Page 1 of 1

C://windows/system32/winpup32.exe

Posted: Mon Jun 16, 2003 6:16 pm
by wldkos
my friend has this, Norton found it for her and it somehow cannot get rid of it. It said it's a backdoor trojan....
help

Archived topic from Iceteks, old topic ID:888, old post ID:7801

C://windows/system32/winpup32.exe

Posted: Mon Jun 16, 2003 7:08 pm
by Wren
Try a program called Swat It, I don't have the link. It's free too.

If the OS is XP, system restore has to be disabled for AV scanner to remove it.

Archived topic from Iceteks, old topic ID:888, old post ID:7802

C://windows/system32/winpup32.exe

Posted: Mon Jun 16, 2003 7:15 pm
by Red Squirrel
Not sure what it is but it looks like some kind of spyware, but it might be a virus too.

Archived topic from Iceteks, old topic ID:888, old post ID:7804

C://windows/system32/winpup32.exe

Posted: Mon Jun 16, 2003 9:45 pm
by Wren
This is a partial quote from a forum about the virus:

Norton detected a virus called winpup32.exe which was located in C:WindowsSystem32. It could not auto protect or access the file and I had to manually quarantine it . I submitted it to Symantec and it is a Trojan Horse type virus. They advised me to repair it or otherwise delete if not repairable, which was the case.


Archived topic from Iceteks, old topic ID:888, old post ID:7811

C://windows/system32/winpup32.exe

Posted: Tue Jun 17, 2003 2:02 am
by wldkos
thank you wren for the help. Somehow she fixed it herself, but I will find out more details tomorrow and post them.

Archived topic from Iceteks, old topic ID:888, old post ID:7821

C://windows/system32/winpup32.exe

Posted: Tue Jun 17, 2003 10:43 pm
by Wren
You're welcome. Yes, I would like to know more about it.

Archived topic from Iceteks, old topic ID:888, old post ID:7884

C://windows/system32/winpup32.exe

Posted: Wed Jun 25, 2003 9:07 pm
by wldkos
HAHAH, did anyone notice the thread's title?

Code: Select all

C://windows/system32/winpup32.exe
I have been using linux too much! c:windowssystemwinpup32.exe is more like it :P

Archived topic from Iceteks, old topic ID:888, old post ID:8575

C://windows/system32/winpup32.exe

Posted: Wed Jun 25, 2003 9:57 pm
by Red Squirrel
Haha, now that you mention it, that's funny. Was the double slash intentional? I did not know Linux had a double slash at the start..

Archived topic from Iceteks, old topic ID:888, old post ID:8587

C://windows/system32/winpup32.exe

Posted: Wed Jun 25, 2003 11:02 pm
by Chris Vogel
Red Squirrel wrote: Haha, now that you mention it, that's funny. Was the double slash intentional? I did not know Linux had a double slash at the start..
I didn't think it did either... I thought it just things like /mnt or /home/chris/music/......

Archived topic from Iceteks, old topic ID:888, old post ID:8589

C://windows/system32/winpup32.exe

Posted: Wed Jul 09, 2003 10:07 am
by Chris Vogel
Been Infected Too wrote: I have this winpup.exe trojan too and i can't get rid of it.  I have winXP...can u tell me how to disable system restore pls co i can remove it. thx a lot :)
To disable System Restore on Windows XP:
<ul>
<li>Right click on My Computer
<li>Go to the SYSTEM RESTORE tab.
<li>Click the box that says "Turn off System Restore".
</ul>
:)

Archived topic from Iceteks, old topic ID:888, old post ID:9346

C://windows/system32/winpup32.exe

Posted: Wed Jul 09, 2003 11:01 am
by Wren
Once you click on My Computer, click on Properties from the drop down menu, then you will see the System Restore tab.

Archived topic from Iceteks, old topic ID:888, old post ID:9347

C://windows/system32/winpup32.exe

Posted: Wed Jul 09, 2003 11:03 am
by Chris Vogel
Wren wrote: Once you click on My Computer, click on Properties from the drop down menu, then you will see the System Restore tab.
Oops... I forgot to include that. :roflmao2: :roflmao2:

Archived topic from Iceteks, old topic ID:888, old post ID:9348

C://windows/system32/winpup32.exe

Posted: Wed Jul 09, 2003 11:12 am
by Wren
You can also get to it from the start menu, but going through My Computer is easier if you are not familiar with using restore. :)

Archived topic from Iceteks, old topic ID:888, old post ID:9349