<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Trojan</title>
	<atom:link href="http://htlogs.com/category/threats/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is cryptnet32.dll, How to remove cryptnet32.dll</title>
		<link>http://htlogs.com/what-is-cryptnet32-dll-how-to-remove-cryptnet32-dll/</link>
		<comments>http://htlogs.com/what-is-cryptnet32-dll-how-to-remove-cryptnet32-dll/#comments</comments>
		<pubDate>Thu, 09 Dec 2010 17:51:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O20]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\Notify]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2080</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: cryptnet32 Filename: cryptnet32.dll Registry key: HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet32 Command: C:\WINDOWS\SYSTEM32\cryptnet32.dll Startup Type: Winlogon->Notify HijackThis Category: O20 [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> cryptnet32<br />
<strong>Filename:</strong> cryptnet32.dll<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet32</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\SYSTEM32\cryptnet32.dll<br />
<strong>Startup Type:</strong> Winlogon->Notify<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O20<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O20 &#8211; Winlogon Notify: cryptnet32 &#8211; C:\WINDOWS\SYSTEM32\cryptnet32.dll</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet32]<br />
2010-12-08 17:31 48128 —-a-w- C:\WINDOWS\SYSTEM32\cryptnet32.dll</p></blockquote>
<p><strong>Description:</strong> Trojan:Win32/Lukicsel.H [Microsoft]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2007/11/06/superantispyware-free-for-home-use/">SUPERAntiSpyware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-cryptnet32-dll-how-to-remove-cryptnet32-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is desktoplayer.exe, How to remove desktoplayer.exe</title>
		<link>http://htlogs.com/what-is-desktoplayer-exe-how-to-remove-desktoplayer-exe/</link>
		<comments>http://htlogs.com/what-is-desktoplayer-exe-how-to-remove-desktoplayer-exe/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 16:05:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[F2]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Winlogon\UserInit]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=2020</guid>
		<description><![CDATA[desktoplayer.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: desktoplayer Filename: desktoplayer.exe Registry key: HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon &#124; Userinit Command: c:\program files\microsoft\desktoplayer.exe Startup Type: HKLM->Winlogon->Userinit [...]]]></description>
			<content:encoded><![CDATA[<h2>desktoplayer.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> desktoplayer<br />
<strong>Filename:</strong> desktoplayer.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon  | Userinit</p></blockquote>
<p><strong>Command:</strong> c:\program files\microsoft\desktoplayer.exe<br />
<strong>Startup Type:</strong> HKLM->Winlogon->Userinit<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> F2<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>F2 &#8211; REG:system.ini: UserInit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]<br />
&#8220;Userinit&#8221;=&#8221;c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe&#8221;</p></blockquote>
<p><strong>Description:</strong> component of Win32.ramnit trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-desktoplayer-exe-how-to-remove-desktoplayer-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is tskmgr.exe, How to remove tskmgr.exe</title>
		<link>http://htlogs.com/what-is-tskmgr-exe-how-to-remove-tskmgr-exe/</link>
		<comments>http://htlogs.com/what-is-tskmgr-exe-how-to-remove-tskmgr-exe/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 13:54:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Policies\Explorer\Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1996</guid>
		<description><![CDATA[tskmgr.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: tskmgr Filename: tskmgr.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run &#124; waults Command: %AppData%\tskmgr.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>tskmgr.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> tskmgr<br />
<strong>Filename:</strong> tskmgr.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | waults</p></blockquote>
<p><strong>Command:</strong> %AppData%\tskmgr.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Policies\Explorer\Run: [waults] C:\Documents and Settings\Username\Application Data\tskmgr.exe</p></blockquote>
<p><strong>Description:</strong> a trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-tskmgr-exe-how-to-remove-tskmgr-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is complmgr.exe, How to remove complmgr.exe</title>
		<link>http://htlogs.com/what-is-complmgr-exe-how-to-remove-complmgr-exe/</link>
		<comments>http://htlogs.com/what-is-complmgr-exe-how-to-remove-complmgr-exe/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 13:46:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1994</guid>
		<description><![CDATA[complmgr.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: complmgr Filename: complmgr.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; COM+ Manage Command: %UserProfile%\.COMMgr\complmgr.exe Startup Type: HKCU->Run HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>complmgr.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> complmgr<br />
<strong>Filename:</strong> complmgr.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | COM+ Manage</p></blockquote>
