus-2012/#comments</comments>
		<pubDate>Sat, 11 Jun 2011 10:53:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2146</guid>
		<description><![CDATA[XP Antivirus 2012 is a harmful program. It is a fake security program, you should immediately remove it using a legitimate antispyware or antivirus software. If that does not help, then ask us for help in the Spyware removal forum. XP Antivirus 2012 associated files and folders: %AppData%\[RANDOM CHARACTERS].exe XP Antivirus 2012 associated registry keys [...]]]></description>
			<content:encoded><![CDATA[<h2>XP Antivirus 2012 is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using a legitimate antispyware or antivirus software.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>XP Antivirus 2012 associated files and folders:</strong></p>
<blockquote><p>%AppData%\[RANDOM CHARACTERS].exe</p></blockquote>
<p><strong>XP Antivirus 2012 associated registry keys and values:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Classes\.exe<br />
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command<br />
HKEY_CURRENT_USER\Software\Classes\pezfile<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\DefaultIcon<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\runas<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\runas\command<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\start<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\start\command<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = “”%AppData%\[RANDOM CHARACTERS].exe” /START “%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = “”%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\.exe | @ = “pezfile”<br />
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = “application/x-msdownload”<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | @ = “”%AppData%\[RANDOM CHARACTERS].exe” /START “%1″ %*”<br />
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | IsolatedCommand = “”%1″ %*”<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command | “(Default)” = ‘”%AppData%\[RANDOM CHARACTERS].exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe”‘<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command | “(Default)” = ‘”%AppData%\[RANDOM CHARACTERS].exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command | “(Default)” = ‘”%AppData%\[RANDOM CHARACTERS].exe” -a “C:\Program Files\Internet Explorer\iexplore.exe”‘</p></blockquote>
<p><strong>Core filename:</strong> [RANDOM CHARACTERS].exe<br />
<strong>Description:</strong> XP Antivirus 2012 is a fake antivirus program that installed through the use of trojans without user knowledge and permission. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, XP Antivirus 2012 will display numerous fake security alerts and block legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake software! Instead, follow the removal guide below to remove XP Antivirus 2012 from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2011/06/11/how-to-remove-xp-antivirus-2012-virus/">XP Antivirus 2012 removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-xp-antivirus-2012-how-to-remove-xp-antivirus-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is PC Security Guardian, How to remove PC Security Guardian</title>
		<link>http://htlogs.com/what-is-pc-security-guardian-how-to-remove-pc-security-guardian/</link>
		<comments>http://htlogs.com/what-is-pc-security-guardian-how-to-remove-pc-security-guardian/#comments</comments>
		<pubDate>Fri, 06 May 2011 13:43:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2143</guid>
		<description><![CDATA[PC Security Guardian is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. PC Security Guardian associated files and folders: C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe %UserProfile%\Application Data\PC Security Guardian [...]]]></description>
			<content:encoded><![CDATA[<h2>PC Security Guardian is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>PC Security Guardian associated files and folders:</strong></p>
<blockquote><p>C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe<br />
%UserProfile%\Application Data\PC Security Guardian<br />
%UserProfile%\Application Data\PC Security Guardian\cookies.sqlite<br />
%UserProfile%\Desktop\PC Security Guardian.lnk<br />
%UserProfile%\Start Menu\PC Security Guardian.lnk<br />
%UserProfile%\Application Data\PC Security Guardian\Instructions.ini<br />
%UserProfile%\Start Menu\Programs\PC Security Guardian.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Security Guardian.lnk</p></blockquote>
<p><strong>PC Security Guardian associated registry keys and values:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | PC Security Guardian</p></blockquote>
<p><strong>Core filename:</strong> AB120_121.exe<br />
<strong>Command:</strong> C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> shows PC Security Guardian:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [PC Security Guardian] “C:\Documents and Settings\All Users\Application Data\da2933\AB120_121.exe” /s /d</p></blockquote>
<p><strong>Description:</strong> PC Security Guardian is a fake antivirus program that installed through the use of trojans without user knowledge and permission. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, this malware will display numerous fake security alerts and block legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake antivirus! Instead, follow the removal guide below to remove PC Security Guardian from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.fakealerts.com/rogue-antispyware-fake-alerts/remove-pc-security-guardian-malware-656.html">PC Security Guardian removal guide</a> or the steps below.</p>
