|
 |
|
Remove Trojan Pup.c
Generic PUP.x is a generic detection used to identify malicious files or Potentially Unwanted Program that promotes unpopular or useless and counterfeit security programs.
Risk Level: Low
File Size: Varies
Affected System: Windows
Common Symptoms:
1. Security pop-ups or security applications installed without users intervention.
Threat Alias and Number of Incidents
Troj/FakeAV-CL [Sophos] 13,800
RogueAntiSpyware.AntivirusXP2008 [PC Tools] 7,660
TROJ_RENOS.ACG [Trend Micro] 7,047
Win32.SuspectCrc [Ikarus] 5,315
AntiVirus2008 [Symantec] 4,758
Troj/FakeVir-DE [Sophos] 4,437
not-a-virus:FraudTool.Win32.XPAntivirus.ld [Kaspersky Lab] 4,263
AntiVirus2009 [Symantec] 2,699
not-a-virus:FraudTool.Win32.XPAntivirus.oj [Kaspersky Lab] 2,664
TROJ_FAKEALER.GV [Trend Micro] 2,664
Troj/FakeAle-GZ [Sophos] 2,352
RogueAntiSpyware.AntiVirusPro [PC Tools] 2,089
Program:Win32/Antivirus2008 [Microsoft] 2,044
FakeAlert-AB [McAfee] 1,776
PHISH.FraudTool.XPAntivirus [Ikarus] 1,776
Trojan:Win32/FakeXPA [Microsoft] 1,527
Adware.Sogou [PC Tools] 1,432
Adware.CPush [Symantec] 1,137
Adware:Win32/AdRotator [Microsoft] 934
not-a-virus:AdWare.Win32.BHO.ee [Kaspersky Lab] 870
not-a-virus:AdWare.Win32.BHO.dbj [Kaspersky Lab] 750
Adware.Begin2search [Symantec] 713
Adware.BHO!sd6 [PC Tools] 705
Adware.BHO!sd5 [PC Tools] 515
Trojan Horse [Symantec] 476
Virus.Trojan.Win32.Agent.abpb [Ikarus] 429
not-a-virus:AdWare.Win32.BHO.cwl [Kaspersky Lab] 280
not-a-virus:AdWare.Win32.Zhongsou.bb [Kaspersky Lab] 257
not-a-virus:AdWare.Win32.BHO.clx [Kaspersky Lab] 247
TrojanDownloader:Win32/Renos.DU [Microsoft] 246
Adware.Zhongsou!sd6 [PC Tools] 201
Program:Win32/Sogou [Microsoft] 198
Downloader [Symantec] 196
AdWare.Win32.AdRotator [Ikarus] 195
Hacktool [Symantec] 191
Adware.BHO.EE [PC Tools] 180
not-a-virus:FraudTool.Win32.MSAntivirus.r [Kaspersky Lab] 176
Troj/AdClick-ER [Sophos] 171
Adware.Adrotator.GEN [PC Tools] 153
Trojan.Dropper [Symantec] 153
Downloader.MisleadApp [Symantec] 140
Adware.CPush!sd6 [PC Tools] 139
not-a-virus:AdWare.Win32.BHO.fne [Kaspersky Lab] 130
Generic.Win32.Malware.Sogou [Ikarus] 127
Mal/FakeAV-F [Sophos] 125
not-a-virus:FraudTool.Win32.UltimateAntivirus.cc [Kaspersky Lab] 121
not-a-virus:AdWare.Win32.BHO.dzf [Kaspersky Lab] 112
Trojan.Fakeavalert [Symantec] 111
TROJ_FAKEALER.VL [Trend Micro] 110
not-a-virus:Client-IRC.Win32.mIRC.603 [Kaspersky Lab] 109
Hacktool.Rootkit [Symantec] 103
Backdoor.IRC.Bot [Symantec] 102
Adware.Agent!sd6 [PC Tools] 101
Adware:Win32/Owlforce [Microsoft] 94
Troj/FakeAle-FJ [Sophos] 94
Trojan.Renos.NDB [Ikarus] 87
not-a-virus:AdWare.Win32.BHO.cep [Kaspersky Lab] 84
Trojan-Spy.Win32.Banbra [Ikarus] 82
Troj/Zlob-AQP [Sophos] 81
Trojan.Win32.BHO.hof [Kaspersky Lab] 81
Backdoor.IRC!sd6 [PC Tools] 80
not-a-virus:FraudTool.Win32.Agent.cb [Kaspersky Lab] 78
Trojan-Downloader.MisleadApp!sd6 [PC Tools] 78
