<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HT Logs. Tips, FAQs, Analyze. &#187; Virus</title>
	<atom:link href="http://htlogs.com/category/threats/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Mon, 05 Dec 2011 07:53:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>What is ansid.exe, How to remove ansid.exe</title>
		<link>http://htlogs.com/what-is-ansid-exe-how-to-remove-ansid-exe/</link>
		<comments>http://htlogs.com/what-is-ansid-exe-how-to-remove-ansid-exe/#comments</comments>
		<pubDate>Sun, 13 Dec 2009 08:20:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O23]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1195</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: ansid Filename: ansid.exe Registry key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mnmsrvcRDSessMgr Command: c:\windows\SYSTEM32\ansid.exe Startup Type: Service HijackThis Category: HijackThis Line: [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ansid<br />
<strong>Filename:</strong> ansid.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mnmsrvcRDSessMgr</p></blockquote>
<p><strong>Command:</strong> c:\windows\SYSTEM32\ansid.exe<br />
<strong>Startup Type:</strong> Service<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong><br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O23 – Service: NetMeeting Remote Desktop Sharing mnmsrvcRDSessMgr (mnmsrvcRDSessMgr) –  – C:\WINDOWS\system32\ansid.exe srv</p></blockquote>
<p><strong>DDS/<a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>R2 mnmsrvcRDSessMgr;NetMeeting Remote Desktop Sharing mnmsrvcRDSessMgr;c:\windows\SYSTEM32\ansid.exe srv</p></blockquote>
<p><strong>Description:</strong> virus also known as W32.Virut.CF [Symantec], Virus.Win32.Virut.ce [Kaspersky Lab], W32/Virut.n.gen [McAfee], W32/Scribble-B [Sophos], Virus:Win32/Virut.BM [Microsoft]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-ansid-exe-how-to-remove-ansid-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is reader_s.exe, How to remove reader_s.exe</title>
		<link>http://htlogs.com/what-is-reader_s-exe-how-to-remove-reader_s-exe/</link>
		<comments>http://htlogs.com/what-is-reader_s-exe-how-to-remove-reader_s-exe/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 05:51:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1108</guid>
		<description><![CDATA[reader_s.exe is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: reader_s Filename: reader_s.exe Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; reader_s HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; reader_s Command: %WinDir%\System32\reader_s.exe %UserProfile%\reader_s.exe Startup [...]]]></description>
			<content:encoded><![CDATA[<h2>reader_s.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> reader_s<br />
<strong>Filename:</strong> reader_s.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | reader_s<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | reader_s</p></blockquote>
<p><strong>Command:</strong></p>
<blockquote><p>%WinDir%\System32\reader_s.exe<br />
%UserProfile%\reader_s.exe</p></blockquote>
<p><strong>Startup Type:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe<br />
O4 &#8211; HKCU\..\Run: [reader_s] C:\Documents and Settings\user\reader_s.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [[reader_s] C:\WINDOWS\System32\reader_s.exe<br />
uRun: [[reader_s] C:\Documents and Settings\user\reader_s.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;reader_s&#8221;=C:\WINDOWS\System32\reader_s.exe<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;reader_s&#8221;=C:\Documents and Settings\user\reader_s.exe</p></blockquote>
<p><strong>Description:</strong> component of Virut virus also known as W32.Virut.CF [Symantec], W32/Scribble-B [Sophos], Virus.Win32.Virut.ce [Kaspersky Lab], Virus:Win32/Virut.BM [Microsoft], W32/Virut.n.gen [McAfee]</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2009/03/26/how-to-use-kaspersky-virus-removal-tool/">Kaspersky virus removal tool</a> + <a href="http://www.myantispyware.com/2007/11/10/drweb-cureit-a-free-anti-malware-utility/">Dr.Web CureIt</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-reader_s-exe-how-to-remove-reader_s-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sopidkc.exe is a virus</title>
		<link>http://htlogs.com/sopidkcexe-is-a-virus/</link>
		<comments>http://htlogs.com/sopidkcexe-is-a-virus/#comments</comments>
		<pubDate>Sun, 28 Jun 2009 03:01:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O23]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=575</guid>
		<description><![CDATA[This is a harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: sopidkc Filename: sopidkc.exe Command: C:\WINDOWS\system32\sopidkc.exe Startup Type: Service HijackThis Category: O23 HijackThis Line: O23 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>This is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> sopidkc<br />
<strong>Filename:</strong> sopidkc.exe<br />
<strong>Command:</strong> C:\WINDOWS\system32\sopidkc.exe<br />
<strong>Startup Type:</strong> Service<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O23<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O23 &#8211; Service: sopidkc Service (sopidkc) &#8211; Elecard Lt &#8211; C:\WINDOWS\system32\sopidkc.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>R2 sopidkc;sopidkc Service; C:\WINDOWS\system32\sopidkc.exe [2004-08-18 124928]</p></blockquote>
