<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Malware</title>
	<atom:link href="http://htlogs.com/category/threats/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Tue, 07 Sep 2010 14:14:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>What is dfmcd21.dll, How to remove dfmcd21.dll</title>
		<link>http://htlogs.com/what-is-dfmcd21-dll-how-to-remove-dfmcd21-dll/</link>
		<comments>http://htlogs.com/what-is-dfmcd21-dll-how-to-remove-dfmcd21-dll/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 17:42:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[BHO]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft active setup]]></category>
		<category><![CDATA[O2]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1867</guid>
		<description><![CDATA[dfmcd21.dll is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: dfmcd21 Filename: dfmcd21.dll Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0098EFCC-12D6-4B0C-B566-E133F6B4941B} HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{77D30FCF-771E-4EF4-9DCD-69056CA0B517} Command: C:\WINDOWS\system32\dfmcd21.dll CLSID: {0098EFCC-12D6-4B0C-B566-E133F6B4941B}, [...]]]></description>
			<content:encoded><![CDATA[<h2>dfmcd21.dll is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> dfmcd21<br />
<strong>Filename:</strong> dfmcd21.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0098EFCC-12D6-4B0C-B566-E133F6B4941B}<br />
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{77D30FCF-771E-4EF4-9DCD-69056CA0B517}</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\dfmcd21.dll<br />
<strong>CLSID:</strong> {0098EFCC-12D6-4B0C-B566-E133F6B4941B}, {77D30FCF-771E-4EF4-9DCD-69056CA0B517}<br />
<strong>Startup Type:</strong> BHO, Microsoft active setup<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O2 &#8211; BHO:  &#8211; {0098EFCC-12D6-4B0C-B566-E133F6B4941B} &#8211; C:\WINDOWS\system32\dfmcd21.dll</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>BHO: : {0098EFCC-12D6-4B0C-B566-E133F6B4941B} &#8211; C:\WINDOWS\system32\dfmcd21.dll<br />
mASetup: {77D30FCF-771E-4EF4-9DCD-69056CA0B517} &#8211; C:\WINDOWS\system32\dfmcd21.dll</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0098EFCC-12D6-4B0C-B566-E133F6B4941B}]<br />
2010-07-14 07:39:17 51200 &#8212;-a-w- C:\WINDOWS\system32\dfmcd21.dll<br />
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{77D30FCF-771E-4EF4-9DCD-69056CA0B517}]<br />
2010-07-14 07:39:17 51200 &#8212;-a-w- C:\WINDOWS\system32\dfmcd21.dll</p></blockquote>
<p><strong>Description:</strong> malware</p>
<p><strong>How to remove:</strong> use the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0098EFCC-12D6-4B0C-B566-E133F6B4941B}]<br />
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{77D30FCF-771E-4EF4-9DCD-69056CA0B517}]</p>
<p>:files<br />
%WinDir%\system32\dfmcd21.dll</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-dfmcd21-dll-how-to-remove-dfmcd21-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is drwat32.exe, How to remove drwat32.exe</title>
		<link>http://htlogs.com/what-is-drwat32-exe-how-to-remove-drwat32-exe/</link>
		<comments>http://htlogs.com/what-is-drwat32-exe-how-to-remove-drwat32-exe/#comments</comments>
		<pubDate>Wed, 19 May 2010 13:14:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1718</guid>
		<description><![CDATA[drwat32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: drwat32 Filename: drwat32.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; Dr.Watson Command: %WinDir%\system32\drwat32.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>drwat32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> drwat32<br />
<strong>Filename:</strong> drwat32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | Dr.Watson</p></blockquote>
<p><strong>Command:</strong> %WinDir%\system32\drwat32.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Policies\Explorer\Run: [Dr.Watson] C:\WINDOWS\system32\drwat32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]<br />
&#8220;Dr.Watson&#8221;=C:\WINDOWS\system32\drwat32.exe</p></blockquote>
<p><strong>Description:</strong> malware</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-drwat32-exe-how-to-remove-drwat32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is microsft.exe, How to remove microsft.exe</title>
		<link>http://htlogs.com/what-is-microsft-exe-how-to-remove-microsft-exe/</link>
		<comments>http://htlogs.com/what-is-microsft-exe-how-to-remove-microsft-exe/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 16:23:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft active setup]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1503</guid>
