<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>HT Logs. Tips, FAQs, Analyze.</title>
	
	<link>http://htlogs.com</link>
	<description>HIJACKTHIS ITEMS/REGISTRY ITEMS/HOW TO REMOVE</description>
	<lastBuildDate>Sun, 21 Mar 2010 18:35:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/htlogs" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="htlogs" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>What is diskperfxp.exe, How to remove diskperfxp.exe</title>
		<link>http://htlogs.com/what-is-diskperfxp-exe-how-to-remove-diskperfxp-exe/</link>
		<comments>http://htlogs.com/what-is-diskperfxp-exe-how-to-remove-diskperfxp-exe/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 18:35:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1554</guid>
		<description><![CDATA[diskperfxp.exe is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: diskperfxp
Filename: diskperfxp.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; diskperfxp.exe
Command: %UserProfile%\LOCALS~1\Temp\diskperfxp.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [diskperfxp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\diskperfxp.exe
DDS Line:
uRun: [diskperfxp.exe] [...]]]></description>
			<content:encoded><![CDATA[<h2>diskperfxp.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> diskperfxp<br />
<strong>Filename:</strong> diskperfxp.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | diskperfxp.exe</p></blockquote>
<p><strong>Command:</strong> %UserProfile%\LOCALS~1\Temp\diskperfxp.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [diskperfxp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\diskperfxp.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [diskperfxp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\diskperfxp.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;diskperfxp.exe&#8221;=C:\DOCUME~1\user\LOCALS~1\Temp\diskperfxp.exe</p></blockquote>
<p><strong>Description:</strong> trojan fakeAlert that displays a lot fake security alerts and downloads and installs User Protection onto your computer. User Protection is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/03/19/how-to-remove-user-protection-uninstall-instructions/">User Protection removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-diskperfxp-exe-how-to-remove-diskperfxp-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is zipdkg32.exe, How to remove zipdkg32.exe</title>
		<link>http://htlogs.com/what-is-zipdkg32-exe-how-to-remove-zipdkg32-exe/</link>
		<comments>http://htlogs.com/what-is-zipdkg32-exe-how-to-remove-zipdkg32-exe/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 07:46:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Startup folder]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1552</guid>
		<description><![CDATA[zipdkg32.exe is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: zipdkg32
Filename: zipdkg32.exe
Command: c:\documents and settings\user\start menu\programs\startup\zipdkg32.exe
Startup Type: Startup folder
HijackThis Category: O4
HijackThis Line:
O4 &#8211; Startup: zipdkg32.exe
DDS Line:
StartupFolder: c:\documents [...]]]></description>
			<content:encoded><![CDATA[<h2>zipdkg32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> zipdkg32<br />
<strong>Filename:</strong> zipdkg32.exe<br />
<strong>Command:</strong> c:\documents and settings\user\start menu\programs\startup\zipdkg32.exe<br />
<strong>Startup Type:</strong> Startup folder<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; Startup: zipdkg32.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>StartupFolder: c:\documents and settings\user\start menu\programs\startup\zipdkg32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>C:\Documents and Settings\user\Start Menu\Programs\Startup<br />
zipdkg32.exe</p></blockquote>
<p><strong>Description:</strong> trojan</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-zipdkg32-exe-how-to-remove-zipdkg32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is WEK9EMDHI9, How to remove WEK9EMDHI9</title>
		<link>http://htlogs.com/what-is-wek9emdhi9-how-to-remove-wek9emdhi9/</link>
		<comments>http://htlogs.com/what-is-wek9emdhi9-how-to-remove-wek9emdhi9/#comments</comments>
		<pubDate>Sat, 20 Mar 2010 19:42:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1550</guid>
		<description><![CDATA[WEK9EMDHI9 is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: WEK9EMDHI9
Filename: [ranndom].exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; WEK9EMDHI9
Command: C:\WINDOWS\Bhihuc.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [WEK9EMDHI9] C:\WINDOWS\Bhihuc.exe
