Computing.Net > Forums > Windows 2000 > weird pup.exe crashes my win2k

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

weird pup.exe crashes my win2k

Reply to Message Icon

Name: fran_cis
Date: December 13, 2003 at 02:42:26 Pacific
OS: Windows 2000
CPU/Ram: Amd Athlon
Comment:

Ok,
My computer is really stuffed up!
I will make some description what happened:

One day i opened the Taskmanager and noticed come prog running, called pup.exe. i closed it and saw other progs running, like lsass.exe, csrss.exe, smss.exe, and things like msblaster.exe and really weird progs i have never heard of before!
now i deleted the folder where the pup.exe was located in (C:\Progs\dm\0\pup.exe) and deleted lots of registry things containing things abut the pup.exe
i thought it was all fine and opened my spybot to check once again, it found about 400 viruses/backdoors/trojans/dialers/stuff that wasnt installed by me or my parents/family.
well i think u know what my eraction was like!
I ran it once again, after fixing them, and there had been another abotu 50 of them coming up. i did that like for an hour and tehre were more and more coming up. Then i closed my internet connection and did it one last time and set my sygate firewall on Block all and restarted connection, somehow there were still comine about 20 new progs per 10 minutes throu.
so now i am here, and here about all sorts of things what this pup.exe does and that nobody has really ever eliminated these problems.

couild anyone help me as soon as possible? pup.exe is still running, IE doesnt work because my svchost.exe collapses on startup of comp, and even things like copy/paste dun work.

PLS help me, thanks

PS.: if needed i can make some screenshots and post them




Sponsored Link
Ads by Google

Response Number 1
Name: chetan thaker
Date: December 13, 2003 at 07:22:18 Pacific
Reply:

dude, u got some HELL OF A BIG PROBLEM here

well first of all, get your hands on AD-AWARE (or spybot is good if u r comfy wid dat.. but i prefer adaware)

update your antivirus definitions
and scan it first
b4 starting the check, remove your internet connection PHYSICALLY (if u get internet thru cable, unplug it totally)

then run spybot (or adaware) twice or thrice (ofcourse with the latest definitions for that too)

and then rescan your PC wid da antivirus software

then go online, update your windows (http://windowsupdate.microsoft.com )

and download all the stuff there

and then run a scan ...

and yeah, try using ZONEALARM (its da world's best firewall available till date... its nice)

u shud have your PC all fixed up once and for all

anything else, mail me

CHetan Thaker


0

Response Number 2
Name: Patrick
Date: December 13, 2003 at 16:19:36 Pacific
Reply:

You say:
IE doesn't work because my svchost.exe collapses on startup of comp, and even
things like copy/paste dun work

You've got blaster (or welchia) worm on your computer! You can find the remedies for this in about 20 other posts around here, but here are the steps again:
the steps I would suggest:
1. block port 135 in your firewall
2. scan your computer with an up to date virus scanner (if getting virus
definitions updates on internet is impossible because of your svchost
problem, download them on another computer and put them on a floppy disk or
cd to copy the update to your own computer)
3. run the tools that scan for and fix W32.Blaster.Worm and
W32.Welchia.Worm (you can find then here:
http://securityresponse.symantec.com/avcenter/tools.list.html
4. run windows update (there should be a shortcut in your start menu) and
install all critical updates.
5. scan your computer again to be sure you're not infected anymore...

for the spyware stuff use adaware as told above :)


0

Response Number 3
Name: ctcnetwork
Date: December 14, 2003 at 08:49:23 Pacific
Reply:

Looks like you may have a trojan or virus as posted here :- http://www.techsupportforum.com/computer/topic/9455-1.html

Try the Mcafee "Stinger" :- http://download.nai.com/products/mcafee-avert/stinger.exe

YES - Do use Ad Aware :- http://www.lavasoft.de/support/download/

Also try Spybot S&D :- http://download.com.com/3000-2144-10122137.html?part=104443&subj=dlpage&tag=button

Good Luck. . .

:o)


0

Response Number 4
Name: R.P.MacMurphy
Date: December 23, 2003 at 11:17:01 Pacific
Reply:

1st you should create a snapshot of your system under system tools (system restore)just in case you need to go back if things don't go as planned. Then you should go to your task manager and kill the 'pup' running. After that you should do a files and folders search of your system and look for the following files and delete them: winpup.exe, pup.exe, sysu.exe, 2831667.exe, 3644961.exe, 1923769.exe, 81911867.exe, 70399111.exe, internet optimizer, ddm, dd_m, amcompat. Even just running the numbers/names without the '.exe' ending the files should come up. Also delete everything in your temporary internet files folder. Next to last, run REGEDIT and look for and delete any of the above values. Some do not have the '.exe' ending but will be named things like 'pup' or 'winpup.setup'. Delete them all. You may have to delete some of the registry keys as well but do so with caution. If you don't 'pup' will creep back in. Finally, run MSCONFIG and look for anything suspicious i.e. values running in startup with the above names. I hope this helps. It took me about 8 hrs. to delete 'pup'. I kept missing the 70399111 file name.

