<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Rootkit</title>
	<atom:link href="http://htlogs.com/category/threats/rootkit/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is ndisdrv.sys, How to remove ndisdrv.sys</title>
		<link>http://htlogs.com/what-is-ndisdrv-sys-how-to-remove-ndisdrv-sys/</link>
		<comments>http://htlogs.com/what-is-ndisdrv-sys-how-to-remove-ndisdrv-sys/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 15:18:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1304</guid>
		<description><![CDATA[ndisdrv.sys is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ndisdrv Filename: ndisdrv.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISDRV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ndisdrv HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISDRV HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ndisdrv Command: c:\windows\system32\ndisdrv.sys Startup Type: Driver DDS/Combofix/RSIT [...]]]></description>
			<content:encoded><![CDATA[<h2>ndisdrv.sys is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ndisdrv<br />
<strong>Filename:</strong> ndisdrv.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISDRV<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ndisdrv<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISDRV<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ndisdrv</p></blockquote>
<p><strong>Command:</strong> c:\windows\system32\ndisdrv.sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong>DDS/<a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>S3 ndisdrv;ndisdrv;\??\c:\windows\system32\ndisdrv.sys &#8211;> c:\windows\system32\ndisdrv.sys [?]</p></blockquote>
<p><strong>Description:</strong> trojan-rootkit also known as Mal/Rootkit-Q [Sophos]</p>
<p><strong>How to remove:</strong></p>
<blockquote><p>Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a><br />
Run OTM.<br />
Copy, then paste the following text in &#8220;Paste Instructions for Items to be Moved&#8221; window (under the yellow bar):</p>
<p><font color=blue>:services<br />
ndisdrv</p>
<p>:files<br />
c:\windows\system32\ndisdrv.sys</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. When the tool is finished, it will produce a report for you.<br />
Download and run <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ndisdrv-sys-how-to-remove-ndisdrv-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is H8SRT.sys, How to remove H8SRT.sys</title>
		<link>http://htlogs.com/what-is-h8srt-sys-how-to-remove-h8srt-sys/</link>
		<comments>http://htlogs.com/what-is-h8srt-sys-how-to-remove-h8srt-sys/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 14:48:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1239</guid>
		<description><![CDATA[H8SRT.sys is a harmful driver. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Driver name: H8SRT.sys Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\H8SRTd.sys Command: C:\WINDOWS\system32\drivers\H8SRT[random].sys Startup Type: Driver Description: trojan-rootkit also known [...]]]></description>
			<content:encoded><![CDATA[<h2>H8SRT.sys is a harmful driver.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Driver name:</strong> H8SRT.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\H8SRTd.sys</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\system32\drivers\H8SRT[random].sys<br />
<strong>Startup Type:</strong> Driver<br />
<strong>Description:</strong> trojan-rootkit also known as Rootkit.TDSS.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2009/12/22/how-to-remove-h8srt-trojan-remove-rootkit-tdss/">H8SRT trojan removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-h8srt-sys-how-to-remove-h8srt-sys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Msqpdxserv.sys is trojan W32.Tidserv</title>
		<link>http://htlogs.com/msqpdxservsys-is-trojan-w32tidserv/</link>
		<comments>http://htlogs.com/msqpdxservsys-is-trojan-w32tidserv/#comments</comments>
		<pubDate>Sat, 02 May 2009 07:11:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=486</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: Msqpdxserv Filename: Msqpdxserv.sys Registry key: HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_msqpdxserv.sys Startup Type: hidden driver Description: Trojan msqpdxserv.sys blocks user [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> Msqpdxserv<br />
<strong>Filename:</strong> Msqpdxserv.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_msqpdxserv.sys</p></blockquote>
<p><strong>Startup Type:</strong> hidden driver<br />
<strong>Description:</strong> Trojan msqpdxserv.sys blocks user access to security websites, web pages have a “VIMAX” ad, Google, Yahoo, MSN search results redirect you to other non related sites. Also trojan msqpdxserv.sys trojan changes the DNS server to 85.255.115.x or 85.255.112.x</p>
<p><strong>How to remove:</strong> use these instructions <a href="http://www.myantispyware.com/2009/01/04/how-to-remove-msqpdxservsys-trojan-w32tidserv/">How to remove msqpdxserv.sys trojan</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/msqpdxservsys-is-trojan-w32tidserv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TDSSserv.sys is trojan TDSSserv</title>
		<link>http://htlogs.com/tdssservsys-is-trojan-tdssserv/</link>
		<comments>http://htlogs.com/tdssservsys-is-trojan-tdssserv/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 11:16:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=462</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: TDSSserv Filename: TDSSserv.sys Registry key: HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_TDSSserv.sys Startup Type: Hidden driver Description: TDSSserv.sys is Trojan.TDSSserv also [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> TDSSserv<br />
<strong>Filename:</strong> TDSSserv.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_TDSSserv.sys</p></blockquote>
<p><strong>Startup Type:</strong> Hidden driver<br />
<strong>Description:</strong> TDSSserv.sys is Trojan.TDSSserv also known as Trojan Backdoor.Tidserv that uses rootkit-specific techniques designed to hide itself.</p>
<p><strong>How to remove:</strong> use the instructions <a href="http://www.myantispyware.com/2008/11/05/how-to-remove-trojan-tdsserv/">How to remove trojan TDSSserv (TDSSserv.sys), clbdriver.sys and seneka.sys</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/tdssservsys-is-trojan-tdssserv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UACd.sys is a trojan</title>
		<link>http://htlogs.com/uacdsys-is-a-trojan/</link>