PSWTool.RAS!sd5 [PC Tools] 77
TROJ_ADCLICK.CH [Trend Micro] 77
not-a-virus:FraudTool.Win32.Agent.jq [Kaspersky Lab] 72
PHISH.FraudTool.XPAntivirus.OJ [Ikarus] 72
Trojan.BHO!sd6 [PC Tools] 67
not-a-virus:AdWare.Win32.Agent.fzw [Kaspersky Lab] 66
Trojan-Downloader.Win32.Renos.DU [Ikarus] 66
Troj/Istbar-EA [Sophos] 65
Adware.SearchNet [Symantec] 62
Generic.Win32.Malware [Ikarus] 62
HackTool.Win32.Homac [Kaspersky Lab] 62
Adware.NetPumper [PC Tools] 61
HackTool.Homac!sd5 [PC Tools] 61
Trojan.Win32.BHO [Ikarus] 60
Generic.Win32.Malware.Antivirus2008 [Ikarus] 59
Mal/Generic-A [Sophos] 58
not-a-virus:FraudTool.Win32.Agent.jl [Kaspersky Lab] 56
not-a-virus:PSWTool.Win32.FirePass.a [Kaspersky Lab] 56
Troj/Bckdr-QPX [Sophos] 56
Trojan.Adclicker [Symantec] 56
Generic.Win32.Malware.FakeAlert.N [Ikarus] 50
Mal/EncPk-DV [Sophos] 49
AdWare.Win32.MxLiveMedia [Ikarus] 48
Trojan:Win32/FakeSecSen [Microsoft] 45
Adware.eZula [PC Tools] 44
not-a-virus:PSWTool.Win32.RAS.a [Kaspersky Lab] 44
TROJ_FAKEAV.JI [Trend Micro] 44
Trojan.Zlob [Symantec] 44
not-a-virus:AdWare.Win32.BHO.fhg [Kaspersky Lab] 42
Rootkit.OnlineGames.Gen.89 [PC Tools] 42
Mal/FakeAV-Q [Sophos] 41
Program:Win32/XLG [Microsoft] 41
Generic PUP.b [McAfee] 40
Hacktool.PassReminder [Symantec] 40
Trojan.Fakeavalert!sd6 [PC Tools] 40
Infostealer.Gampass [Symantec] 39
Mal/Packer [Sophos] 39
Generic PUP.x [McAfee] is known to be created as:
%AppData%\dxdlls\dxdlg.exe
%AppData%\dxdlls\imapdb.exe
%AppData%\microsoft\windows\winlogon.exe
%AppData%\spool.exe
%DownloadedProgramFiles%\thunderadvise.dll
%DownloadedProgramFiles%\ygw1.dll
%MyDocuments%\spydevastator\sdbho.dll
%ProgramFiles%\360saofe.exe
%ProgramFiles%\360sys.exe
%ProgramFiles%\aav\aav.exe
%ProgramFiles%\acspmonitor\hk.dll
%ProgramFiles%\advancedhelper\advancedhelper-1.dll
%ProgramFiles%\adware deluxe\spywares\browser hijack\helper.dll
%ProgramFiles%\agava spamprotexx\tma-setup.exe
%ProgramFiles%\alertspy\spywares\spydb.exe
%ProgramFiles%\amsys\swsys.exe
%ProgramFiles%\antispywarexp2009\uninstall.exe
%ProgramFiles%\antivirus 2008\antvrs.exe
%ProgramFiles%\aol toolbar\toolbar.dll
%ProgramFiles%\asc 2.1\ascwarning32.dll
%ProgramFiles%\avm\avm.exe
%ProgramFiles%\bifrost\mgs.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bifrost\svchost32.exe
%ProgramFiles%\buysafeshoppingadvisor\buysafeshoppingadvisor.dll
%ProgramFiles%\calendar\htmlpeek.dll
%ProgramFiles%\closemonitor\baidu.exe
%ProgramFiles%\common files\cpush\cpush.dll
%ProgramFiles%\common files\cpush\uninst.exe
%ProgramFiles%\common files\pushware\cpush.dll
%ProgramFiles%\common files\pushware\uninst.exe
%ProgramFiles%\common files\system\svchostu.exe
%ProgramFiles%\dfsdfsd\kiss.exe
%ProgramFiles%\dfse.exe
%ProgramFiles%\doctor adware\spywares\browser hijack\helper.dll
%ProgramFiles%\ekerberos\ekerberos.exe
%ProgramFiles%\elcomsoft\advanced im password recovery\aimpr.exe