Also it would be a very good idea to download adaware for free and spybot-search and destroy for free and running them to see what they can kill.


0

Response Number 5
Name: ctcnetwork
Date: December 23, 2003 at 12:08:46 Pacific
Reply:

My, that is one big load of trash to get rid of . . .

ALSO. . . Disable system recovery.... Do this because some of the files you are about to delete may be covered by the system recovery.

Restart and then hack you way through. Once SURE you have got everything, you can re enable system recovery....

:o)


0

Related Posts

See More



Response Number 6
Name: AnakiMana
Date: January 17, 2004 at 01:55:26 Pacific
Reply:

I also found this pup.exe running on my WinXP computer. I had no viruses, but this pup.exe kept bringing ads up on my screen. In the task manager (alt-ctrl-del) I right clicked on pup.exe, then clicked on "Go To Process". It highlighted a process called "99862307.EXE". A search of my hard drive found 3 different pup files. I also found 99862307.exe in my C:/windows/system32 folder. I scanned through that folder to see if there were any other EXE files with that naming convention. Sure enough I found one other called 73397463.exe. I deleted all 5 of these files and hopefully that's the end of this PUP thing! So if you have it, delete all those files! By the way, I ran SpyBot Search & Destroy before deleting anything and it didn't find it. So either it's not spyware, or SpyBot doesn't know about it yet. Hope this helps someone out there.


0

Response Number 7
Name: ctcnetwork
Date: January 17, 2004 at 05:40:20 Pacific
Reply:

Be interesting to know where these files originally came from.

What software was installed to get these odd files on your system???

Or what were the origins of any email that may be responsible . . .

:o)


0

Response Number 8
Name: darkk-desires
Date: January 18, 2004 at 12:54:47 Pacific
Reply:

I had pup.exe , do.exe and over.exe all on my computer. All three were put on at the same time.I have deleted them twice each time to come back again. I have nortons and spybot and a firewall. I have did a search on my pc for 99862307.exe and I come up with nothing. Also i have seached my pc for these files and deleted them competely. Where do these come from? And why are they returning? thanks for any help in advance. :)


0

Response Number 9
Name: mikelong
Date: January 29, 2004 at 18:18:48 Pacific
Reply:

I have this virus on my system.
I found it when I opened notepad.exe my firewall prompted that it was going to connect to the internet.
I disambled the notepad.exe which was replaced by an unknown virus. All its job is to download http://retardedinternetgeek.com/over.exe and http://retardedinternetgeek.com/pup.exe and run them. The over.exe is just to restore the original notepad.exe, and do nothing. But after I ran pup.exe, it extracted some exe file in system32 directory. This kind of exe file is only 64k and is written in VB native code. And it has a random name. I`m not experienced in dissembling vb program, and I`m not interested in it.
What I want to find out is just how the notepad.exe is replaced by the virus. If it can replace the notepad.exe then it can replace a lot of critical files in my system. That is terrible. I updated my system with most recent patches. And the Norton 2004 can not discover it even when I run the pup.exe. I have updated the norton2004 also.


0

Response Number 10
Name: j_private0123
Date: January 30, 2004 at 00:57:04 Pacific
Reply:

yeah. this is the worst thing i have *ever* encountered. i feel your pain. just when i though i had it totally gone, i saw a running process called: oisen.exe which is panother part of that nightmare. looking at the attributes for oisen.exe, i saw the same info as pup.exe and over.exe. i was truly disgusted that both ad-aware and apybot failed to find this. it seems these exes keep downloading new versions and morphing into new exes. they are pretty cocky about it too. look at the company name: "totally" adn "we rule"


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 2000 Forum Home


Sponsored links

Ads by Google


Results for: weird pup.exe crashes my win2k

Rundll32.exe crash www.computing.net/answers/windows-2000/rundll32exe-crash/56084.html

SP1 crashed my OS!!! www.computing.net/answers/windows-2000/sp1-crashed-my-os/4556.html

Explorer.exe crashes when copying, paste www.computing.net/answers/windows-2000/explorerexe-crashes-when-copying-paste/18374.html