		<description><![CDATA[microsft.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: microsft Filename: microsft.exe Registry key: HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C77088EB-52B1-173B-F6D5-36B5619926BD} Command: %Program Files%\whyu\microsft.exe CLSID: {C77088EB-52B1-173B-F6D5-36B5619926BD} Startup Type: [...]]]></description>
			<content:encoded><![CDATA[<h2>microsft.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> microsft<br />
<strong>Filename:</strong> microsft.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C77088EB-52B1-173B-F6D5-36B5619926BD}</p></blockquote>
<p><strong>Command:</strong> %Program Files%\whyu\microsft.exe<br />
<strong>CLSID:</strong> {C77088EB-52B1-173B-F6D5-36B5619926BD}<br />
<strong>Startup Type:</strong> Microsoft active setup<br />
<strong>DDS Line:</strong></p>
<blockquote><p>mASetup: {C77088EB-52B1-173B-F6D5-36B5619926BD} &#8211; C:\Program Files\whyu\microsft.exe s</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C77088EB-52B1-173B-F6D5-36B5619926BD}]<br />
C:\Program Files\whyu\microsft.exe s</p></blockquote>
<p><strong>Description:</strong> malware also known as Mal/VB-Z [Sophos]</p>
<p><strong>How to remove:</strong> Registry editor +  <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-microsft-exe-how-to-remove-microsft-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is apocalyps32.exe, How to remove apocalyps32.exe</title>
		<link>http://htlogs.com/what-is-apocalyps32-exe-how-to-remove-apocalyps32-exe/</link>
		<comments>http://htlogs.com/what-is-apocalyps32-exe-how-to-remove-apocalyps32-exe/#comments</comments>
		<pubDate>Sat, 09 Jan 2010 15:53:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1290</guid>
		<description><![CDATA[apocalyps32.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: apocalyps32 Filename: apocalyps32.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; apocalyps32 Command: C:\Windows\apocalyps32.exe Startup Type: HKLM->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>apocalyps32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> apocalyps32<br />
<strong>Filename:</strong> apocalyps32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | apocalyps32</p></blockquote>
<p><strong>Command:</strong> C:\Windows\apocalyps32.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [apocalyps32] C:\Windows\apocalyps32.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [apocalyps32] C:\Windows\apocalyps32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;apocalyps32&#8243;=C:\Windows\apocalyps32.exe</p></blockquote>
<p><strong>Description:</strong> malware also known as Mal/Behav-328, Mal/Dropper-G, Mal/Behav-053 [Sophos]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-apocalyps32-exe-how-to-remove-apocalyps32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PrestoTuneUp &#8211; PrestoTuneUp.exe &#8211; Presto Tuneup scareware</title>
		<link>http://htlogs.com/prestotuneup-prestotuneupexe-presto-tuneup-scareware/</link>
		<comments>http://htlogs.com/prestotuneup-prestotuneupexe-presto-tuneup-scareware/#comments</comments>
		<pubDate>Sun, 31 May 2009 08:08:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=504</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: PrestoTuneUp Filename: PrestoTuneUp.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; Presto TuneUp Command: C:\Documents and Settings\All Users\Application Data\b1529a0\PrestoTuneUp.exe [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> PrestoTuneUp<br />
<strong>Filename:</strong> PrestoTuneUp.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Presto TuneUp</p></blockquote>
<p><strong>Command:</strong> C:\Documents and Settings\All Users\Application Data\b1529a0\PrestoTuneUp.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [Presto TuneUp] “C:\Documents and Settings\All Users\Application Data\b1529a0\PrestoTuneUp.exe” /s /d</p></blockquote>
<p><strong>Description:</strong> <a href="http://www.myantispyware.com/2009/05/31/how-to-remove-presto-tuneup-uninstall-instructions/">Presto Tuneup</a> is a scareware program that uses false system errors to trick you into buying the software.</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Antimalware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/prestotuneup-prestotuneupexe-presto-tuneup-scareware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>diarprof.exe is a malware</title>
		<link>http://htlogs.com/diarprofexe-is-a-malware/</link>
		<comments>http://htlogs.com/diarprofexe-is-a-malware/#comments</comments>
