Question

WINPUP32.EXE

Asked by: rhino31

I realize this question has been asked all ready, or one like it, however, I'm wondering how to get this trojan horse off my computer.  is this torjan horse just a pop-up spreader, or is this a pass word stealer?  I'm having a hell of a time deleting it

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2003-06-11 at 20:44:57ID20645367
Topic

Miscellaneous

Participating Experts
6
Points
125
Comments
11

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Trojan horse
    Trojan horse Downloader.Q I have a window that pops up saying I have this Downloader. Q down.C in C:\System Volume. I ran my avg and it says it deleted it. What can I do to get this window to go away.
  2. Possible Trojan: CSRSS.EXE
    Very unusual situation. I have just talked to the technical folks at Webroot whose product, SpySweeper, does not detect the following during a sweep; but, in the midst of my doinb work (Word, etc.) on the PC an alert pops up regarding: csrss.exe. I did a search on my PC an...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: CrazyOnePosted on 2003-06-11 at 20:46:52ID: 8705282

 

by: CrazyOnePosted on 2003-06-11 at 20:47:53ID: 8705290

And this ungoing question here at EE http://www.experts-exchange.com/Security/Q_20641756.html

 

by: war1Posted on 2003-06-11 at 20:54:11ID: 8705317

Greetings, rhino31!
   This may help you.

http://www.experts-exchange.com/Miscellaneous/New_Net_Users/Q_20640277.html

Accepted answer from spiderfix

>>Is it still a BHO exploit?<<
http://www.tomcoyote.org/hjt/
"HiJack This" will scan and show all BHO exploits.

>>it was not a porn site<<
Yup, that's quite a rude page that install.php
Don't forget there is no way for you to see the actual source code for that install.php page,
just the served html portion. The VB code link in winpup32.exe is porn.


undergroundlair.net and smokeandapancake.org are the same owner (same fake info registered)
I can only speculate because I don't have all the php code but my guess would be two scenarios;

1) martylikes*******.com wrote (or owns) the code for the winpup32.exe and the
undergroundlair.net/smokeandapancake.org guy runs it. In porn it works this way
because marty...com is a sponsor and the other guy gets paid if people sign up
through the link. More than likely it's what's called a dialer. Forced porn downloads
are usually dialers. (dialers use your modem for $7.00 per minute charges)

2) marty....com and the other sites are the same person.

#2 not very likely though, the repetitive iframe call on the winupup32.exe is pretty ridiculous.
Forced stuff is usually in stealth mode (written so the user has no idea something is going on),
this "machine gun" of download windows is the opposite of stealth. So the person who wrote
the VB winpup32.exe is smarter than the person who wrote the install.php

winpup32.exe is VB code compiled to *.exe, it may be a dialer or it may just be a popup generator.
I would probably think it's a dialer (because it's related to porn) because that's what that industry has
been offering as *.exe(s) for awhile now.

Either way it's still an *.exe and there is no danger for anyone unless the download it and click on it.
The worst anyone gets is the machine gun page.


Best wishes, war1

 

by: rhino31Posted on 2003-06-11 at 21:01:54ID: 8705342

I downloaded adaware 6.0, and I ran it, but it said that certain files could not be deleted.  so the same question goes, how do I get this thing off my computer, and is it just a pop up machine gun, or a pass word theif?  

 

by: war1Posted on 2003-06-11 at 21:31:32ID: 8705488

rhino31,
   Adaware is only one of the tools for removing adware. Did you try this tool

http://www.tomcoyote.org/hjt/

It a BHO remover.

Here is a website that discusses many aspects of spyware.

http://www.cexx.org/adware.htm

Look at "General strategies for neutering Ad/Spyware".

If there is a program that is bothering you, and you cannot get rid of it, post a note in the "Discussion Forums", and one of the spyware specialists will look at it and make a recommendation.

Also, make sure programs cannot just download on your computer without your permission.  From the Internet Toolbar, go to Tools > Internet Options > Advanced.  Make sure "Enable Install On Demand (Internet Explorer)" and "Enable Install On Demand (Other)" are unchecked.

 

by: spiderfixPosted on 2003-06-11 at 21:33:58ID: 8705502

The process is running that's why it can't be deleted.

Your suppose to run HiJackThis and Spybot (or Ad-aware) from safe mode.

You have to manually take the call for it out of msconfig startup after you've done the two scans.

HiJackThis
http://www.tomcoyote.org/hjt/
Spybot S&D
http://security.kolla.de/index.php?lang=en&page=download

Both these programs have the ability to update. Update them both before scanning.

 

by: kenesoPosted on 2003-06-12 at 02:44:42ID: 8707117

You may need to manually remove some left over files, and to clean the registry.
Many of these malwares do put an exe in the temp folder, and in the system folder.
The reason adaware can't clean them is as spiderfix said because the system is using it.

Sometimes if you run adaware, spybot, and hijackthis, and then reboot and rerun them they can get rid of the malware.
Otherwise follow the manual removal instructions.

You can check my post on this
http://www.experts-exchange.com/Miscellaneous/New_Net_Users/Q_20616106.html

You also can look at

www.cexx.org
has detailed info for removal of the malware
has also links to download
adaware
spybot
highjackthis

which in combination should get rid of the problem

You may want to take a look at the following.
They are about malware, maybe one of the ones annoying you is there.
Anyhow in a couple I detail how to edit the registry for your kind of problem

http://www.experts-exchange.com/Miscellaneous/Q_20512586.html
http://www.experts-exchange.com/Applications/Q_20583091.html
http://www.experts-exchange.com/Operating_Systems/Q_20583731.html

to download

adaware
http://www.lavasoftusa.com

spybot
http://security.kolla.de

highjackthis
http://www.tomcoyote.org/hjt/#introduction

 

by: tazzy52Posted on 2003-06-12 at 08:33:30ID: 8709817

http://www.the-it-mercenary.com/forums/Windows98/posts/1973.html  This link tells you to go and do online virus scan by mcafee.  Says you may have backdoor virus and links to a symantec virus definition

 

by: war1Posted on 2003-06-17 at 22:32:24ID: 8746551

rhino31,
   We have not heard from you in awhile? Did any comment help you solve your problem? Do you have any more questions? If an Expert help you, please accept his/her answer and provide him with an excellent or good grade.

Thanks, war1

 

by: MASQUERAIDPosted on 2004-02-08 at 05:33:13ID: 10302881

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
No comment has been added lately, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question is:

Split between CrazyOne, War1 & spiderfix


Please leave any comments here within the next four (4) days.

PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!

MASQUERAID
EE Cleanup Volunteer - Miscellaneous TA

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...