Friday, November 21, 2008

Puper Trojan

How To Remove Puper?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Puper is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
A Search hijacker redirects search results to other pages and may
transmit search and browsing data to unknown servers. An error page hijacker directs
the browser to another page, usually an advertising page, instead of the usual error
page when the requested URL is not found.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.

Puper It also known as:

[Kaspersky]Trojan-Downloader.Win32.Zlob.cb,Trojan-Downloader.Win32.Zlob.aai,Trojan-Downloader.Win32.Zlob.aac,Trojan-Downlaoder.Win32.Zlob.zi,Trojan-Downlaoder.Win32.Zlob.zy,Trojan-Downloader.win32.Zlob.yt,Trojan-downloader.Win32.Zlob.uf,Trojan-Downloader.Win32.Zlob.yt,Trojan-Downloader.Win32.Zlob.aas,Trojan-Downlaoder.Win32.Zlob.aai,Trojan-Downloader.Win32.Zlob.abt,Trojan-Downloader.Win32.Zlob.add,Trojan-Downloader.Win32.Zlob.aaq,Trojan-Downloader.Win32.Zlob.dz,Trojan-Downloader.Win32.Zlob.aec,Trojan-Downloader.Win32.Zlob.adb,Trojan-Downloader.Win32.Zlob.ael,Hoax.Win32.Renos.eg,Trojan-Downloader.Win32.Zlob.adl,Trojan-Downlaoder.Win32.Zlob.afo,Trojan-Downloader.Win32.Zlob.abk,Trojan-Downloader.Win32.Zlob.xp,Trojan-Downloader.Win32.Zlob.alw,Trojan-Downloader.Win32.Zlob.amw,Trojan-Downloader.Win32.Zlob.amk,Trojan-Downloader.Win32.Zlob.anu,Trojan-Downloader.Win32.Zlob.zng,Trojan-Downloader.Win32.Zlob.alu,Trojan-Downlaoder.Win32.Zlob.arw,Trojan-Downloader.Win32.Zlob.apu,hoax.win32.Renos.fo,Trojan-Downloader.Win32.Zlob.arz,Trojan-Downloader.win32.Zlob.ase,Trojan-Downloader.Win32.Zlob.agu,Trojan-Downloader.Win32.Zlob.asl,Trojan-Downloader.Win32.Zlob.awq,Trojan-Downloader.Win32.Zlob.atg,Trojan-Downloader.Win32.Zlob.aue,Trojan-Downloader.Win32.Zlob.avf,Trojan-Downloader.Win32.Zlob.aoi,Trojan-Downloader.Win32.Zlob.aot,Trojan-Downloader.Win32.Zlob.cs,Trojan-Downloader.Win32.Zlob.de,Trojan-Downloader.Win32.Zlob.dj,Trojan-Downloader.Win32.Zlob.cf,Trojan-Downloader.Win32.Zlob.bjo,Trojan-Downloader.Win32.Zlob.bjy,Trojan-Downloader.Win32.Zlob.biu,Trojan-Downloader.Win32.Zlob.ayf,Trojan-Downloader.Win32.Zlob.axt,Trojan-Dropper.Win32.Agent.agx,Trojan-Downloader.Win32.Zlob.bpf,Trojan-Downloader.Win32.Zlob.boo,Trojan-Downloader.Win32.Zlob.bkw,Trojan-Downloader.Win32.Zlob.bti,Trojan-Downloader.Win32.Zlob.bih,Trojan-Downloader.Win32.Zlob.bqw,Trojan-Downloader.Win32.Zlob.pn,Trojan-Downloader.Win32.Zlob.dlf,Hoax.Win32.Renos.vk,Trojan-Downloader.Win32.Zlob.eed,Trojan-Downloader.Win32.Zlob.foq,Trojan-Downloader.Win32.Zlob.fpe,Trojan-Downloader.Win32.Zlob.cth;