DDS Line:
uRun: [WEK9EMDHI9] [...]]]></description>
			<content:encoded><![CDATA[<h2>WEK9EMDHI9 is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> WEK9EMDHI9<br />
<strong>Filename:</strong> [ranndom].exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | WEK9EMDHI9</p></blockquote>
<p><strong>Command:</strong> C:\WINDOWS\Bhihuc.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [WEK9EMDHI9] C:\WINDOWS\Bhihuc.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [WEK9EMDHI9] C:\WINDOWS\Bhihuc.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;WEK9EMDHI9&#8243;=C:\WINDOWS\Bhihuc.exe [2010-03-15 40448]</p></blockquote>
<p><strong>Description:</strong> trojan FakeAlert</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-wek9emdhi9-how-to-remove-wek9emdhi9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is usrprot.exe, How to remove usrprot.exe</title>
		<link>http://htlogs.com/what-is-usrprot-exe-how-to-remove-usrprot-exe/</link>
		<comments>http://htlogs.com/what-is-usrprot-exe-how-to-remove-usrprot-exe/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 18:29:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>
		<category><![CDATA[Run]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1547</guid>
		<description><![CDATA[usrprot.exe is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: usrprot
Filename: usrprot.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; User Protection
Command: C:\Program Files\User Protection\usrprot.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [User [...]]]></description>
			<content:encoded><![CDATA[<h2>usrprot.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> usrprot<br />
<strong>Filename:</strong> usrprot.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | User Protection</p></blockquote>
<p><strong>Command:</strong> C:\Program Files\User Protection\usrprot.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKCU\..\Run: [User Protection] “C:\Program Files\User Protection\usrprot.exe” -noscan</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [User Protection] C:\Program Files\User Protection\usrprot.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p><[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
"User Protection"=C:\Program Files\User Protection\usrprot.exe</p></blockquote>
<p><strong>Description:</strong> core component of User Protection. User Protection is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/03/19/how-to-remove-user-protection-uninstall-instructions/">User Protection removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-usrprot-exe-how-to-remove-usrprot-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is msnfo32.exe, How to remove msnfo32.exe</title>
		<link>http://htlogs.com/what-is-msnfo32-exe-how-to-remove-msnfo32-exe/</link>
		<comments>http://htlogs.com/what-is-msnfo32-exe-how-to-remove-msnfo32-exe/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 19:45:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1542</guid>
		<description><![CDATA[msnfo32.exe is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: msnfo32
Filename: msnfo32.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; msnfo32
Command: %WinDir%\system32\msnfo32.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 &#8211; HKLM\..\Run: [msnfo32] C:\WINDOWS\system32\msnfo32.exe
DDS Line:
mRun: [msnfo32] [...]]]></description>
			<content:encoded><![CDATA[<h2>msnfo32.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> msnfo32<br />
<strong>Filename:</strong> msnfo32.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | msnfo32</p></blockquote>
<p><strong>Command:</strong> %WinDir%\system32\msnfo32.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKLM\..\Run: [msnfo32] C:\WINDOWS\system32\msnfo32.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [msnfo32] C:\WINDOWS\system32\msnfo32.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;msnfo32&#8243;=C:\WINDOWS\system32\msnfo32.exe</p></blockquote>
<p><strong>Description:</strong> trojan also known as trojan agent</p>
<p><strong>How to remove:</strong> use <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> + <a href="http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/">Malwarebytes` Anti-malware</a></p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-msnfo32-exe-how-to-remove-msnfo32-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is bill104.exe, How to remove bill104.exe</title>
		<link>http://htlogs.com/what-is-bill104-exe-how-to-remove-bill104-exe/</link>
