Announcement

Collapse
No announcement yet.

PUP.exe?????

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • PUP.exe?????

    Further to the previous post re: pup.exe. I also have the problem where i get this error when trying to play media player. I tried to follow the msconfig method detailed but couldn't find any reference to pup.exe. I had found a lycos adware file that I deleted. Can anyone help me?

  • #2
    Find the file itself and delete it.

    Comment


    • #3
      Originally posted by Yawgm0th
      Find the file itself and delete it.
      What file am I looking to delete? I've got it too and its driving me nuts.

      Comment


      • #4
        Pup.exe
        ......
        :roll:
        : omg:

        Comment


        • #5
          ok i have the same problem i've found pup when i did a windows search and deleted it it comes right back... its not on my startup list in msconfig and its not on my processes list when i hit ctrl alt dlt, i have spy sweeper ad aware, spybot, hijak this, and zone alarm, none of which found this file, i've tried to delete it like 5 times and it just comes back... i'm ready to reinstall windows.

          Comment


          • #6
            i also have avg anti virus... and i selected the file pup.exe i tried putting it in the virus vault it came back, i healed it, it did nothing, and i had that delete it and it still is in my windows folder... i don't even know how i got this thing at one point in time i had a million pop ups and download boxes maybe it came from them i dont' know but i need to get rid of it...

            Comment


            • #7
              i also have avg anti virus... and i selected the file pup.exe i tried putting it in the virus vault it came back, i healed it, it did nothing, and i had that delete it and it still is in my windows folder... i don't even know how i got this thing at one point in time i had a million pop ups and download boxes maybe it came from them i dont' know but i need to get rid of it...

              Comment


              • #8
                There was a point in time where I wouldn't have helped simply because you just triple-posted, but these forums have gone to Hell anyway....

                There might be ather files associated with pup.exe that recreate it. Post your log of hijack this.

                Comment


                • #9
                  Sorry for the tripple post i only meant to post it twice cuz i forgot to mention something be4 some how three came out but w/e here's my hijack this log... also my computer now takes like 2minutes to open something i don't know whats going on it starts up everythings fine i click on something and it has the busy icon then it goes away i don't hear any loading or anything then 2 minutes later everything i clicked on pops up anyways here it is its long thanks for helping me sorry again for the tripple post.

                  Logfile of HijackThis v1.97.7
                  Scan saved at 12:35:08 AM, on 4/20/2004
                  Platform: Windows XP SP1 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\System32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\System32\TCAUDIAG.exe
                  C:\Program Files\ASUS\Probe\AsusProb.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Rage3DTweak\RegTwk.exe
                  C:\Program Files\Support.com\bin\tgcmd.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                  C:\Program Files\ICQLite\ICQLite.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\program files\steam\steam.exe
                  C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                  C:\Program Files\rage3dtweak\gameutil.exe
                  C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  C:\WINDOWS\System32\cisvc.exe
                  C:\WINDOWS\System32\inetsrv\inetinfo.exe
                  C:\WINDOWS\System32\tcpsvcs.exe
                  C:\WINDOWS\System32\snmp.exe
                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  C:\WINDOWS\System32\mqsvc.exe
                  C:\WINDOWS\System32\mqtgsvc.exe
                  C:\Program Files\AIM95\aim.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\WINDOWS\System32\taskmgr.exe
                  C:\Documents and Settings\Jarrett Sylvester\Desktop\HijackThis.exe
                  C:\WINDOWS\System32\cidaemon.exe
                  C:\WINDOWS\System32\cidaemon.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
                  O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: LBBHO - {EFD84954-6B46-42f4-81F3-94CE9A77052D} - C:\WINDOWS\lbbho.dll
                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.exe -on
                  O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
                  O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [RegTweak] C:\Program Files\Rage3DTweak\RegTwk.exe
                  O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                  O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
                  O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
                  O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
                  O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                  O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
                  O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
                  O4 - Global Startup: gameutil.exe.lnk = ?
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
                  O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                  O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                  O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
                  O9 - Extra button: AIM (HKLM)
                  O9 - Extra button: ICQ Lite (HKLM)
                  O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
                  O9 - Extra button: Messenger (HKLM)
                  O9 - Extra 'Tools' menuitem: Messenger (HKLM)
                  O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
                  O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccom...ad/tgctlcm.cab
                  O16 - DPF: {11113111-1411-1611-8111-111111111413} - mhtml:file://c:\nul.mht!http://www.capital-systems.net//browser.exe
                  O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
                  O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab

                  Comment


                  • #10
                    Don't know what I did last time I Googled it ( :rolleyes: ), but here we go:

                    It seems Trend Micro is losing popularity in the antivirus business...
                    A Google search on Pup.exe gave this thread as the first result!

                    Comment


                    • #11
                      I had the same problem...all you have to do is disable your System Restore, run a scan again and it should be gone. It's up to you whether or not you want to enable your System Restore or not. If it isn't on it can't store the viruses and they are very hard to find...Good Luck :D

                      Comment


                      • #12
                        I have Win98SE and have gotten it twice even with AVG and zonealarm installed. I have ALL of the latest patches and and definitions are never older than a day or so. Some how, I opened the door that the pest came in. The only way is from MSN & Yahoo messenger, email and neopets! Damb it the bad luck!

                        Comment

                        Working...
                        X