<p>1. Reboot your computer in <a href="http://www.myantispyware.com/2009/03/01/how-to-reboot-computer-in-safe-mode/">Safe mode with networking</a>.</p>
<p>2. Reset proxy settings of your browser (this malware hijacked them) by doing: run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Uncheck “Use a proxy server” box. Click OK and click OK again.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
<p>4. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:Commands<br />
[emptytemp]<br />
[resethosts]</font></p>
<p>Click the red Moveit! button. Close OTM.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-pc-security-guardian-how-to-remove-pc-security-guardian/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Windows Power Expansion, How to remove Windows Power Expansion</title>
		<link>http://htlogs.com/what-is-windows-power-expansion-how-to-remove-windows-power-expansion/</link>
		<comments>http://htlogs.com/what-is-windows-power-expansion-how-to-remove-windows-power-expansion/#comments</comments>
		<pubDate>Sat, 26 Mar 2011 07:33:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2140</guid>
		<description><![CDATA[Windows Power Expansion is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Windows Power Expansion associated files and folders: %AppData%\Microsoft\[RANDOM CHARACTERS].exe Windows Power Expansion associated registry keys and [...]]]></description>
			<content:encoded><![CDATA[<h2>Windows Power Expansion is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Windows Power Expansion associated files and folders:</strong></p>
<blockquote><p>%AppData%\Microsoft\[RANDOM CHARACTERS].exe</p></blockquote>
<p><strong>Windows Power Expansion associated registry keys and values:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe | Debugger<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe | Debugger<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell = “%AppData%\Microsoft\[RANDOM CHARACTERS].exe”</p></blockquote>
<p><strong>Core filename:</strong> [RANDOM CHARACTERS].exe<br />
<strong>Description:</strong>Windows Power Expansion is a fake antivirus program that installed through the use of Microsoft Security Essentials Alert trojan without user knowledge and permission. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, this malware will display numerous fake security alerts and block legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake antivirus! Instead, follow the removal guide below to remove Windows Power Expansion from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2011/03/26/how-to-remove-windows-power-expansion-virus/">Windows Power Expansion removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-windows-power-expansion-how-to-remove-windows-power-expansion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Windows Remedy, How to remove Windows Remedy</title>
		<link>http://htlogs.com/what-is-windows-remedy-how-to-remove-windows-remedy/</link>
		<comments>http://htlogs.com/what-is-windows-remedy-how-to-remove-windows-remedy/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 02:25:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2137</guid>
		<description><![CDATA[Windows Remedy is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Windows Remedy associated files and folders: %AppData%\Microsoft\[RANDOM CHARACTERS].exe Windows Remedy associated registry keys and values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image [...]]]></description>
			<content:encoded><![CDATA[<h2>Windows Remedy is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Windows Remedy associated files and folders:</strong></p>
<blockquote><p>%AppData%\Microsoft\[RANDOM CHARACTERS].exe</p></blockquote>
<p><strong>Windows Remedy associated registry keys and values:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe | Debugger<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe | Debugger<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell = “%AppData%\Microsoft\[RANDOM CHARACTERS].exe”</p></blockquote>
<p><strong>Core filename:</strong> [RANDOM CHARACTERS].exe<br />
<strong>Description:</strong>Windows Remedy is a fake antivirus program that installed through the use of Microsoft Security Essentials Alert trojan without user knowledge and permission. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, this malware will display numerous fake security alerts and block legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake antivirus! Instead, follow the removal guide below to remove Windows Remedy from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the Windows Remedy <a href="http://www.myantispyware.com/2011/03/15/how-to-remove-windows-remedy-virus/">removal instructions</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-windows-remedy-how-to-remove-windows-remedy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is System Defender, How to remove System Defender</title>
		<link>http://htlogs.com/what-is-system-defender-how-to-remove-system-defender/</link>
		<comments>http://htlogs.com/what-is-system-defender-how-to-remove-system-defender/#comments</comments>
		<pubDate>Fri, 11 Mar 2011 13:15:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2129</guid>