[McAfee]Puper.dll,Puper,StartPage-JL,Generic.Downlader.bd,Puper.dll.gen,Generic Downloader.bd,Puper.dr;
[F-Prot]W32/Downloader.LBX,W32/Downloader.LTH,W32/Downloader.LTQ,W32/Dropper.AUQ,W32/Downloader.AXZW,W32/Downloader.AXXG,W32/Zlob.ABQ,W32/Downloader.ATUF,W32/NewMalware-Rootkit-I-based!Maximus;
[Other]Troj/Puper-AC,Win32.Puper.BU,Trojan.Zlob,Win32/Puper.EX,Win32/Puper.EZ,Win32/Puper.DA,Trojan.StartPage,Win32/Puper.DK,Win32/Moiling.CP,Trojan-Downloader.Win32.Zlob.zp,Win32/Puper.DJ,Trojan-Downloader.Win32.Zlob.yt,Win32/Puper.DC,Win32/Puper.DD,Win32/Puper.DF,Win32/Puper.DH,Win32.Puper.DO,Win32/Puper,Trojan-Downloader.Win32.Zlob.acc,Trojan-Downlaoder.Win32.Zlob.abk,Zlob.Media-Codec,Win32/Puper.FQ,Troajn.Zlob,Win32/Puper.FZ,Trojan-Dwonladoer.Win32.zlob.adb,SpywareQuake,Win32/Puper.FX,Trojan.Emcodec.G,Win32/Puper.FU,Win32/Puper.GA,Puper,Win32/Puper.GE,Win32/Puper.GC,Win32/Puper.GG,Win32/Puper.GF,Trojan.Dropper,Win32/Puper.FT,Win32/Zlob.JTG,WIn32/Puper.FJ,Win32/Beovens.IA,Trojan.Emcodec,Win32/Moiling.EI,Win32/Puper.GO,Win32.Puper.GQ,win32/Puper.GR,Win32/Puper.GT,Win32/Puper.GU,Win32/Puper.GW,Trojan-Downloader.Win32.Zlob.aoi,Win32/Puper.GX,Win32/Puper.GY,Win32/Puper.GZ,Win32/Puper.HA,Win32/Puper.HB,Win32/Puper.HD,Win32/Puper.HE,Win32/Puper.HG,Win32/Puper.HH,Win32/Boarim.W,Win32/Puper.HM,W32/Zlob.gen68,Win32/Puper.HI,Win32/Puper.HJ,Win32/Puper.HN,Win32/Puper.HL,W32/Zlob.UTG,Win32/Puper.HP,W32/Puper.BI,Trojan Horse,W32/Zlob.EG,Troj/Zlob-CU,DesktopScam,Win32/Puper.BN,W32/Zlob.HN,Troj/Zlob-CV,Popuper,Win32/Puper.BT,W32/Zlob.GMB,Troj/Zlob-CZ,security2k hijacker,Win32/Puper.BF,Trojan.Zlob.F,W32/Zlob.BV,Troj/Zlob-CY,trojan-downloader.zlob,Win32/Puper.IB,Win32/Moiling.FA,Trojan.AdClicker,Win32/Puper.IH,W32/Zlob.gen71,Troj/Zlobmi-Gen,Win32/Puper.IG,TrojanDownloader.Win32/Zlob.gen,Trojan-Downloader.Zlob.Media-Codec,Win32/Puper.IC,Win32/Puper.HS,Win32/Beovens.IC,Win32/Puper.HQ,Win32/Puper.IV,Win32/Puper!generic,Win32/Puper.ID,Win32/Puper.IJ,Win32/Puper.JF,Win32/Puper.JG,TROJ_ZLOB.BFO,Win32/Puper.JQ,Troj/Puper-KX,TROJ_PUPER.BL,W32/Zlob.HVP,Win32/Puper.JX,TrojanDownloader:Win32/Zlob.gen!T,TROJ_ZLOB.DCR,Troj/Zlob-AFE,Win32/Puper.JY,TrojanDownloader:Win32/Zlob.gen!O,TROJ_ZLOB.DCS,VirusProtectPro,Win32/Puper.KN,TrojanDownloader:Win32/Zlob.gen!P,Win32/Puper.KS,TrojanDownloader:Win32/Zlob.gen!A