		<comments>http://htlogs.com/uacdsys-is-a-trojan/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 14:06:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=435</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: UACd Filename: UACd.sys Registry key: HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_UACd.sys Startup Type: hidden driver Description: trojan that uses rootkit-specific [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> UACd<br />
<strong>Filename:</strong> UACd.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_UACd.sys</p></blockquote>
<p><strong>Startup Type:</strong> hidden driver<br />
<strong>Description:</strong> trojan that uses rootkit-specific techniques designed to hide itself.<br />
<strong>How to remove:</strong> use the instruction <a href="http://www.myantispyware.com/2009/01/24/how-to-remove-windowsclickcom-redirect-uacdsys-trojan/">How to remove windowsclick.com redirect [UACd.sys trojan]</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/uacdsys-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>gaopdxserv.sys is a trojan, variant of TDSSserv trojan</title>
		<link>http://htlogs.com/gaopdxservsys-is-a-trojan-variant-of-tdssserv-trojan/</link>
		<comments>http://htlogs.com/gaopdxservsys-is-a-trojan-variant-of-tdssserv-trojan/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 13:47:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=433</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: gaopdxserv Filename: gaopdxserv.sys Registry key: HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_gaopdxserv.sys Startup Type: hidden driver Description:variant of TDSSserv trojan (uses [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> gaopdxserv<br />
<strong>Filename:</strong> gaopdxserv.sys<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_gaopdxserv.sys</p></blockquote>
<p><strong>Startup Type:</strong> hidden driver<br />
<strong>Description:</strong>variant of TDSSserv trojan (uses rootkit-specific techniques designed to hide the software presence in the system.)</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2009/03/15/how-to-remove-google-searches-redirectvimax-ads-gaopdxservsys-trojan/">use the instruction How to remove Google searches redirect/vimax ads [gaopdxserv.sys trojan]</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/gaopdxservsys-is-a-trojan-variant-of-tdssserv-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>gxvxcserv.sys is a troajn w32.Tidserv</title>
		<link>http://htlogs.com/gxvxcservsys-is-a-troajn-w32tidserv/</link>
		<comments>http://htlogs.com/gxvxcservsys-is-a-troajn-w32tidserv/#comments</comments>
		<pubDate>Sat, 25 Apr 2009 13:19:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=417</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: gxvxcserv Registry key: HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_gxvxcserv.sys HKEY_LOCAL_MACHINE\System\Controlset003\Enum\legacy_gxvxcserv.sys HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gxvxcserv.sys Command: command Startup Type: Hidden driver Description: troajn w32.Tidserv. [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> gxvxcserv<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\System\Controlset001\Enum\legacy_gxvxcserv.sys<br />
HKEY_LOCAL_MACHINE\System\Controlset003\Enum\legacy_gxvxcserv.sys<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gxvxcserv.sys
</p></blockquote>
<p><strong>Command:</strong> command<br />
<strong>Startup Type:</strong> Hidden driver<br />
<strong>Description:</strong> troajn w32.Tidserv. The trojan uses rootkit techniques designed to hide the software presence in the system.</p>
<p><strong>How to remove:</strong> use the instructions <a href="http://www.myantispyware.com/2009/04/22/how-to-remove-gxvxcservsys-trojan-redirect-virus/">How to remove gxvxcserv.sys trojan (Google redirect virus)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/gxvxcservsys-is-a-troajn-w32tidserv/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>gaopdxqltiqmuy.sys is a rootkit/trojan</title>
		<link>http://htlogs.com/gaopdxqltiqmuysys-is-a-rootkittrojan/</link>
		<comments>http://htlogs.com/gaopdxqltiqmuysys-is-a-rootkittrojan/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 12:59:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Driver]]></category>
		<category><![CDATA[Rootkit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=148</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: gaopdxqltiqmuy Filename: gaopdxqltiqmuy.sys Command: c:\windows\system32\drivers\gaopdxqltiqmuy.sys Startup Type: Hidden driver Description: Rootkit/trojan component How to remove: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> gaopdxqltiqmuy<br />
<strong>Filename:</strong> gaopdxqltiqmuy.sys<br />
<strong>Command:</strong> c:\windows\system32\drivers\gaopdxqltiqmuy.sys<br />
<strong>Startup Type:</strong> Hidden driver<br />
<strong>Description:</strong> Rootkit/trojan component</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2008/11/05/how-to-remove-trojan-tdsserv/">How to remove trojan TDSSserv (TDSSserv.sys), clbdriver.sys and seneka.sys</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/gaopdxqltiqmuysys-is-a-rootkittrojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>tcpsr.sys</title>
		<link>http://htlogs.com/tcpsrsys/</link>
		<comments>http://htlogs.com/tcpsrsys/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 05:29:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rootkit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=59</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: tcpsr Filename: tcpsr.sys Registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpsr Command: C:\WINDOWS\System32\drivers\tcpsr.sys Startup Type: services RSIT/Combofix log line: S3 [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> tcpsr<br />
<strong>Filename:</strong> tcpsr.sys<br />
<strong>Registry key:</strong> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpsr<br />
<strong>Command:</strong> C:\WINDOWS\System32\drivers\tcpsr.sys<br />
<strong>Startup Type:</strong> services<br />
<strong>RSIT/Combofix log line:</strong> S3 tcpsr;tcpsr; \??\C:\WINDOWS\System32\drivers\tcpsr.sys []<br />
<strong>Description:</strong> Rootkit.MailGrab also known as TROJ_PANDEX.CHL, looks <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_PANDEX.CHL&#038;VSect=T">here</a></p>
<p><strong>How to remove:</strong> Use <a href="http://www.myantispyware.com/2007/11/09/sdfix-free-trojan-remover-tool/">SDFix free trojan remover tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/tcpsrsys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