<p><strong>Description:</strong> Virus, identified as Backdoor:Win32/Refpron.gen!C [Microsoft], Troj/Comsa-C [Sophos], New Win32 [McAfee], Packed.Win32.Koblu.b [Kaspersky Lab]</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/sopidkcexe-is-a-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>lkxcqdb.bat is a component of autorun.inf virus</title>
		<link>http://htlogs.com/lkxcqdbbat-is-a-component-of-autoruninf-virus/</link>
		<comments>http://htlogs.com/lkxcqdbbat-is-a-component-of-autoruninf-virus/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 06:00:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=194</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: lkxcqdb Filename: lkxcqdb.bat Command: E:\lkxcqdb.bat CLSID: {df709192-1538-11dd-bc9a-0011675aabad} Startup Type: autorun.inf [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df709192-1538-11dd-bc9a-0011675aabad}] shell\AutoRun\command &#8211; E:\lkxcqdb.bat shell\explore\command [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> lkxcqdb<br />
<strong>Filename:</strong> lkxcqdb.bat<br />
<strong>Command:</strong> E:\lkxcqdb.bat<br />
<strong>CLSID:</strong> {df709192-1538-11dd-bc9a-0011675aabad}<br />
<strong>Startup Type:</strong> autorun.inf</p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df709192-1538-11dd-bc9a-0011675aabad}]<br />
shell\AutoRun\command &#8211; E:\lkxcqdb.bat<br />
shell\explore\command &#8211; E:\lkxcqdb.bat<br />
shell\open\command &#8211; E:\lkxcqdb.bat</p></blockquote>
<p><strong>Description:</strong> component of autorun.inf virus</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">How to remove lkxcqdb.bat &#8211; trojan that uses autorun.inf file</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/lkxcqdbbat-is-a-component-of-autoruninf-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>gy.cmd is a component of autorun.inf virus</title>
		<link>http://htlogs.com/gycmd-is-a-component-of-autoruninf-virus/</link>
		<comments>http://htlogs.com/gycmd-is-a-component-of-autoruninf-virus/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 05:57:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=190</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: gy Filename: gy.cmd CLSID: {b75b8d74-94b1-11dc-bb7c-00c09fcd8ea0} Startup Type: autorun.inf [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b75b8d74-94b1-11dc-bb7c-00c09fcd8ea0}] shell\AutoRun\command &#8211; gy.cmd shell\explore\command &#8211; gy.cmd [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> gy<br />
<strong>Filename:</strong> gy.cmd<br />
<strong>CLSID:</strong> {b75b8d74-94b1-11dc-bb7c-00c09fcd8ea0}<br />
<strong>Startup Type:</strong> autorun.inf</p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b75b8d74-94b1-11dc-bb7c-00c09fcd8ea0}]<br />
shell\AutoRun\command &#8211; gy.cmd<br />
shell\explore\command &#8211; gy.cmd<br />
shell\open\command &#8211; gy.cmd</p></blockquote>
<p><strong>Description:</strong> component of autorun.inf virus</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">How to remove gy.cmd &#8211; trojan that uses autorun.inf file</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/gycmd-is-a-component-of-autoruninf-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>itsduel.exe is a component of autorun.inf virus</title>
		<link>http://htlogs.com/itsduelexe-is-a-component-of-autoruninf-virus/</link>
		<comments>http://htlogs.com/itsduelexe-is-a-component-of-autoruninf-virus/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 05:52:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus]]></category>
		<category><![CDATA[autorun.inf]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=188</guid>
		<description><![CDATA[This is an harmful program. It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. Name: itsduel Filename: itsduel.exe Command: E:\itsduel.exe CLSID: {98ffd239-a6ee-11dd-bd91-00c09fcd8ea0} Startup Type: autorun.inf Combofix/RSIT Line: [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98ffd239-a6ee-11dd-bd91-00c09fcd8ea0}] shell\AutoRun\command &#8211; [...]]]></description>
			<content:encoded><![CDATA[<h2>This is an harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> itsduel<br />
<strong>Filename:</strong> itsduel.exe<br />
<strong>Command:</strong> E:\itsduel.exe<br />
<strong>CLSID:</strong> {98ffd239-a6ee-11dd-bd91-00c09fcd8ea0}<br />
<strong>Startup Type:</strong> autorun.inf<br />
<strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98ffd239-a6ee-11dd-bd91-00c09fcd8ea0}]<br />
shell\AutoRun\command &#8211; E:\itsduel.exe<br />
shell\explore\command &#8211; E:\itsduel.exe<br />
shell\open\command &#8211; E:\itsduel.exe</p></blockquote>
<p><strong>Description:</strong> component of autorun.inf virus</p>
<p><strong>How to remove:</strong> <a href="http://www.myantispyware.com/2008/05/26/how-to-remove-trojans-that-uses-autoruninf-file/">How to remove itsduel.exe &#8211; trojan that uses autorun.inf file</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/itsduelexe-is-a-component-of-autoruninf-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