		<comments>http://htlogs.com/what-is-bill104-exe-how-to-remove-bill104-exe/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 16:07:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1540</guid>
		<description><![CDATA[bill104.exe is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: bill104
Filename: bill104.exe
Registry key:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &#124; sysfbtray
Command: %Windir%\bill104.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sysfbtray] C:\windows\bill104.exe
DDS Line:
mRun: [sysfbtray] [...]]]></description>
			<content:encoded><![CDATA[<h2>bill104.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> bill104<br />
<strong>Filename:</strong> bill104.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sysfbtray</p></blockquote>
<p><strong>Command:</strong> %Windir%\bill104.exe<br />
<strong>Startup Type:</strong> HKLM->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 – HKLM\..\Run: [sysfbtray] C:\windows\bill104.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>mRun: [sysfbtray] C:\windows\bill104.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“sysfbtray”=C:\windows\bill104.exe</p></blockquote>
<p><strong>Description:</strong> new variant of koobface worm</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2009/11/22/how-to-remove-koobface-worm/">koobface removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-bill104-exe-how-to-remove-bill104-exe/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>What is eventtriggersxp.exe, How to remove eventtriggersxp.exe</title>
		<link>http://htlogs.com/what-is-eventtriggersxp-exe-how-to-remove-eventtriggersxp-exe/</link>
		<comments>http://htlogs.com/what-is-eventtriggersxp-exe-how-to-remove-eventtriggersxp-exe/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 14:40:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[O4]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1538</guid>
		<description><![CDATA[eventtriggersxp.exe is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: eventtriggersxp
Filename: eventtriggersxp.exe
Registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run &#124; eventtriggersxp.exe
Command: %Temp%\eventtriggersxp.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 &#8211; HKCU\..\Run: [eventtriggersxp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\eventtriggersxp.exe
DDS Line:
uRun: [eventtriggersxp.exe] [...]]]></description>
			<content:encoded><![CDATA[<h2>eventtriggersxp.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> eventtriggersxp<br />
<strong>Filename:</strong> eventtriggersxp.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | eventtriggersxp.exe</p></blockquote>
<p><strong>Command:</strong> %Temp%\eventtriggersxp.exe<br />
<strong>Startup Type:</strong> HKCU->Run<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Category:</strong> O4<br />
<strong><a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/">HijackThis</a> Line:</strong></p>
<blockquote><p>O4 &#8211; HKCU\..\Run: [eventtriggersxp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\eventtriggersxp.exe</p></blockquote>
<p><strong>DDS Line:</strong></p>
<blockquote><p>uRun: [eventtriggersxp.exe] C:\DOCUME~1\user\LOCALS~1\Temp\eventtriggersxp.exe</p></blockquote>
<p><strong><a href="http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/">Combofix</a>/RSIT Line:</strong></p>
<blockquote><p>[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
“eventtriggersxp.exe”=C:\DOCUME~1\user\LOCALS~1\Temp\eventtriggersxp.exe</p></blockquote>
<p><strong>Description:</strong> trojan fakeAlert that once started will display a lot of fake security alerts and will suggest to download and install Dr. Guard. Dr. Guard is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/02/28/how-to-remove-dr-guard-uninstall-instructions/">Dr. Guard removal</a> instructions in order to remove Dr. Guard and the eventtriggersxp.exe trojan fakealert.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-eventtriggersxp-exe-how-to-remove-eventtriggersxp-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ave.exe – Total Vista Security, Vista Security Tool 2010</title>
		<link>http://htlogs.com/ave-exe-total-vista-security-vista-security-tool-2010/</link>
		<comments>http://htlogs.com/ave-exe-total-vista-security-vista-security-tool-2010/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 17:56:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[File associations]]></category>
		<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1536</guid>
		<description><![CDATA[ave.exe is a harmful program.



