What Is This EXE File ??

  • Thread starter Thread starter Stuart
  • Start date Start date
S

Stuart

Looking at Task Manager earlier I saw an entry " pup "
and the symbol looked the same ,nay,WAS the same as the "sysu.exe"
that has been causing all the desktop icons.start menu etc problems
recently .I went the proces and it showed as "43589419.exe" which is in
the C/Windows/System32 folder .
can anyone tell me what this is and can it be got rid of ??

Stuart
 
No. But I think you already know, and it explains why some didn't have sysu on their computer. Others are reporting filenames like this. Send me the file and I'll tell you.
 
No. But I think you already know, and it explains why some didn't have sysu on their computer. Others are reporting filenames like this. Send me the file and I'll tell you.
Ive sent it by e-mail David
Stuart
 
Export the following registry key
HKEY_LOCAL_MACHINE\SOFTWARE\pup\ (presume this is it's settings)


and visit this web site if you can handle something sus (I didn't let it finish downloading)
http://www.penchantforbuggery.com/go.php?l=0005&reg=1

It put a window off screen. And started downloading something big onb a page that looked like an ad and wanted me to click - always a bad idea on these pages..

I added it to restricted Zone
and I get a ad each time I go there. But doesn't download anything. It's always the same add in restricted zone with a link that doesn't work (to an ad server). Not that I clicked it, I typed it in another window.

If you go to the domain root it just tells you your IP and country (which you can work out from an IP address).

It seems to find the system32 folder, copies a file there (itself?),

It a virus. It's a VB6 application, and it all seems about adds. This seems to be it's purpose. But I've just installed my AV program after month of not using it.

I haven't seen sysu. Look for a file called win32_app.exe as it's mentioned in the file. It seems to copy 2 copies of itself to system32.

This is guess work and assumes the don't expect people to read the file in Word (Recover Text From Any File Converter).
This is the text in the file

LÍ!This program cannot be run in DOS mode.