Puper Symptoms:

Files:
[%PROFILE_TEMP%]\temp.fr????
[%PROFILE_TEMP%]\temp.fr????\iesmin.exe
[%PROFILE_TEMP%]\temp.fr????\iesmn.exe
[%PROFILE_TEMP%]\temp.fr????\iesplg.dll
[%PROFILE_TEMP%]\temp.fr????\iesunst.exe
[%PROFILE_TEMP%]\temp.fr????\isadd.dll
[%PROFILE_TEMP%]\temp.fr????\isamini.exe
[%PROFILE_TEMP%]\temp.fr????\isamntr.exe
[%PROGRAM_FILES%]\iVideoCodec\isamini.exe
[%PROGRAM_FILES%]\iVideoCodec\isamonitor.exe
[%PROGRAM_FILES%]\Protection Tools\bpmini.exe
[%PROGRAM_FILES%]\Protection Tools\bpmon.exe
[%PROGRAM_FILES%]\Protection Tools\bpvol.dll
[%PROGRAM_FILES%]\Video Access ActiveX Object\isamini.exe
[%PROGRAM_FILES%]\Video Access ActiveX Object\isamntr.exe
[%PROGRAM_FILES%]\Video ActiveX Access\iesmn.exe
[%PROGRAM_FILES%]\Video ActiveX Access\iesplg.dll
[%SYSTEM%]\ishost.exe
[%SYSTEM%]\ismini.exe
[%SYSTEM%]\ixt0.dll
[%SYSTEM%]\ixt1.dll
[%WINDOWS%]\dls0523pmw.exe
[%WINDOWS%]\dls0523pmw.exe~
[%SYSTEM%]\hp3B80.tmp
[%PROFILE_TEMP%]\temp.fr????
[%PROFILE_TEMP%]\temp.fr????\iesmin.exe
[%PROFILE_TEMP%]\temp.fr????\iesmn.exe
[%PROFILE_TEMP%]\temp.fr????\iesplg.dll
[%PROFILE_TEMP%]\temp.fr????\iesunst.exe
[%PROFILE_TEMP%]\temp.fr????\isadd.dll
[%PROFILE_TEMP%]\temp.fr????\isamini.exe
[%PROFILE_TEMP%]\temp.fr????\isamntr.exe
[%PROGRAM_FILES%]\iVideoCodec\isamini.exe
[%PROGRAM_FILES%]\iVideoCodec\isamonitor.exe
[%PROGRAM_FILES%]\Protection Tools\bpmini.exe
[%PROGRAM_FILES%]\Protection Tools\bpmon.exe
[%PROGRAM_FILES%]\Protection Tools\bpvol.dll
[%PROGRAM_FILES%]\Video Access ActiveX Object\isamini.exe
[%PROGRAM_FILES%]\Video Access ActiveX Object\isamntr.exe
[%PROGRAM_FILES%]\Video ActiveX Access\iesmn.exe
[%PROGRAM_FILES%]\Video ActiveX Access\iesplg.dll
[%SYSTEM%]\ishost.exe
[%SYSTEM%]\ismini.exe
[%SYSTEM%]\ixt0.dll
[%SYSTEM%]\ixt1.dll
[%WINDOWS%]\dls0523pmw.exe
[%WINDOWS%]\dls0523pmw.exe~
[%SYSTEM%]\hp3B80.tmp