It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


Name: ave
Filename: ave.exe
Registry key:
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\secfile
Command: %Appdata%\ave.exe
Startup Type: File associations
Description: core component of Total Vista Security (Vista Security Tool 2010). [...]]]></description>
			<content:encoded><![CDATA[<h2>ave.exe is a harmful program.</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>It is a component of malware or spyware, you should immediately remove it using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>Name:</strong> ave<br />
<strong>Filename:</strong> ave.exe<br />
<strong>Registry key:</strong></p>
<blockquote><p>HKEY_CURRENT_USER\Software\Classes\.exe<br />
HKEY_CURRENT_USER\Software\Classes\secfile</p></blockquote>
<p><strong>Command:</strong> %Appdata%\ave.exe<br />
<strong>Startup Type:</strong> File associations<br />
<strong>Description:</strong> core component of Total Vista Security (Vista Security Tool 2010). Total Vista Security (Vista Security Tool 2010) is a rogue antispyware program.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/03/19/how-to-remove-ave-exe-malware/">ave.exe removal</a> instructions.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/ave-exe-total-vista-security-vista-security-tool-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is infoprotector.net, How to remove infoprotector.net</title>
		<link>http://htlogs.com/what-is-infoprotector-net-how-to-remove-infoprotector-net/</link>
		<comments>http://htlogs.com/what-is-infoprotector-net-how-to-remove-infoprotector-net/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 20:18:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1534</guid>
		<description><![CDATA[infoprotector.net is a malicious website



The site was created to spread Antivirus Soft. If your browser is redirected to infoprotector.net, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


IP Address: 195.88.190.54
Site addess: infoprotector.net
Description: infoprotector.net is not related [...]]]></description>
			<content:encoded><![CDATA[<h2>infoprotector.net is a malicious website</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>The site was created to spread Antivirus Soft. If your browser is redirected to infoprotector.net, then you should immediately check your PC using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>IP Address:</strong> 195.88.190.54<br />
<strong>Site addess:</strong> infoprotector.net<br />
<strong>Description:</strong> infoprotector.net is not related with legitimate security company and can only be seen on infected computers. The site used to promote the rogue antispyware program called THREATNAME.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/01/30/how-to-remove-antivirus-soft-uninstall-instructions/">Antivirus Soft removal</a> instructions in order to remove this infection.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-infoprotector-net-how-to-remove-infoprotector-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Info-protector.com, How to remove Info-protector.com</title>
		<link>http://htlogs.com/what-is-info-protector-com-how-to-remove-info-protector-com/</link>
		<comments>http://htlogs.com/what-is-info-protector-com-how-to-remove-info-protector-com/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 20:14:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Rogue Antispyware/Antivirus]]></category>

		<guid isPermaLink="false">http://htlogs.com/?p=1532</guid>
		<description><![CDATA[Info-protector.com is a malicious website



The site was created to spread Antivirus Soft. If your browser is redirected to Info-protector.com, then you should immediately check your PC using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum. 


IP Address: 79.135.152.5
Site addess: Info-protector.com
Description: Info-protector.com is not related [...]]]></description>
			<content:encoded><![CDATA[<h2>Info-protector.com is a malicious website</h2>
<table cellpading=0 cellspacing=0 border=0>
<tr>
<td><img src="http://htlogs.com/wp-content/uploads/2009/01/remove-icon-80.jpg" alt="remove" title="remove-icon-80" width="80" height="79" class="size-full wp-image-16" /></td>
<td>The site was created to spread Antivirus Soft. If your browser is redirected to Info-protector.com, then you should immediately check your PC using an <a href="http://www.myantispyware.com/free-programs/">antivirus</a> and <a href="http://www.myantispyware.com/free-programs/">antispyware</a> program.<br />
If that does not help, then ask us for help in the <a href="http://myantispyware.com/forum/spyware-removal-f4.html">Spyware removal forum</a>. </td>
</tr>
</table>
<p><strong>IP Address:</strong> 79.135.152.5<br />
<strong>Site addess:</strong> Info-protector.com<br />
<strong>Description:</strong> Info-protector.com is not related with legit Security company and can only be seen on infected computers. The site used to promote the rogue antispyware program called Antivirus Soft.</p>
<p><strong>How to remove:</strong> use these <a href="http://www.myantispyware.com/2010/01/30/how-to-remove-antivirus-soft-uninstall-instructions/">Antivirus Soft removal</a> instructions in order to remove this infection.</p>
]]></content:encoded>
			<wfw:commentRss>http://htlogs.com/what-is-info-protector-com-how-to-remove-info-protector-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
