Winpup32, fa riferimento a uno dei seguenti trojan :
Trojan.Win32.Revop.b; Trojan.Win32.StartPage.ae; TrojanClicker.Win32.VB.o
<b><font size=4>Prima di procedere fai un backup del registro</font id=size4></b>
Start > Esegui digita regedit, evidenzia la prima voce (risorse del computer)
clicca su File e quindi su ESPORTA per salvare il registro
La rimozione manuale non è semplice... ecco come fare:
<u>Se presenti,</u> termina i seguenti processi con il TASK MANAGER:
(programfilesdir = c\:Programmi; systemroot = c:\windows)
<font color=brown>
c:\do.exe
cmpi.exe
programfilesdir+\over.exe
programfilesdir+\pup.exe
stimem.exe
syscm.exe
systemroot+\pup.exe
systemroot+\system\allbackf.exe
systemroot+\system\cctresa.exe
systemroot+\system\dvdq.exe
systemroot+\system\hellexts.exe
systemroot+\system\lb32v.exe
systemroot+\system\lethk32o.exe
systemroot+\system\m20f.exe
systemroot+\system\mcompata.exe
systemroot+\system\msdmodw.exe
systemroot+\system\nternati.exe
systemroot+\system\ommdlgc.exe
systemroot+\system\pg2spltm.exe
systemroot+\system\prservm.exe
systemroot+\system\sound3dd.exe
systemroot+\system\sratelcm.exe
systemroot+\system\storesp.exe
systemroot+\system\taigfxi.exe
systemroot+\system\winpup32.exe
systemroot+\system\ysinfos.exe
systemroot+\system32\20444887.exe
systemroot+\system32\23777407.exe
systemroot+\system32\24065798.exe
systemroot+\system32\25199526.exe
systemroot+\system32\27032107.exe
systemroot+\system32\4026430.exe
systemroot+\system32\61692446.exe
systemroot+\system32\64075869.exe
systemroot+\system32\6904238.exe
systemroot+\system32\73934572.exe
systemroot+\system32\75082033.exe
systemroot+\system32\77946108.exe
systemroot+\system32\8439272.exe
systemroot+\system32\92135256.exe
systemroot+\system32\96062868.exe
systemroot+\system32\astapir.exe
systemroot+\system32\en2232v.exe
systemroot+\system32\input8d.exe
systemroot+\system32\inverw.exe
systemroot+\system32\mdrvm.exe
systemroot+\system32\onsolec.exe
systemroot+\system32\winpup.exe
systemroot+\system32\winpup32.exe
trojanclicker.win32.vb.o.exe</font id=brown>
Vai su START > ESEGUI digita Regedit e cerca questa chiave:
<b>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.</b>
se trovi il valore <b>asauthr</b>,Eliminalo e riavvia il PC immediatamente.
se trovi il valore <b>dhcpv</b>,Eliminalo e riavvia il PC immediatamente.
se trovi il valore <b>dwwizh</b>,Eliminalo e riavvia il PC immediatamente.
se trovi il valore <b>qlsrv32s</b>,Eliminalo e riavvia il PC immediatamente.
se trovi il valore <b>svidc32m</b>,Eliminalo e riavvia il PC immediatamente.
se trovi il valore <b>win32app</b>,Eliminalo e riavvia il PC immediatamente.
Vai su START> ESEGUI e digita: <font color=blue>regsvr32 /u c:\windows\msa32chk.dll</font id=blue>
(rispetta gli spazi)
Vai ancora su START > ESEGUI digita Regedit e ripulisci il registro da queste voci SE SONO PRESENTI:
<font color=brown>HKEY_CLASSES_ROOT\<b>pup.setup</b>
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\<b>pup</b>
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\<b>asauthr</b>
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\<b>dhcpv</b>
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\<b>dwwizh</b>
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\<b>qlsrv32s</b>
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\<b>svidc32m</b>
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\<b>win32app</b>
HKEY_LOCAL_MACHINE\software\<b>pup</b></font id=brown>
Sempre se sono presenti, cerca e rimuovi i seguenti files:
<font color=purple>
c:\do.exe
cmpi.exe
msa32chk.dll
programfilesdir+\over.exe
programfilesdir+\pup.exe
stimem.exe
syscm.exe
systemroot+\pup.exe
systemroot+\system\allbackf.exe
systemroot+\system\cctresa.exe
systemroot+\system\dvdq.exe
systemroot+\system\hellexts.exe
systemroot+\system\lb32v.exe
systemroot+\system\lethk32o.exe
systemroot+\system\m20f.exe
systemroot+\system\mcompata.exe
systemroot+\system\msdmodw.exe
systemroot+\system\nternati.exe
systemroot+\system\ommdlgc.exe
systemroot+\system\pg2spltm.exe
systemroot+\system\prservm.exe
systemroot+\system\sound3dd.exe
systemroot+\system\sratelcm.exe
systemroot+\system\storesp.exe
systemroot+\system\taigfxi.exe
systemroot+\system\winpup32.exe
systemroot+\system\ysinfos.exe
systemroot+\system32\20444887.exe
systemroot+\system32\23777407.exe
systemroot+\system32\24065798.exe
systemroot+\system32\25199526.exe
systemroot+\system32\27032107.exe
systemroot+\system32\4026430.exe
systemroot+\system32\61692446.exe
systemroot+\system32\64075869.exe
systemroot+\system32\6904238.exe
systemroot+\system32\73934572.exe
systemroot+\system32\75082033.exe
systemroot+\system32\77946108.exe
systemroot+\system32\8439272.exe
systemroot+\system32\92135256.exe
systemroot+\system32\96062868.exe
systemroot+\system32\astapir.exe
systemroot+\system32\en2232v.exe
systemroot+\system32\input8d.exe
systemroot+\system32\inverw.exe
systemroot+\system32\mdrvm.exe
systemroot+\system32\onsolec.exe
systemroot+\system32\winpup.exe
systemroot+\system32\winpup32.exe
trojanclicker.win32.vb.o.exe</font id=purple>
Fonte: >
http://www.pestpatrol.com/pestinfo/w/winpup32.asp