%ProgramFiles%\eroca\eroca.exe
%ProgramFiles%\fieryads\commlayer.dll
%ProgramFiles%\fieryads\fieryads.dll
%ProgramFiles%\flashmute\uninstall.exe
%ProgramFiles%\game\htmlpeek.dll
%ProgramFiles%\ganeralos\kiral.exe
%ProgramFiles%\getmodule\getmodule24.exe
%ProgramFiles%\getpack\getpack23.exe
%ProgramFiles%\google\googletoolbar1.dll
%ProgramFiles%\halloweentoolbar\halloweentoolbar.dll
%ProgramFiles%\helper\helper6.dll
%ProgramFiles%\hp easy internet\interdialer.exe
%ProgramFiles%\http brute forcer\httpbruteforcer.exe
%ProgramFiles%\i711.com toolbar\tbhelper.dll
%ProgramFiles%\ie passview\iepv.exe
%ProgramFiles%\iesuper\iesuper.dll
%ProgramFiles%\instant buzz\ibdaemon.exe
%ProgramFiles%\intelinet\intelin2.exe
%ProgramFiles%\ism\ism.exe
%ProgramFiles%\ithink\ithink.exe
%ProgramFiles%\kav.exe
%ProgramFiles%\kwssolution\kwsguide.dll
%ProgramFiles%\kwssolution\kwsguideupt.exe
%ProgramFiles%\luckytender\1.3.0\luckytender.dll
%ProgramFiles%\mail passview\mailpv.exe
%ProgramFiles%\medilexicon toolbar\tbhelper.dll
%ProgramFiles%\messenpass\mspass.exe
%ProgramFiles%\microantivirus\microav.exe
%ProgramFiles%\microav\microav.exe
%ProgramFiles%\microsoft office\office11\smss.exe
%ProgramFiles%\mirc\irc bot\svchost.exe
%ProgramFiles%\msa\msa.exe
%ProgramFiles%\mycentria\infobar\mycentriainfobar.dll
%ProgramFiles%\myportal\speed-x\uninstall.exe
%ProgramFiles%\mywebsearch\bar\1.bin\f3schmon.exe
%ProgramFiles%\netbox 2.8\netbox.exe
%ProgramFiles%\netpumper\netpumperieproxy.exe
%ProgramFiles%\netpumper\netpumpernnproxy.dll
%ProgramFiles%\netpumper\npnetpumper_application.dll
%ProgramFiles%\netpumper\npnetpumper_audio.dll
%ProgramFiles%\netpumper\npnetpumper_video.dll
%ProgramFiles%\netpumper\turnlog.exe
%ProgramFiles%\network password recovery\netpass.exe
%ProgramFiles%\oovootoolbar\oovootoolbar.dll
%ProgramFiles%\ozby toolbar\tbhelper.dll
%ProgramFiles%\pchealthcenter\0.exe
%ProgramFiles%\pchealthcenter\1.exe
%ProgramFiles%\pchealthcenter\2.exe
%ProgramFiles%\pchealthcenter\5.exe
%ProgramFiles%\pcprivacycleaner\pcpc.exe
%ProgramFiles%\pestbot\spywares\browser hijack\helper.dll
%ProgramFiles%\plein66\tbhelper.dll
%ProgramFiles%\pointcash\uninstall.exe
%ProgramFiles%\pornoplayer\uninstall.exe
%ProgramFiles%\pps\update.exe
%ProgramFiles%\privacy components\tools\sp\sp.dll
%ProgramFiles%\privacy components\tools\sp\srpt.dll
%ProgramFiles%\prodegetoolbar567\prodegetoolbar567.dll
%ProgramFiles%\prodegetoolbar680\prodegetoolbar680.dll
%ProgramFiles%\qdrdrive\qdrdrive20.dll
%ProgramFiles%\qdrdrive\qdrdrive9.dll
%ProgramFiles%\remote\remote.exe
%ProgramFiles%\rhc75dj0erc1\rhc75dj0erc1.exe
There are now Manual removal instructions now a proper removal tool found for this trojan.pup.c as yet. We still suggest using MICROSOFT MALICIOUS SOFTWARE REMOVAL TOOL. It might remove this trojan.
 download microsoft malicious software removal tool
|
| | |
 |
|
|