<p><strong>Command:</strong> %UserProfile%\.COMMgr\complmgr.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [COM+ Manager] &#8220;C:\Documents and Settings\Username\.COMMgr\complmgr.exe&#8221;</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [COM+ Manager] C:\Documents and Settings\Username\.COMMgr\complmgr.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;COM+ Manager&#8221;=C:\Documents and Settings\Username\.COMMgr\complmgr.exe</p></blockquote>
<p><strong>Description:</strong> trojan known as Downloader [Symantec], Trojan.Win32.Scar.bueu [Kaspersky Lab], Generic Downloader.x!dju [McAfee], Mal/Generic-L [Sophos], TrojanDownloader:Win32/Scar.B [Microsoft], Trojan.Win32.Scar [Ikarus]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a> or the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“COM+ Manager”=-</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a>. Run, perform a scan and let it remove what it found. </p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-complmgr-exe-how-to-remove-complmgr-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is 3FWHZQA3LT, How to remove 3FWHZQA3LT</title>
		<link>http://htlogs.com/what-is-3fwhzqa3lt-how-to-remove-3fwhzqa3lt/</link>
		<comments>http://htlogs.com/what-is-3fwhzqa3lt-how-to-remove-3fwhzqa3lt/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 09:13:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1992</guid>
		<description><![CDATA[3FWHZQA3LT is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Filename: {RANDOM:3}.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; 3FWHZQA3LT Command: %Temp%\{RANDOM:3}.exe Startup Type: HKCU->Run HijackThis Category: O4 HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>3FWHZQA3LT is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Filename:</strong> {RANDOM:3}.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | 3FWHZQA3LT</p></blockquote>
<p><strong>Command:</strong> %Temp%\{RANDOM:3}.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [3FWHZQA3LT] C:\DOCUME~1\username\LOCALS~1\Temp\Qwd.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [3FWHZQA3LT] C:\DOCUME~1\username\LOCALS~1\Temp\Qwd.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;3FWHZQA3LT&#8221;=C:\DOCUME~1\username\LOCALS~1\Temp\Qwd.exe</p></blockquote>
<p><strong>Description:</strong> new variant of trojan FakeAlert that also known as Mal/FakeAV-CX [Sophos], TrojanDownloader:Win32/Renos.KF [Microsoft], Win-Trojan/Variant.183296.B [AhnLab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> or the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“3FWHZQA3LT”=-</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-3fwhzqa3lt-how-to-remove-3fwhzqa3lt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ASH24SXZ9S, How to remove ASH24SXZ9S</title>
		<link>http://htlogs.com/what-is-ash24sxz9s-how-to-remove-ash24sxz9s/</link>
		<comments>http://htlogs.com/what-is-ash24sxz9s-how-to-remove-ash24sxz9s/#comments</comments>
		<pubDate>Fri, 24 Sep 2010 17:52:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1986</guid>
		<description><![CDATA[ASH24SXZ9S is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Filename: {RANDOM:3}.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; ASH24SXZ9S Command: %Temp%\{RANDOM:3}.exe Startup Type: HKCU->Run HijackThis Category: O4 HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>ASH24SXZ9S is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Filename:</strong> {RANDOM:3}.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | ASH24SXZ9S</p></blockquote>
<p><strong>Command:</strong> %Temp%\{RANDOM:3}.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [ASH24SXZ9S] C:\DOCUME~1\username\LOCALS~1\Temp\Qwd.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [ASH24SXZ9S] C:\DOCUME~1\username\LOCALS~1\Temp\Qwd.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;ASH24SXZ9S&#8221;=C:\DOCUME~1\username\LOCALS~1\Temp\Qwd.exe</p></blockquote>
<p><strong>Description:</strong> new variant of trojan FakeAlert that also known as Mal/FakeAV-CX [Sophos], TrojanDownloader:Win32/Renos.KF [Microsoft], Win-Trojan/Variant.183296.B [AhnLab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> or the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“ASH24SXZ9S”=-</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ash24sxz9s-how-to-remove-ash24sxz9s/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is dfrgsnapnt.exe, How to remove dfrgsnapnt.exe</title>
		<link>http://htlogs.com/what-is-dfrgsnapnt-exe-how-to-remove-dfrgsnapnt-exe/</link>
		<comments>http://htlogs.com/what-is-dfrgsnapnt-exe-how-to-remove-dfrgsnapnt-exe/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 16:07:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1970</guid>
		<description><![CDATA[dfrgsnapnt.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: dfrgsnapnt Filename: dfrgsnapnt.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; dfrgsnapnt.exe Command: %TEMP%\dfrgsnapnt.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>dfrgsnapnt.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> dfrgsnapnt<br />
<strong>Filename:</strong> dfrgsnapnt.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | dfrgsnapnt.exe</p></blockquote>
<p><strong>Command:</strong> %TEMP%\dfrgsnapnt.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [dfrgsnapnt.exe] C:\WINDOWS\TEMP\dfrgsnapnt.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [dfrgsnapnt.exe] C:\WINDOWS\TEMP\dfrgsnapnt.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;dfrgsnapnt.exe&#8221;=C:\WINDOWS\TEMP\dfrgsnapnt.exe</p></blockquote>
<p><strong>Description:</strong> trojan FakeAlert</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-dfrgsnapnt-exe-how-to-remove-dfrgsnapnt-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is YXE7DXCQ37, How to remove YXE7DXCQ37</title>