Folders:
[%PROGRAM_FILES%]\eMedia Codec

Registry Keys:
HKEY_CLASSES_ROOT\CLSID\{192c5b4a-3efd-40c7-9f99-c472deb8efc0}
HKEY_CLASSES_ROOT\CLSID\{1a1ddc19-5893-43ab-a73f-f41a0f34d115}
HKEY_CLASSES_ROOT\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}
HKEY_CLASSES_ROOT\CLSID\{1FC80E00-41B0-4F74-BC16-2C83ED49CAC9}
HKEY_CLASSES_ROOT\CLSID\{36ADA89D-2440-4DC4-820A-3A05E8630935}
HKEY_CLASSES_ROOT\CLSID\{4734044c-7427-43d8-adbe-df942e52bef2}
HKEY_CLASSES_ROOT\CLSID\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D}
HKEY_CLASSES_ROOT\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}
HKEY_CLASSES_ROOT\HP
HKEY_CLASSES_ROOT\HP.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{192c5b4a-3efd-40c7-9f99-c472deb8efc0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ca480cd-c0e5-4548-874e-b85b17905b3a}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FC80E00-41B0-4F74-BC16-2C83ED49CAC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36ADA89D-2440-4DC4-820A-3A05E8630935}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4734044c-7427-43d8-adbe-df942e52bef2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e0103cd4-d1ce-411a-b75b-4fec072867f4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\eMedia Codec
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_net_agent
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\net agent
HKEY_CLASSES_ROOT\clsid\{192c5b4a-3efd-40c7-9f99-c472deb8efc0}
HKEY_CLASSES_ROOT\clsid\{1a1ddc19-5893-43ab-a73f-f41a0f34d115}
HKEY_CLASSES_ROOT\clsid\{1c3c4699-b285-475f-be47-0b26088ce876}
HKEY_CLASSES_ROOT\clsid\{1ca480cd-c0e5-4548-874e-b85b17905b3a}
HKEY_CLASSES_ROOT\clsid\{1fc80e00-41b0-4f74-bc16-2c83ed49cac9}
HKEY_CLASSES_ROOT\clsid\{23b760d6-c98b-450b-9b32-26c7775cdf83}
HKEY_CLASSES_ROOT\clsid\{36ada89d-2440-4dc4-820a-3a05e8630935}
HKEY_CLASSES_ROOT\clsid\{4734044c-7427-43d8-adbe-df942e52bef2}
HKEY_CLASSES_ROOT\clsid\{67982bb7-0f95-44c5-92dc-e3af3dc19d6d}
HKEY_CLASSES_ROOT\clsid\{69b98c68-d2b8-4a4e-9cb7-e85b6f3a7014}
HKEY_CLASSES_ROOT\clsid\{cfe15135-c591-4000-a55e-a50e5f9f82bc}
HKEY_CLASSES_ROOT\clsid\{e0103cd4-d1ce-411a-b75b-4fec072867f4}
HKEY_CLASSES_ROOT\hp
HKEY_CLASSES_ROOT\hp.1
HKEY_CURRENT_USER\software\microsoft\internet explorer\searchscopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{9034a523-d068-4be8-a284-9df278be776e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{192c5b4a-3efd-40c7-9f99-c472deb8efc0}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1ca480cd-c0e5-4548-874e-b85b17905b3a}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1fc80e00-41b0-4f74-bc16-2c83ed49cac9}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{23b760d6-c98b-450b-9b32-26c7775cdf83}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{36ada89d-2440-4dc4-820a-3a05e8630935}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4734044c-7427-43d8-adbe-df942e52bef2}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{67982bb7-0f95-44c5-92dc-e3af3dc19d6d}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{cfe15135-c591-4000-a55e-a50e5f9f82bc}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{e0103cd4-d1ce-411a-b75b-4fec072867f4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ffffffff-ffff-ffff-ffff-fffffffffffa}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\emedia codec

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping
HKEY_CURRENT_USER\software\microsoft\internet explorer\searchscopes
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
DyFuCa Internet Optimizer Adware Information
SearchCentrix.Seek4Free BHO Symptoms
Removing CPush Adware
PStopper Adware Cleaner
BlackHaraz Backdoor Removal instruction

No comments: