And this ungoing question here at EE http://www.experts-exchang
Main Topics
Browse All TopicsI realize this question has been asked all ready, or one like it, however, I'm wondering how to get this trojan horse off my computer. is this torjan horse just a pop-up spreader, or is this a pass word stealer? I'm having a hell of a time deleting it
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
And this ungoing question here at EE http://www.experts-exchang
Greetings, rhino31!
This may help you.
http://www.experts-exchang
Accepted answer from spiderfix
>>Is it still a BHO exploit?<<
http://www.tomcoyote.org/h
"HiJack This" will scan and show all BHO exploits.
>>it was not a porn site<<
Yup, that's quite a rude page that install.php
Don't forget there is no way for you to see the actual source code for that install.php page,
just the served html portion. The VB code link in winpup32.exe is porn.
undergroundlair.net and smokeandapancake.org are the same owner (same fake info registered)
I can only speculate because I don't have all the php code but my guess would be two scenarios;
1) martylikes*******.com wrote (or owns) the code for the winpup32.exe and the
undergroundlair.net/smokea
because marty...com is a sponsor and the other guy gets paid if people sign up
through the link. More than likely it's what's called a dialer. Forced porn downloads
are usually dialers. (dialers use your modem for $7.00 per minute charges)
2) marty....com and the other sites are the same person.
#2 not very likely though, the repetitive iframe call on the winupup32.exe is pretty ridiculous.
Forced stuff is usually in stealth mode (written so the user has no idea something is going on),
this "machine gun" of download windows is the opposite of stealth. So the person who wrote
the VB winpup32.exe is smarter than the person who wrote the install.php
winpup32.exe is VB code compiled to *.exe, it may be a dialer or it may just be a popup generator.
I would probably think it's a dialer (because it's related to porn) because that's what that industry has
been offering as *.exe(s) for awhile now.
Either way it's still an *.exe and there is no danger for anyone unless the download it and click on it.
The worst anyone gets is the machine gun page.
Best wishes, war1
rhino31,
Adaware is only one of the tools for removing adware. Did you try this tool
http://www.tomcoyote.org/h
It a BHO remover.
Here is a website that discusses many aspects of spyware.
http://www.cexx.org/adware
Look at "General strategies for neutering Ad/Spyware".
If there is a program that is bothering you, and you cannot get rid of it, post a note in the "Discussion Forums", and one of the spyware specialists will look at it and make a recommendation.
Also, make sure programs cannot just download on your computer without your permission. From the Internet Toolbar, go to Tools > Internet Options > Advanced. Make sure "Enable Install On Demand (Internet Explorer)" and "Enable Install On Demand (Other)" are unchecked.
The process is running that's why it can't be deleted.
Your suppose to run HiJackThis and Spybot (or Ad-aware) from safe mode.
You have to manually take the call for it out of msconfig startup after you've done the two scans.
HiJackThis
http://www.tomcoyote.org/h
Spybot S&D
http://security.kolla.de/i
Both these programs have the ability to update. Update them both before scanning.
You may need to manually remove some left over files, and to clean the registry.
Many of these malwares do put an exe in the temp folder, and in the system folder.
The reason adaware can't clean them is as spiderfix said because the system is using it.
Sometimes if you run adaware, spybot, and hijackthis, and then reboot and rerun them they can get rid of the malware.
Otherwise follow the manual removal instructions.
You can check my post on this
http://www.experts-exchang
You also can look at
www.cexx.org
has detailed info for removal of the malware
has also links to download
adaware
spybot
highjackthis
which in combination should get rid of the problem
You may want to take a look at the following.
They are about malware, maybe one of the ones annoying you is there.
Anyhow in a couple I detail how to edit the registry for your kind of problem
http://www.experts-exchang
http://www.experts-exchang
http://www.experts-exchang
to download
adaware
http://www.lavasoftusa.com
spybot
http://security.kolla.de
highjackthis
http://www.tomcoyote.org/h
http://www.the-it-mercenar
++++++++++++++++++++++++++
No comment has been added lately, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question is:
Split between CrazyOne, War1 & spiderfix
Please leave any comments here within the next four (4) days.
PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!
MASQUERAID
EE Cleanup Volunteer - Miscellaneous TA
Business Accounts
Answer for Membership
by: CrazyOnePosted on 2003-06-11 at 20:46:52ID: 8705282
Check this out
exec/forum /winme/t10 54312380
http://www.annoyances.org/