1. Este site usa cookies. Ao continuar a usar este site está a concordar com o nosso uso de cookies. Saber Mais.

Winstart.dll is Infected HELP

Discussão em 'Dúvidas e Suporte—Internet, Redes, Segurança' iniciada por Hipop_Man, 7 de Julho de 2005. (Respostas: 2; Visualizações: 736)

  1. Hipop_Man

    Hipop_Man Guest

    Boas numa manha de julho kd ligeui o PC deu me uma viso de VIRUS e eu vi ke ra no winstart.dll e kd eu faço delete akilo renicia e depis volta a dar o aviso de virus..komo posso remover esse bicho????
  2. kazuza

    kazuza Power Member

    Convinha saber qual o vírus ... :rolleyes:
  3. Forgotten

    Forgotten Banido

    Trojan-Spy.Win32.SCKeyLog.t Será este?

    se for..


    You will want to copy the text from this post and save it as a text file (*.txt) or print it because you will be working offline (in safemode) to resolve your problem and not have access to this forum.

    Follow these STEPS.

    STEP 1
    You must turn off System Restore during this process. You will keep it off until we are done fixing your system.

    STEP 2

    1. Download mwavscan (It is free), if you don't have a zip-tool we suggest zipgenius (It is free).
    2. You MUST Unzip mwavscan to 'C:\bases' (case sensitive, any other folder and it won't work properly)
    3. After installing some systems automatically start up the program, if this happens close it, you don't want to run it now.
    4. Open 'My Computer'
    5. Double click on 'C:'
    6. Double click on the folder 'bases'
    7. Now in that root folder look for 'kavupd.exe' and double click on it. (We are updating mwavscan to the latest definitions.)
    8. NOTE: Occasionally users receive an error that 'signatures are more then 30 days old'. If you receive this keep trying to run kavupd.exe, it means the definition server is busy, but you will eventually get through.

    STEP 3

    1. Now turn off your computer and remove the network cable/phone line from your machine.
    2. Reboot your computer in Safe Mode

    STEP 4

    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Double click on 'mwavscan.com'
    5. Now close all other windows, browsers, and programs other then Mwavscan before continuing
    6. Checkmark: Memory, StartUp-Folders, Drives, All Local Drives, Registry and INI Files, System Folders, Services
    7. Now select 'Scan All Files'
    8. Finally, click on 'Scan Clean' (The program will take several hours to run)
    9. When the scan is complete, click 'View Log' and Save it!

    STEP 5

    1. Reconnect your network cable/phone line
    2. Reboot your system into normal mode.

    STEP 6

    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Find the log file in the directory.
    5. Open it with an editor (Notepad will do fine)
    6. Look for the files which are tagged as "virus" or "infected"
    7. Copy&paste all these files tagged as "virus" or "infected" in a new document and save to your desktop

    STEP 7
    Run Hijackthis again and have it save a new log file.

    Step 8

    Post every file of mwavscan by looking for "infected" and "tagged as" to this thread:

    It looks like this:

    File C:\WINDOWS\sssasasb32.exe infected by "Trojan-Downloader.Win32.Agent.ig" Virus. Action Taken

    File C:\Documents and Settings\user\Local Settings\Application Data\Wildtangent\0F.dat tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.

    Also post the total results:

    =>Total Number of Files Scanned:
    =>Total Number of Virus(es) Found:
    =>Total Number of Disinfected Files:
    =>Total Number of Files Renamed:
    =>Total Number of Deleted Files:
    =>Total Number of Errors:
    ***** Scanning complete. *****

    Finally, post the new Hijackthis logfile!


    tens ai mais como resolver, se for esse é claro.
    Última edição: 7 de Julho de 2005

Partilhar esta Página