$

`.data

MSVBVM60.DLL

Qs [Qsn^Rs

Rs

RsÑPDs'FDss

DsaTQs

\PsèZQsû

Ps

PsëPDsY,Os.¬Ps

TQskcDsi

Ps- PsðADs

TQs\BDs­UQs

pQs¬

Rst¥Qso<RssADsÿÏCso´Psæ«RssDsx²Cs?£Rs[QsÁ

PséæDs

QsýqQsmYOs

KDs?sQsî`Os0XQsaUQs?´PsÞ<Ds

RsY©Ps½¢Psc?Ps[TPsp

Ds±¤Qs¸,Os4¿CsáTQs

UQsºADstEDs

UQsPOQs

BsþÿQsK÷Osq?Ps-Rs¢

EDsE£Rs<

RsÍöOsF£Qs"DDs

QsÂDDs>MDs

000-C0pup

000046}

Referencsetup

@isual Studio\VB98\LINK.EXE.Man???*

winpup

Module1

+3qµC:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB

`Ó"Timer1

shell32.dll

ShellExecuteA

WScript.Shell

WScript.Shell

System

System

Environment

Environment

Scripting.FileSystemObject

Scripting.FileSystemObject

winpup

winpup

Windows_NT

Windows_NT

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot

regread

regread

\System32\

\System32\

REG_SZ

REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SystemRoot

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SystemRoot

\System\

\System\

CopyFile

CopyFile

[1].exe

[1].exe

[2].exe

[2].exe

HKEY_LOCAL_MACHINE\SOFTWARE\pup\12212

HKEY_LOCAL_MACHINE\SOFTWARE\pup\12212

HKEY_LOCAL_MACHINE\SOFTWARE\pup\cname

HKEY_LOCAL_MACHINE\SOFTWARE\pup\cname

RegWrite

RegWrite

HKEY_LOCAL_MACHINE\SOFTWARE\pup\nname

HKEY_LOCAL_MACHINE\SOFTWARE\pup\nname

HKEY_LOCAL_MACHINE\SOFTWARE\pup\oname

HKEY_LOCAL_MACHINE\SOFTWARE\pup\oname

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

RegDelete

RegDelete

DeleteFile

DeleteFile

InternetExplorer.Application

InternetExplorer.Application

Visible

Visible

StatusBar

StatusBar

AddressBar

AddressBar

MenuBar

MenuBar

ToolBar

ToolBar

Height

Height

http://www.penchantforbuggery.com/go.php?l=0005&reg=1

http://www.penchantforbuggery.com/go.php?l=0005&reg=1

Navigate

Navigate

kernel32

GetExitCodeProcess

CreateToolhelp32Snapshot

Process32First

Process32Next

CloseHandle

advapi32.dll

RegCloseKey

RegCreateKeyExA

RegOpenKeyExA

RegQueryValueExA

RegSetValueExA

RegDeleteKeyA

RegDeleteValueA

IEXPLOR

IEXPLOR

http://www.penchantforbuggery.com/go.php?l=0005

http://www.penchantforbuggery.com/go.php?l=0005

VBA6.DLL

__vbaErrorOverflow

__vbaI2Var

__vbaEnd

__vbaVarTstGt

__vbaLsetFixstr

__vbaStrFixstr

__vbaInStrVar

__vbaBoolVarNull

__vbaRecAnsiToUni

__vbaRecUniToAnsi

__vbaSetSystemError

__vbaVarLateMemSt

__vbaObjVar

__vbaLateMemCall

__vbaFreeObj

__vbaHresultCheckObj

__vbaNew2

__vbaFreeVarList

__vbaVarCat

__vbaStrErrVarCopy

__vbaVarTstNe

__vbaVarAdd

__vbaVarIndexLoad

__vbaVarTstEq

__vbaFreeStr

__vbaStrMove

__vbaStrCat

__vbaFPInt

__vbaVarMove

__vbaFreeVar

__vbaVarSetObjAddref

__vbaVarCopy

__vbaVarLateMemCallLd

__vbaVarSetVar

__vbaOnError

Software\

Software\

http://www..com/movies.exe

http://www..com/movies.exe

Microsoft.XMLHTTP

Microsoft.XMLHTTP

Adodb.Stream

Adodb.Stream

responseBody

responseBody

\win32_app.exe

\win32_app.exe

SaveToFile

SaveToFile

__vbaObjSetAddref

__vbaI4Var

__vbaLenBstr

__vbaVarVargNofree

__vbaExitProc

__vbaResume

__vbaVargVarMove

__vbaFreeStrList

__vbaStrVarMove

__vbaError

__vbaStrToUnicode

__vbaStrToAnsi

__vbaStrCopy

+3qµClass

C:\WINDOWS\SYSTEM32\MSVBVM60.DLL\3

Timer1

}#jPhÜ!@

}#jPhÜ!@

}#jPhÜ!@

}#jPhÜ!@

}#jPhÜ!@

}#jPhÜ!@

}#jPhÜ!@

}#jPhÜ!@

MSVBVM60.DLL

__vbaVarTstGt

_CIcos

_adj_fptan

__vbaVarMove

__vbaVarVargNofree

__vbaFreeVar

__vbaStrVarMove

__vbaLenBstr

__vbaFreeVarList

__vbaEnd

_adj_fdiv_m64

__vbaStrErrVarCopy

_adj_fprem1

__vbaRecAnsiToUni

__vbaResume

__vbaStrCat

__vbaError

__vbaLsetFixstr

__vbaSetSystemError

__vbaHresultCheckObj

_adj_fdiv_m32

__vbaExitProc

__vbaOnError

_adj_fdiv_m16i

__vbaObjSetAddref

_adj_fdivr_m16i

__vbaVarIndexLoad

__vbaStrFixstr

__vbaBoolVarNull

_CIsin

__vbaVargVarMove

__vbaChkstk

EVENT_SINK_AddRef

__vbaVarTstEq

__vbaObjVar

DllFunctionCall

__vbaVarLateMemSt

_adj_fpatan

__vbaRecUniToAnsi

EVENT_SINK_Release

_CIsqrt

EVENT_SINK_QueryInterface

__vbaExceptHandler

__vbaStrToUnicode

_adj_fprem

_adj_fdivr_m64

__vbaFPException

__vbaInStrVar

__vbaVarCat

__vbaI2Var

_CIlog

__vbaErrorOverflow

__vbaNew2

_adj_fdiv_m32i

_adj_fdivr_m32i

__vbaStrCopy

__vbaFreeStrList

_adj_fdivr_m32

_adj_fdiv_r

__vbaVarTstNe

__vbaVarSetVar

__vbaI4Var

__vbaVarAdd

__vbaLateMemCall

__vbaStrToAnsi

__vbaVarLateMemCallLd

__vbaVarCopy

__vbaVarSetObjAddref

_CIatan

__vbaStrMove

_allmul

_CItan

__vbaFPInt

_CIexp

__vbaFreeStr

__vbaFreeObj

TYPELIB

_IID_SETUP

TYPELIB

_IID_SETUP

VS_VERSION_INFO

VS_VERSION_INFO

VarFileInfo

VarFileInfo

Translation

Translation

StringFileInfo

StringFileInfo

040904B0

040904B0

CompanyName

CompanyName

ProductName

ProductName

FileVersion

FileVersion

ProductVersion

ProductVersion

InternalName

InternalName

winpup

winpup

OriginalFilename

OriginalFilename

winpup.exe

winpup.exe

OLESelfRegister

OLESelfRegister

stdole2.tlbWWWÿÿÿÿ

8ÁÀ_setupWWd

8Å×setupWWW

{\aaWW
 
Export the following registry key
HKEY_LOCAL_MACHINE\SOFTWARE\pup\ (presume this is it's settings)


and visit this web site if you can handle something sus (I didn't let it finish downloading)
http://www.penchantforbuggery.com/go.php?l=0005&reg=1

Hi David-that's a lot to take in but Ive exported etc the registry entry .
I do recall yesterday or possibly it was this morning fleetingly seeing a
window that mentioned something about penchantforbuggery when visiting
another site and wondered about that at the time -now I cant remember
which site I was heading for at the time .
Wish the bastards that do this and also the ones that do popups and e-mail
spam would all go f themselves .Lowest form of human life IMHO :-)
Stuart
 
Can you post the reg file so we can see what's it's writing to your registry. Also search for this file
win32_app.exe I can't tell where it might be.

If you r/c a file and choose Run As you can tick Protect My Computer. This prevents programs writing to the registry. A file like this if run will copy itself still but won't be able to write the registry entries to automatically start itself. Also only admins can get infected by the random file names, so I suspect that win32_app.exe may be somewhere non admins are allowed to write to.
 
Can you post the reg file so we can see what's it's writing to your registry. Also search for this file
win32_app.exe I can't tell where it might be.

If you r/c a file and choose Run As you can tick Protect My Computer. This prevents programs writing to the registry.
A file like this if run will copy itself still but won't be able to write the registry entries to automatically start itself.
Also only admins can get infected by the random file names, so I suspect
that win32_app.exe may be somewhere non admins are allowed to write to.


What file is it you want posted to you David ?

I checked for win32_exe in my HD but doesn't appear to be there .When I
did a search in regedit it showed up under NAME 000/TYPE REG-SZ/DATA
Win32_app.exe
Stuart
 
The exported reg file. You can delete those registry entries. Did you tick all advanced options in search? If it's not there then maybe your AV program removed it. It should keep a log so you can check.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top