Export the following registry key
HKEY_LOCAL_MACHINE\SOFTWARE\pup\ (presume this is it's settings)
and visit this web site if you can handle something sus (I didn't let it finish downloading)
http://www.penchantforbuggery.com/go.php?l=0005®=1
It put a window off screen. And started downloading something big onb a page that looked like an ad and wanted me to click - always a bad idea on these pages..
I added it to restricted Zone
and I get a ad each time I go there. But doesn't download anything. It's always the same add in restricted zone with a link that doesn't work (to an ad server). Not that I clicked it, I typed it in another window.
If you go to the domain root it just tells you your IP and country (which you can work out from an IP address).
It seems to find the system32 folder, copies a file there (itself?),
It a virus. It's a VB6 application, and it all seems about adds. This seems to be it's purpose. But I've just installed my AV program after month of not using it.
I haven't seen sysu. Look for a file called win32_app.exe as it's mentioned in the file. It seems to copy 2 copies of itself to system32.
This is guess work and assumes the don't expect people to read the file in Word (Recover Text From Any File Converter).
This is the text in the file
LÍ!This program cannot be run in DOS mode.
$
`.data
MSVBVM60.DLL
Qs [Qsn^Rs
Rs
RsÑPDs'FDss
DsaTQs
\PsèZQsû
Ps
PsëPDsY,Os.¬Ps
TQskcDsi
Ps- PsðADs
TQs\BDsUQs
pQs¬
Rst¥Qso<RssADsÿÏCso´Psæ«RssDsx²Cs?£Rs[QsÁ
PséæDs
QsýqQsmYOs
KDs?sQsî`Os0XQsaUQs?´PsÞ<Ds
RsY©Ps½¢Psc?Ps[TPsp
Ds±¤Qs¸,Os4¿CsáTQs
UQsºADstEDs
UQsPOQs
BsþÿQsK÷Osq?Ps-Rs¢
EDsE£Rs<
RsÍöOsF£Qs"DDs
QsÂDDs>MDs
000-C0pup
000046}
Referencsetup
@isual Studio\VB98\LINK.EXE.Man???*
winpup
Module1
+3qµC:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
`Ó"Timer1
shell32.dll
ShellExecuteA
WScript.Shell
WScript.Shell
System
System
Environment
Environment
Scripting.FileSystemObject
Scripting.FileSystemObject
winpup
winpup
Windows_NT
Windows_NT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot
regread
regread
\System32\
\System32\
REG_SZ
REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SystemRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SystemRoot
\System\
\System\
CopyFile
CopyFile
[1].exe
[1].exe
[2].exe
[2].exe
HKEY_LOCAL_MACHINE\SOFTWARE\pup\12212
HKEY_LOCAL_MACHINE\SOFTWARE\pup\12212
HKEY_LOCAL_MACHINE\SOFTWARE\pup\cname
HKEY_LOCAL_MACHINE\SOFTWARE\pup\cname
RegWrite
RegWrite
HKEY_LOCAL_MACHINE\SOFTWARE\pup\nname
HKEY_LOCAL_MACHINE\SOFTWARE\pup\nname
HKEY_LOCAL_MACHINE\SOFTWARE\pup\oname
HKEY_LOCAL_MACHINE\SOFTWARE\pup\oname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
RegDelete
RegDelete
DeleteFile
DeleteFile
InternetExplorer.Application
InternetExplorer.Application
Visible
Visible
StatusBar
StatusBar
AddressBar
AddressBar
MenuBar
MenuBar
ToolBar
ToolBar
Height
Height
http://www.penchantforbuggery.com/go.php?l=0005®=1
http://www.penchantforbuggery.com/go.php?l=0005®=1
Navigate
Navigate
kernel32
GetExitCodeProcess
CreateToolhelp32Snapshot
Process32First
Process32Next
CloseHandle
advapi32.dll
RegCloseKey
RegCreateKeyExA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RegDeleteKeyA
RegDeleteValueA
IEXPLOR
IEXPLOR
http://www.penchantforbuggery.com/go.php?l=0005
http://www.penchantforbuggery.com/go.php?l=0005
VBA6.DLL
__vbaErrorOverflow
__vbaI2Var
__vbaEnd
__vbaVarTstGt
__vbaLsetFixstr
__vbaStrFixstr
__vbaInStrVar
__vbaBoolVarNull
__vbaRecAnsiToUni
__vbaRecUniToAnsi
__vbaSetSystemError
__vbaVarLateMemSt
__vbaObjVar
__vbaLateMemCall
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaFreeVarList
__vbaVarCat
__vbaStrErrVarCopy
__vbaVarTstNe
__vbaVarAdd
__vbaVarIndexLoad
__vbaVarTstEq
__vbaFreeStr
__vbaStrMove
__vbaStrCat
__vbaFPInt
__vbaVarMove
__vbaFreeVar
__vbaVarSetObjAddref
__vbaVarCopy
__vbaVarLateMemCallLd
__vbaVarSetVar
__vbaOnError
Software\
Software\
http://www..com/movies.exe
http://www..com/movies.exe
Microsoft.XMLHTTP
Microsoft.XMLHTTP
Adodb.Stream
Adodb.Stream
responseBody
responseBody
\win32_app.exe
\win32_app.exe
SaveToFile
SaveToFile
__vbaObjSetAddref
__vbaI4Var
__vbaLenBstr
__vbaVarVargNofree
__vbaExitProc
__vbaResume
__vbaVargVarMove
__vbaFreeStrList
__vbaStrVarMove
__vbaError
__vbaStrToUnicode
__vbaStrToAnsi
__vbaStrCopy
+3qµClass
C:\WINDOWS\SYSTEM32\MSVBVM60.DLL\3
Timer1
}#jPhÜ!@
}#jPhÜ!@
}#jPhÜ!@
}#jPhÜ!@
}#jPhÜ!@
}#jPhÜ!@
}#jPhÜ!@
}#jPhÜ!@
MSVBVM60.DLL
__vbaVarTstGt
_CIcos
_adj_fptan
__vbaVarMove
__vbaVarVargNofree
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaStrErrVarCopy
_adj_fprem1
__vbaRecAnsiToUni
__vbaResume
__vbaStrCat
__vbaError
__vbaLsetFixstr
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaExitProc
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaBoolVarNull
_CIsin
__vbaVargVarMove
__vbaChkstk
EVENT_SINK_AddRef
__vbaVarTstEq
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
_adj_fpatan
__vbaRecUniToAnsi
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
__vbaVarCat
__vbaI2Var
_CIlog
__vbaErrorOverflow
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarAdd
__vbaLateMemCall
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
_allmul
_CItan
__vbaFPInt
_CIexp
__vbaFreeStr
__vbaFreeObj
TYPELIB
_IID_SETUP
TYPELIB
_IID_SETUP
VS_VERSION_INFO
VS_VERSION_INFO
VarFileInfo
VarFileInfo
Translation
Translation
StringFileInfo
StringFileInfo
040904B0
040904B0
CompanyName
CompanyName
ProductName
ProductName
FileVersion
FileVersion
ProductVersion
ProductVersion
InternalName
InternalName
winpup
winpup
OriginalFilename
OriginalFilename
winpup.exe
winpup.exe
OLESelfRegister
OLESelfRegister
stdole2.tlbWWWÿÿÿÿ
8ÁÀ_setupWWd
8Å×setupWWW
{\aaWW