<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Trojan] Win32.EggDrop-AE  And Win32:PoeBot in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20299147</link>
<description></description>
<language>en</language>
<pubDate>Fri, 25 Jul 2008 14:04:35 EDT</pubDate>
<lastBuildDate>Fri, 25 Jul 2008 14:04:35 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] Win32.EggDrop-AE  And Win32:PoeBot</title>
<link>http://www.dslreports.com/forum/remark,20316666</link>
<description><![CDATA[<A HREF="/useremail/u/625869"><b>unhg</b></A> : I have 3 weeks left before i can good home. My laptop has to last me until i can transfer off some of my files before i can wipe out my OS.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20316666</guid>
<pubDate>Fri, 11 Apr 2008 02:20:07 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Win32.EggDrop-AE  And Win32:PoeBot</title>
<link>http://www.dslreports.com/forum/remark,20310604</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : You have XP without any Service Packs, and without any security updates.  This is in the main why you become infected. It also explains why your posts in several security Forums about this computer have been ignored.<br><br>Most of your infection is using security loopholes long closed by keeping XP up to date.<br><br>In addition, at least one of your infections is a file injector, as seen in your AVAST screenshot.<br><br>Format all drives and reinstall XP clean.  No other cleanup step should be considered.  It is time to flatten and reinstall the Operating System.<br><br>When done, Enable the firewall; install an Antivirus program, update the antivirus program.<br><br>Then head to Windows Update and install at least Service Pack 2 -- or given the timing of matters, the Release Candidate of Service Pack 3.  Install every update offered that is listed as "Critical".<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20310604</guid>
<pubDate>Wed, 09 Apr 2008 20:04:26 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Win32.EggDrop-AE  And Win32:PoeBot</title>
<link>http://www.dslreports.com/forum/remark,20299160</link>
<description><![CDATA[<A HREF="/useremail/u/625869"><b>unhg</b></A> : &raquo;<A HREF="http://img221.imageshack.us/my.php?image=helpqd5.png" >img221.imageshack.us/my.php?imag&middot;&middot;&middot;pqd5.png</A> <br><br>A pic i took from Avast.<br><br>Install AVG too and this is a screen from that<br><br>&raquo;<A HREF="http://img91.imageshack.us/my.php?image=avgsj8.png" >img91.imageshack.us/my.php?image=avgsj8.png</A><br><br>I still have this backdrop virus even tho both detects it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20299160</guid>
<pubDate>Mon, 07 Apr 2008 20:08:38 EDT</pubDate>
</item>

<item>
<title>[Trojan] Win32.EggDrop-AE  And Win32:PoeBot</title>
<link>http://www.dslreports.com/forum/remark,20299147</link>
<description><![CDATA[<A HREF="/useremail/u/625869"><b>unhg</b></A> : My avast detect both of these but avast keeps popping back up reporting the problem again after i supposely deleted it from avast.<br>Spybot didn't detect anything at all. All updated too.<br>HJ Log<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:30:49 PM, on 4/7/2008<br>Platform: Windows XP  (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 (6.00.2600.0000)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\NEW\System32\smss.exe<br>C:\WINDOWS\NEW\system32\csrss.exe<br>C:\WINDOWS\NEW\system32\winlogon.exe<br>C:\WINDOWS\NEW\system32\services.exe<br>C:\WINDOWS\NEW\system32\lsass.exe<br>C:\WINDOWS\NEW\system32\svchost.exe<br>C:\WINDOWS\NEW\System32\svchost.exe<br>C:\WINDOWS\NEW\System32\svchost.exe<br>C:\WINDOWS\NEW\System32\svchost.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\NEW\system32\spoolsv.exe<br>C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>C:\Program Files\ewido anti-malware\ewidoctrl.exe<br>C:\WINDOWS\NEW\Explorer.EXE<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe<br>C:\WINDOWS\NEW\System32\hkcmd.exe<br>C:\WINDOWS\NEW\TPPALDR.EXE<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\WINDOWS\NEW\System32\ctfmon.exe<br>C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br>C:\WINDOWS\NEW\system32\ZoneLabs\vsmon.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Trillian\trillian.exe<br>C:\Program Files\Alwil Software\Avast4\ashSimp2.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\WINDOWS\NEW\System32\wbem\wmiprvse.exe<br><br>O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Documents and Settings\ecoli2\Desktop\Freshman paper\Patch\IDMIECC.dll (file missing)<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\NEW\System32\msdxm.ocx<br>O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\NEW\System32\hkcmd.exe<br>O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\NEW\TPPALDR.EXE<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\NEW\System32\igfxtray.exe<br>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\NEW\System32\IME\PINTLGNT\ImScInst.exe /SYNC<br>O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\NEW\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\NEW\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\NEW\System32\ctfmon.exe<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br>O8 - Extra context menu item: Download All Links with IDM - C:\Documents and Settings\ecoli2\Desktop\Freshman paper\Patch\IEGetAll.htm<br>O8 - Extra context menu item: Download with IDM - C:\Documents and Settings\ecoli2\Desktop\Freshman paper\Patch\IEExt.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\NEW\web\related.htm<br>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\NEW\web\related.htm<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe<br>O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\NEW\system32\ZoneLabs\vsmon.exe<br><br>--<br>End of file - 4690 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20299147</guid>
<pubDate>Mon, 07 Apr 2008 20:07:10 EDT</pubDate>
</item>

</channel>
</rss>