		<description><![CDATA[System Defender is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. System Defender associated files and folders: C:\Program Files\System Defender C:\Program Files\System Defender\System Defender.dll %AppData%\Microsoft\Internet Explorer\Quick Launch\System Defender.lnk [...]]]></description>
			<content:encoded><![CDATA[<h2>System Defender is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>System Defender associated files and folders:</strong></p>
<blockquote><p>C:\Program Files\System Defender<br />
C:\Program Files\System Defender\System Defender.dll<br />
%AppData%\Microsoft\Internet Explorer\Quick Launch\System Defender.lnk<br />
%UserProfile%\Desktop\System Defender.lnk<br />
%UserProfile%\Start Menu\Programs\Startup\{RANDOM}.lnk<br />
C:\Documents and Settings\All Users\Application Data\{RANDOM}.avi<br />
C:\Documents and Settings\All Users\Application Data\{RANDOM}.ico<br />
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\{RANDOM}.lnk</p></blockquote>
<p><strong>System Defender associated registry keys and values:</strong></p>
<blockquote><p>HKEY_CLASSES_ROOT\CLSID\{RANDOM}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{RANDOM}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | {RANDOM}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | {RANDOM}</p></blockquote>
<p><strong>Core filename:</strong> {RANDOM}<br />
<strong>Description:</strong> System Defender is a fake antivirus program. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, System Defender will display numerous fake security alerts and may block the legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake software! Instead, follow the removal guide below to remove System Defender from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2011/03/11/how-to-remove-system-defender-virus/">System Defender removal</a> instructions or the steps below.</p>
<p>1. Reboot your computer in <a href="http://www.myantispyware.com/2009/03/01/how-to-reboot-computer-in-safe-mode/">Safe mode with networking</a>.<br />
2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-system-defender-how-to-remove-system-defender/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Antivirus Monitor, How to remove Antivirus Monitor</title>
		<link>http://htlogs.com/what-is-antivirus-monitor-how-to-remove-antivirus-monitor/</link>
		<comments>http://htlogs.com/what-is-antivirus-monitor-how-to-remove-antivirus-monitor/#comments</comments>
		<pubDate>Mon, 07 Mar 2011 14:17:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2126</guid>
		<description><![CDATA[Antivirus Monitor is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Antivirus Monitor associated files and folders: %Temp%\{RANDOM}\ %Temp%\{RANDOM}\{RANDOM}.exe AAntivirus Monitor associated registry keys and values: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter [...]]]></description>
			<content:encoded><![CDATA[<h2>Antivirus Monitor is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Antivirus Monitor associated files and folders:</strong></p>
<blockquote><p>%Temp%\{RANDOM}\<br />
%Temp%\{RANDOM}\{RANDOM}.exe</p></blockquote>
<p><strong>AAntivirus Monitor associated registry keys and values:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter | “Enabled” = “0″<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings | “ProxyOverride” = “”<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings | “ProxyServer” = “http=127.0.0.1:11215″<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings | “ProxyEnable” = “1″<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | {RANDOM}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | {RANDOM}</p></blockquote>
<p><strong>Core filename:</strong> {RANDOM}.exe<br />
<strong>Command:</strong> C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> shows Antivirus Monitor:</strong></p>
<blockquote><p>O4 – HKCU\..\RunOnce: [{RANDOM}] C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe</p></blockquote>
<p><strong>Description:</strong> Antivirus Monitor is a fake antivirus program that installed through the use of trojans without user knowledge and permission. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, Antivirus Monitor will display numerous fake security alerts and block all the legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake software! Instead, follow the removal guide below to remove Antivirus Monitor from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.fakealerts.com/rogue-antispyware-fake-alerts/remove-antivirus-monitor-malware-495.html">Antivirus Monitor removal</a> instructions or the steps below.</p>
<p>1. Reboot your computer in <a href="http://www.myantispyware.com/2009/03/01/how-to-reboot-computer-in-safe-mode/">Safe mode with networking</a>.<br />
2. Reset proxy settings of your browser (this malware hijacked them) by doing: run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Uncheck “Use a proxy server” box. Click OK and click OK again.<br />
3. Download HijackThis from <a href="http://go.trendmicro.com/free-tools/hijackthis/HiJackThis.exe">here</a> and save it to your desktop.<br />
4. Run HijackThis. Click to Scan button. After HijackThis completes the system scan, check the box to the left of the following items:</p>
<blockquote><p>O4 – HKCU\..\Run: [{RANDOM}] %Temp%\{RANDOM}.exe</p></blockquote>
<p>Please be very careful, do NOT check any other boxes! Next, click on Fix checked on the bottom left side of the HijackThis screen. Close HijackThis.<br />
5. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-antivirus-monitor-how-to-remove-antivirus-monitor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Internet Security Essentials, How to remove Internet Security Essentials</title>
