Skeet's Stuff

August 21, 2008

I’ve been invaded

trojan infection 03

This is what appeared in my computer last night (click the photo to view large enough to read.) I was in a search engine and found an entry that was exactly the phrase I had entered. I clicked on it and a video box came up, but with a notice that I needed to install a new software upgrade in order to view the video. I wanted to see the video, so I installed the stupid thing. As you can see from my scan log above, I opened up Pandora’s box.

AV alert that won't die

I guess my AV protection is pretty good. It deleted the Win32/Puper!generic trojan right away. Here’s the problem, though: it keeps coming back. Literally every thirty second or so I get the above pop-up telling me that it’s back but my AV protection has deleted it.

Trojan infection 01

This has happened hundreds of times since it started last night. If I’m typing when the infection alert pops-up (like right now) I have to stop what I’m doing and close it before I can continue. On the info page for this monster I find that:

The file “intmonp.exe” is usually accompanied by the file “popuper.exe”. Both files are used to re-launch the other in-case any of them are terminated. “popuper.exe” also drops “intmonp.exe” if it is not found on the system. It also sets the following registry value in order to execute itself when “explorer.exe” is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\policies\explorer\notepad2.exe = “popuper.exe”

This registry value is also monitored by the trojan. If it is modified in any way, the trojan sets it again.

So, that explains what’s going on, but doesn’t tell me anything about how to fix it. I’ve found nothing on the CA site that tells me how to block the blasted thing so it will quit coming back. According to what I’m understanding, it won’t even do any good to open my registry and delete it there because it will continue to re-install itself. Isn’t that what it’s saying? I should tell you the idea of opening my registry and deleting anything scares me to death. I’ve don’t even know how to open my registry, much less how to find the right stuff when I’m in there. I greatly fear that I would do the wrong thing and end up erasing myself from the universe.

If you know what I’m supposed to do, could you help me out here, please?

Technorati Tags: , ,

Posted by skeet @ 7:36 am • Computers & Technology   

RSS feed for comments on this post.
TrackBack URI

4 Responses to “I’ve been invaded”

  1. did you turn off system restore when you ran the virus scan? According to trend, XP and ME users must disable system restore while cleaning up the virus

  2. I didn’t, but I will now. Mahalo!

  3. […] no picture this time. I’m still struggling with the Win32/Puper!generic trojan and my computer is running so slow I keep timing out. Editing photos is not going to […]

  4. […] problems started Wednesday night when my CA Anti-Virus alerted me to an intruder. Only a Trojan virus, one of the more innocuous […]

Leave a Reply


  • Your Domain     web                

  • Add to Technorati Favorites





  • Menu


  • Subscribe with Bloglines




  • follow skeeterbess at http://twitter.com

  • A Contest Blog


    Laura Williams' Musings

    Links to Site



    Alltop, all the top stories


    There's a Blog in My Soup





  • Powered by IP2Location.com

    The Crohn's Forum Book Store

    More than just books! You'll find holiday gifts for everyone on your list at the Crohn's Forum Bookstore! A portion of every purchase helps support research through Crohn's & Colitis Foundation of Canada.





    engested ss_blog_claim=2bfd15c7911f47c632ac9f38e9907688