hey ive had this file dpusy.ini on my desktop for a while now and im wondering what is this and how i can get rid of it if its harmfull

Dani AI

Generated

Short summary and expert notes tied to the thread

The file named dpusys.ini is not a normal user-created INI in typical Windows installs; it has repeatedly appeared in removal logs as part of adware/spyware infections (commonly the Vundo/Virtumonde family). Scanner reports from multiple community cleanups show dpusys.ini flagged alongside Virtumonde detections. (bleepingcomputer.com) (f-secure.com)

Behavior and why it keeps coming back

This family often drops multiple similarly named data files (INI/INI2) and may also create or spawn executables with names like sysupd/WindowsUpd* so a visible dpusys.ini on the desktop or in %WINDIR% usually means other components are present and a running process will recreate it if not fully removed. The code commonly installs as a BHO/DLL and uses Run keys to persist. (f-secure.com)

Practical removal workflow (what has worked historically)

A proven sequence is: boot to Safe Mode (to stop persistence), use a process-killer utility to halt malicious services, run up-to-date anti‑malware scanners (Malwarebytes/modern scanners or the Windows Malicious Software Removal Tool), then run targeted removal tools for Vundo variants (historically VundoFix/ComboFix as described in removal guides). After scans remove items, check and clean Run/RunOnce registry entries and delete leftover dpusys.ini / sysupd files before a final reboot. If the file reappears, an offline scan or full image restore is the safer option. (bleepingcomputer.com)

Context for the original replies

’s suggestion to inspect the file is reasonable for harmless INI files, but dpusys.ini’s frequent appearance in malware scans means it should be treated as hostile rather than merely edited. ’s observation that a plain name search links to spyware reports is consistent with the historical evidence cited above. When present, removal should follow the multi-step cleanup pattern rather than just deleting the single INI file. (bleepingcomputer.com)

Recommended Answers

All 2 Replies

have you simply tried opening it in notepad?

A google search didn't turn up anything, that's all I know. You might just want to read it, and see if it relates to anything you might find relevant.

A google search didn't turn up anything...

Try it without the .ini extension and you'll get exactly 1 return- and guess what? Surprise- it's spyware-related!

alc6379 is right- .ini files are simple text files (or should be); open the file in Notepad and have a look at it. If you have questions, post the contents of the file here.

I'd also suggest that you take a look at many of the threads in our Security forum to find out how to detect and remove Spyware, Adware, Trojans, and the like- if you've got one malicious program on your system, you definitely have others... :(

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.