|
|
Popuper Adware Information
| Name: |
Popuper |
| Category: |
Adware |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
Popuper drops a file named intmonp.exe into the Windows system folder and then runs it. The intmonp.exe file monitors the Trojan and restarts it if it is terminated. The Trojan restarts the monitoring process if it is terminated and recreates it if deleted.
Popuper creates the following registry entry to ensure it is run when the infected computer starts:
HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRun
notepad2.exe
popuper.exe
|
| Signatures:
|
process: popuper.exe: MD5 Hash: 66fd366137120d302b5...
process: popuper.exe: MD5 Hash: 3c061342d35c5b9ebcd...
process: popuper.exe: MD5 Hash: bc193cdf1bebe5abb29...
process: popuper.exe: MD5 Hash: 20c96822257c25b19a1...
process: popuper.exe: MD5 Hash: c8474846b569e5201a8...
process: popuper.exe: MD5 Hash: b746515fbb0ef9be8ee...
process: popuper.exe: MD5 Hash: 423fb920de7e662fd02...
process: popuper.exe: MD5 Hash: 77c43a6c6729bccde44...
process: popuper.exe: MD5 Hash: 60913abf4b40b7c1156...
process: popuper.exe: MD5 Hash: 5eb1d1a05a188705309...
process: popuper.exe: MD5 Hash: e44b908c3406c5987c6...
process: popuper.exe: MD5 Hash: 3afa095bb97c1db4b7f...
process: popuper.exe: MD5 Hash: e1440eb028dddcf8ba5...
process: popuper.exe: MD5 Hash: 695f99c4efd11928b95...
process: popuper.exe: MD5 Hash: 51923cf88243ae8e397...
process: popuper.exe: MD5 Hash: 38831b14f0aa525e7bb...
process: popuper.exe: MD5 Hash: f9f4db444c1d8ad9435...
process: intmonp.exe: MD5 Hash: f0b1485fbe00e0f82ea...
process: popuper.exe: MD5 Hash: f9f4db444c1d8ad9435...
process: popuper.exe: MD5 Hash: 27861471a71aee1f743...
process: popuper.exe: MD5 Hash: d8df1b054cf49b3e044...
process: popuper.exe: MD5 Hash: 708c75633c7e3967cfe...
process: popuper.exe: MD5 Hash: 7caffe82ee8cf909bfa...
process: popuper.exe: MD5 Hash: 4c6192dbd628475ba1c...
process: popuper.exe: MD5 Hash: b27e268739733bbc88e...
process: popuper.exe: MD5 Hash: 017f492a68434521505...
process: popuper.exe: MD5 Hash: 2045840c261d519bef1...
process: popuper.exe: MD5 Hash: 911cc0a23e91eff44aa...
process: popuper.exe: MD5 Hash: bb8c94f4dbe9752e935...
process: popuper.exe: MD5 Hash: fbeaaf66bf6fe32d52b...
process: popuper.exe: MD5 Hash: 6bb7b0f6990f3014cb0...
process: popuper.exe: MD5 Hash: b9299fecbf433517b4b...
process: popuper.exe: MD5 Hash: 2b9dc40c93882d0bc8b...
process: popuper.exe: MD5 Hash: 47c23689358afcd3be0...
process: popuper.exe: MD5 Hash: 55291bc2cf4957a87b4...
process: mrjj.exe: MD5 Hash: 7a2c5f50842e83d1ff2...
process: popuper.exe: MD5 Hash: 6f2c2ca309382089c92...
process: popuper.exe: MD5 Hash: b33d5154350a2b80abe...
process: popuper.exe: MD5 Hash: 7a4c93eca77bd547ea8...
process: popuper.exe: MD5 Hash: 4aae00998fb833928e0...
process: intmonp.exe: MD5 Hash: d90dbffc6a6348e33b5...
process: intmonp.exe: MD5 Hash: f0b1485fbe00e0f82ea...
process: popuper.exe: MD5 Hash: 5b2d0e6bf3073f0882c...
process: popuper.exe: MD5 Hash: a9661ecab63d38ce0c7...
process: popuper.exe: MD5 Hash: 02b1989b943483e7c4e...
process: popuper.exe: MD5 Hash: 99d83d2f263c171e311...
process: popuper.exe: MD5 Hash: d1861a077872ff952e7.. |
| Type: |
Adware - Adware is generally software that displays advertisements. Some advertisers may covertly install adware on your system and generate a stream of unsolicited advertisements that can clutter your desktop and affect your productivity. The advertisements may also contain pornographic or other material that you might find inappropriate. The extra processing required to track you or to display advertisements can tax your computer and hurt your system performance. |
Top Adware Visited Pages:
Adw.WinSoftware.WinAntiSpyware - 536 visits
ClickSpring.PuritySCAN.Downloader - 395 visits
DMCast - Alias: Desktop Media Cast - 167 visits
RBot.schvost - Alias: WORM_RBOT.CAU - 101 visits
WhenU.SaveNow - Alias: SAVE!, SaveNow, WhenU.SaveNow, WhenUSaveNow - 77 visits
Adw.FreePcScan.SpywareSlayer - 64 visits
Seekmo Search Assistant - 63 visits
ABetterInternet.Transponder.Ceres - Alias: Ceres - 63 visits
HelpExpress - Alias: Adware.HelpExpress - 59 visits
TopRebates.RebateNation - Alias: Adware:WebRebates.D - 54 visits
Random Adware Pages:
StopGuard - Alias: Stopguard Pop-up, RealScanner
Cydoor.TOPicks - Alias: ToPicks
IST.PowerScan
Claria - Alias: Gator, GAIN, GIAN Publishing
Adw.NewAds.IRASSync
ArmBender
SEP - Alias: SideSearch Toolbar
Adware.VideoCCodec - Alias: videoc
ABetterInternet.Respondmiter - Alias: NetPal, Sputnik, VX2 RespondMiter
Adw.SysTray.Exsn
|
|