		<link>http://htlogs.com/what-is-internet-security-essentials-how-to-remove-internet-security-essentials/</link>
		<comments>http://htlogs.com/what-is-internet-security-essentials-how-to-remove-internet-security-essentials/#comments</comments>
		<pubDate>Tue, 22 Feb 2011 02:42:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2124</guid>
		<description><![CDATA[Internet Security Essentials is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Internet Security Essentials associated files and folders: C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe %UserProfile%\Application Data\Internet Security Essentials [...]]]></description>
			<content:encoded><![CDATA[<h2>Internet Security Essentials is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Internet Security Essentials associated files and folders:</strong></p>
<blockquote><p>C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe<br />
%UserProfile%\Application Data\Internet Security Essentials<br />
%UserProfile%\Application Data\Internet Security Essentials\cookies.sqlite<br />
%UserProfile%\Desktop\Internet Security Essentials.lnk<br />
%UserProfile%\Start Menu\Internet Security Essentials.lnk<br />
%UserProfile%\Application Data\Internet Security Essentials\Instructions.ini<br />
%UserProfile%\Start Menu\Programs\Internet Security Essentials.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security Essentials.lnk</p></blockquote>
<p><strong>Internet Security Essentials associated registry keys and values:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Internet Security Essentials</p></blockquote>
<p><strong>Core filename:</strong> AB120_121.exe<br />
<strong>Command:</strong> C:\Documents and Settings\All Users\Application Data\da1933\AB120_121.exe<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> shows Internet Security Essentials:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [Internet Security Essentials] “C:\Documents and Settings\All Users\Application Data\da2933\AB120_121.exe” /s /d</p></blockquote>
<p><strong>Description:</strong> rogue antispyware program</p>
<p><strong>How to remove:</strong> use the <a href="http://www.fakealerts.com/rogue-antispyware-fake-alerts/remove-internet-security-essentials-malware-436.html">Internet Security Essentials removal guide</a> or the steps below.</p>
<p>1. Reboot your computer in <a href="http://www.myantispyware.com/2009/03/01/how-to-reboot-computer-in-safe-mode/">Safe mode with networking</a>.</p>
<p>2. Reset proxy settings of your browser (this malware hijacked them) by doing: run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Uncheck “Use a proxy server” box. Click OK and click OK again.</p>
<p>3. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
<p>4. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:Commands<br />
[emptytemp]<br />
[resethosts]</font></p>
<p>Click the red Moveit! button. Close OTM.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-internet-security-essentials-how-to-remove-internet-security-essentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Windows User Satellite, How to remove Windows User Satellite</title>
		<link>http://htlogs.com/what-is-windows-user-satellite-how-to-remove-windows-user-satellite/</link>
		<comments>http://htlogs.com/what-is-windows-user-satellite-how-to-remove-windows-user-satellite/#comments</comments>
		<pubDate>Thu, 17 Feb 2011 13:03:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2122</guid>
		<description><![CDATA[Windows User Satellite is a harmful program. It is a fake security program, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Windows User Satellite associated files and folders: %AppData%\[RANDOM CHARACTERS].exe Windows User Satellite associated registry keys and [...]]]></description>
			<content:encoded><![CDATA[<h2>Windows User Satellite is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a fake security program, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Windows User Satellite associated files and folders:</strong></p>
<blockquote><p>%AppData%\[RANDOM CHARACTERS].exe</p></blockquote>
<p><strong>Windows User Satellite associated registry keys and values:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell = “%AppData%\[RANDOM CHARACTERS].exe”</p></blockquote>
<p><strong>Core filename:</strong> [RANDOM CHARACTERS].exe<br />
<strong>Description:</strong> Windows User Satellite is a fake antivirus program that installed through the use of trojans without user knowledge and permission. When is started, it will perform a fake scan and state that your computer is infected with viruses, spyware and malware. Moreover, Windows User Satellite will display numerous fake security alerts and block legitimate and trustful applications used on your computer. In order to cure your PC, the program will suggest you to purchase its full version. Most important, do not pay for the fake software! Instead, follow the removal guide below to remove Windows User Satellite from your computer for free using legitimate free antimalware software.</p>
<p><strong>How to remove:</strong> use the <a href="http://www.fakealerts.com/rogue-antispyware-fake-alerts/remove-windows-user-satellite-malware-422.html">Windows User Satellite removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-windows-user-satellite-how-to-remove-windows-user-satellite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