		<link>http://htlogs.com/what-is-yxe7dxcq37-how-to-remove-yxe7dxcq37/</link>
		<comments>http://htlogs.com/what-is-yxe7dxcq37-how-to-remove-yxe7dxcq37/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 17:32:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1968</guid>
		<description><![CDATA[YXE7DXCQ37 is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Filename: {RANDOM:3}.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; YXE7DXCQ37 Command: %Temp%\{RANDOM:3}.exe Startup Type: HKCU->Run HijackThis Category: O4 HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>YXE7DXCQ37 is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Filename:</strong> {RANDOM:3}.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | YXE7DXCQ37</p></blockquote>
<p><strong>Command:</strong> %Temp%\{RANDOM:3}.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [YXE7DXCQ37] C:\DOCUME~1\username\LOCALS~1\Temp\Rch.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [YXE7DXCQ37] C:\DOCUME~1\username\LOCALS~1\Temp\Rch.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;YXE7DXCQ37&#8243;=C:\DOCUME~1\username\LOCALS~1\Temp\Rch.exe</p></blockquote>
<p><strong>Description:</strong> new variant of trojan FakeAlert that also known as Mal/FakeAV-CX [Sophos], TrojanDownloader:Win32/Renos.KF [Microsoft], Win-Trojan/Variant.183296.B [AhnLab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> or the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“YXE7DXCQ37”=-</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-yxe7dxcq37-how-to-remove-yxe7dxcq37/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is XBV6RD5SZF, How to remove XBV6RD5SZF</title>
		<link>http://htlogs.com/what-is-xbv6rd5szf-how-to-remove-xbv6rd5szf/</link>
		<comments>http://htlogs.com/what-is-xbv6rd5szf-how-to-remove-xbv6rd5szf/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 16:31:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1945</guid>
		<description><![CDATA[XBV6RD5SZF is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Filename: {RANDOM:3}.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; XBV6RD5SZF Command: %Temp%\{RANDOM:3}.exe Startup Type: HKCU->Run HijackThis Category: O4 HijackThis [...]]]></description>
			<content:encoded><![CDATA[<h2>XBV6RD5SZF is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Filename:</strong> {RANDOM:3}.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | XBV6RD5SZF</p></blockquote>
<p><strong>Command:</strong> %Temp%\{RANDOM:3}.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [XBV6RD5SZF] C:\DOCUME~1\username\LOCALS~1\Temp\Ude.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [XBV6RD5SZF] C:\DOCUME~1\username\LOCALS~1\Temp\Ude.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;XBV6RD5SZF&#8221;=C:\DOCUME~1\username\LOCALS~1\Temp\Ude.exe</p></blockquote>
<p><strong>Description:</strong> new variant of trojan FakeAlert that also known as Mal/FakeAV-CX [Sophos], TrojanDownloader:Win32/Renos.KF [Microsoft], Win-Trojan/Variant.183296.B [AhnLab]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a> or the steps below.</p>
<p>1. Download OTM by OldTimer from <a href="http://oldtimer.geekstogo.com/OTM.exe">here</a> and save to your desktop.<br />
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):</p>
<p><font color="grey">:reg<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“XBV6RD5SZF”=-</p>
<p>:Commands<br />
[emptytemp]<br />
[Reboot]</font></p>
<p>Click the red Moveit! button. If you are asked to reboot the machine choose Yes. When the tool is finished, it will produce a report for you.</p>
<p>2. Download <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes Anti-malware</a>. Install, perform a scan and let it remove what it found. Reboot afterwards (important).</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-xbv6rd5szf-how-to-remove-xbv6rd5szf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is defender.exe, How to remove defender.exe</title>
		<link>http://htlogs.com/what-is-defender-exe-how-to-remove-defender-exe/</link>
		<comments>http://htlogs.com/what-is-defender-exe-how-to-remove-defender-exe/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 18:16:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1918</guid>
		<description><![CDATA[defender.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: defender Filename: defender.exe Registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; tmp Command: %AppData%\defender.exe Startup Type: HKCU->Run HijackThis Category: [...]]]></description>
			<content:encoded><![CDATA[<h2>defender.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> defender<br />
<strong>Filename:</strong> defender.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | tmp</p></blockquote>
<p><strong>Command:</strong> %AppData%\defender.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [tmp] C:\Documents and Settings\comp\Application Data\defender.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [tmp] C:\Documents and Settings\comp\Application Data\defender.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;tmp&#8221;=C:\Documents and Settings\comp\Application Data\defender.exe</p></blockquote>
<p><strong>Description:</strong> core component of Microsoft Security Essentials Alert trojan</p>
<p><strong>How to remove:</strong> use the <a href="http://www.myantispyware.com/2010/08/26/how-to-remove-fake-microsoft-security-essentials-alert/">fake Microsoft Security Essentials Alert removal</a> instructions</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-defender-exe-how-to-remove-defender-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

