<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dangerous Trojan Removal Guide</title>
	<atom:link href="https://spyware-techie.com/dangerous-trojan-removal-guide/feed" rel="self" type="application/rss+xml" />
	<link>https://spyware-techie.com/dangerous-trojan-removal-guide</link>
	<description>A techie’s take on Spyware.</description>
	<lastBuildDate>Mon, 14 Oct 2024 08:58:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
	<item>
		<title>By: Cordzill</title>
		<link>https://spyware-techie.com/dangerous-trojan-removal-guide#comment-6039</link>
		<dc:creator>Cordzill</dc:creator>
		<pubDate>Thu, 12 Jun 2008 12:37:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.spyware-techie.com/dangerous-trojan-removal-guide/#comment-6039</guid>
		<description><![CDATA[Hey, 

So I had a very similar thing occur to me over the last few days, and have finally gotten rid of it. Assumably the above works fine (from the comments posted) but for those who were in my shoes, with lovely &quot;dangerous trogan&quot; messages trying to download IEAV.exe (or something around those lines), here is what I did:

1. Tracked events in Windows Defender (of all things) and found the following:

---------------------------

Description:
This program has potentially unwanted behavior.

Advice:
Permit this detected item only if you trust the program or the software publisher.

Resources:
clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{50AB4474-F8B5-4F66-BAC5-4251E765B827}

regkey:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50AB4474-F8B5-4F66-BAC5-4251E765B827}

regkey:
HKLM\SOFTWARE\CLASSES\TYPELIB\{6549E485-C533-4E58-BA92-9FBCD2F6E839}\1.0

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{50AB4474-F8B5-4F66-BAC5-4251E765B827}

bho:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50AB4474-F8B5-4F66-BAC5-4251E765B827}

typelibversion:
HKLM\SOFTWARE\CLASSES\TYPELIB\{6549E485-C533-4E58-BA92-9FBCD2F6E839}\1.0

file:
C:\WINDOWS\tupost32.dll

--------------------------------------

2. Now I am not sure if the registry info here is common for all cases, but i proceeded to open RegEdit (Start Menu --&gt; run --&gt; Regedit)

3. Find the keys above in the registry (HKLM = HKey_Local_Machine) and delete them.

4. Tupost32.dll is still in my windows folder at this stage as I am unsure of its function, however the popup warning messages have stopped.

This was done after numerous software scans which didnt seam to solve the problem. 

I hope this helps some people and makes a bit of sense. I am by no means a computer wizz, so am unaware if I have done the &#039;right&#039; thing, but have undoubtedly managed to solve the problem at hand.]]></description>
		<content:encoded><![CDATA[<p>Hey, </p>
<p>So I had a very similar thing occur to me over the last few days, and have finally gotten rid of it. Assumably the above works fine (from the comments posted) but for those who were in my shoes, with lovely "dangerous trogan" messages trying to download IEAV.exe (or something around those lines), here is what I did:</p>
<p>1. Tracked events in Windows Defender (of all things) and found the following:</p>
<p>---------------------------</p>
<p>Description:<br />
This program has potentially unwanted behavior.</p>
<p>Advice:<br />
Permit this detected item only if you trust the program or the software publisher.</p>
<p>Resources:<br />
clsid:<br />
HKLM\SOFTWARE\CLASSES\CLSID\{50AB4474-F8B5-4F66-BAC5-4251E765B827}</p>
<p>regkey:<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50AB4474-F8B5-4F66-BAC5-4251E765B827}</p>
<p>regkey:<br />
HKLM\SOFTWARE\CLASSES\TYPELIB\{6549E485-C533-4E58-BA92-9FBCD2F6E839}\1.0</p>
<p>regkey:<br />
HKLM\SOFTWARE\CLASSES\CLSID\{50AB4474-F8B5-4F66-BAC5-4251E765B827}</p>
<p>bho:<br />
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50AB4474-F8B5-4F66-BAC5-4251E765B827}</p>
<p>typelibversion:<br />
HKLM\SOFTWARE\CLASSES\TYPELIB\{6549E485-C533-4E58-BA92-9FBCD2F6E839}\1.0</p>
<p>file:<br />
C:\WINDOWS\tupost32.dll</p>
<p>--------------------------------------</p>
<p>2. Now I am not sure if the registry info here is common for all cases, but i proceeded to open RegEdit (Start Menu --&gt; run --&gt; Regedit)</p>
<p>3. Find the keys above in the registry (HKLM = HKey_Local_Machine) and delete them.</p>
<p>4. Tupost32.dll is still in my windows folder at this stage as I am unsure of its function, however the popup warning messages have stopped.</p>
<p>This was done after numerous software scans which didnt seam to solve the problem. </p>
<p>I hope this helps some people and makes a bit of sense. I am by no means a computer wizz, so am unaware if I have done the 'right' thing, but have undoubtedly managed to solve the problem at hand.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cez</title>
		<link>https://spyware-techie.com/dangerous-trojan-removal-guide#comment-3469</link>
		<dc:creator>cez</dc:creator>
		<pubDate>Sun, 13 Apr 2008 21:32:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.spyware-techie.com/dangerous-trojan-removal-guide/#comment-3469</guid>
		<description><![CDATA[Thank you.

I didn&#039;t have safe search on in google. Clicked something by accident ended up on that icky site and was infected. Bing Bang Boom! Sheesh.  First one in almost three years!

The removal tool worked like a charm!

A note to those looking for help via google, even tho the trojan hijacks the hyperlink you can still cut and paste the url from the listing.

cez]]></description>
		<content:encoded><![CDATA[<p>Thank you.</p>
<p>I didn't have safe search on in google. Clicked something by accident ended up on that icky site and was infected. Bing Bang Boom! Sheesh.  First one in almost three years!</p>
<p>The removal tool worked like a charm!</p>
<p>A note to those looking for help via google, even tho the trojan hijacks the hyperlink you can still cut and paste the url from the listing.</p>
<p>cez</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sridhar</title>
		<link>https://spyware-techie.com/dangerous-trojan-removal-guide#comment-3446</link>
		<dc:creator>Sridhar</dc:creator>
		<pubDate>Sun, 13 Apr 2008 06:31:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.spyware-techie.com/dangerous-trojan-removal-guide/#comment-3446</guid>
		<description><![CDATA[great job done. it worked]]></description>
		<content:encoded><![CDATA[<p>great job done. it worked</p>
]]></content:encoded>
	</item>
</channel>
</rss>