		<pubDate>Sat, 14 Mar 2009 03:24:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=298</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: diarprof Filename: diarprof.exe Startup Type: HKCU->Run HijackThis Category: O4 HijackThis Line: O4 &#8211; HKCU\..\Run: [bo0pRSZ3e] [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> diarprof<br />
<strong>Filename:</strong> diarprof.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [bo0pRSZ3e] diarprof.exe</p></blockquote>
<p><strong>Description:</strong> Unknown malware component</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/diarprofexe-is-a-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>distus40.exe is  a malware</title>
		<link>http://htlogs.com/distus40exe-is-a-malware/</link>
		<comments>http://htlogs.com/distus40exe-is-a-malware/#comments</comments>
		<pubDate>Sat, 14 Mar 2009 03:16:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=294</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: distus40 Filename: distus40.exe Startup Type: HKLM->Run HijackThis Category: O4 HijackThis Line: O4 &#8211; HKLM\..\Run: [qFrf32V] [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> distus40<br />
<strong>Filename:</strong> distus40.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [qFrf32V] distus40.exe</p></blockquote>
<p><strong>Description:</strong> Unknown malware component</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/distus40exe-is-a-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>xivop.exe is a malware</title>
		<link>http://htlogs.com/xivopexe-is-a-malware/</link>
		<comments>http://htlogs.com/xivopexe-is-a-malware/#comments</comments>
		<pubDate>Sat, 28 Feb 2009 13:42:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=252</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: xivop Filename: xivop.exe Command: C:\WINDOWS\xivop.exe Startup Type: HKLM->Run HijackThis Category: O4 HijackThis Line: O4 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> xivop<br />
<strong>Filename:</strong> xivop.exe<br />
<strong>Command:</strong> C:\WINDOWS\xivop.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [xivop] C:\WINDOWS\xivop.exe</p></blockquote>
<p><strong>Description:</strong>  component of unknown malware</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/xivopexe-is-a-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>qwbqgkxr.exe is a malware</title>
		<link>http://htlogs.com/qwbqgkxrexe-is-a-malware/</link>
		<comments>http://htlogs.com/qwbqgkxrexe-is-a-malware/#comments</comments>
		<pubDate>Sat, 28 Feb 2009 13:39:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=249</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: qwbqgkxr Filename: qwbqgkxr.exe Command: C:\WINDOWS\qwbqgkxr.exe Startup Type: HKLM->Run HijackThis Category: O4 HijackThis Line: O4 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> qwbqgkxr<br />
<strong>Filename:</strong> qwbqgkxr.exe<br />
<strong>Command:</strong> C:\WINDOWS\qwbqgkxr.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [MaG78PfJs] C:\WINDOWS\qwbqgkxr.exe</p></blockquote>
<p><strong>Description:</strong> component of unknown malware</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/qwbqgkxrexe-is-a-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BHO module {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} is part of SPYW_IMISERV.C</title>
		<link>http://htlogs.com/bho-module-69135bde-5fdc-4b61-98aa-82ad2091bccc-is-part-of-spyw_imiservc/</link>
		<comments>http://htlogs.com/bho-module-69135bde-5fdc-4b61-98aa-82ad2091bccc-is-part-of-spyw_imiservc/#comments</comments>
		<pubDate>Sat, 28 Feb 2009 13:32:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[BHO]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[O2]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=247</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. CLSID: {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} Startup Type: BHO HijackThis Category: O2 HijackThis Line: O2 &#8211; BHO: (no name) &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>CLSID:</strong> {69135BDE-5FDC-4B61-98AA-82AD2091BCCC}<br />
<strong>Startup Type:</strong> BHO<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O2 &#8211; BHO: (no name) &#8211; {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} &#8211; (no file)</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong><br />
<strong>Description:</strong> part of SPYW_IMISERV.C, looks <a href="http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=SPYW%5FIMISERV%2EC">here</a></p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">Use HijackThis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/bho-module-69135bde-5fdc-4b61-98aa-82ad2091bccc-is-part-of-spyw_imiservc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
