PPRuNe Forums - View Single Post - Yet another (irremovable) trojan
View Single Post
Old 26th September 2005 | 09:46
  #2 (permalink)  
Evo
20 Anniversary
 
Joined: Sep 2002
Posts: 1,650
Likes: 0
From: Chichester, UK
Note C : \ is deliberately spaced because without the spaces it is read as a smiley and I get shouted at for using too many!
Selecting Disable Smilies in This Post fixes that one.

As for the rest, you're not using the latest HJT (1.99.1) but I don't think that matters. I googled rdriv.sys and this looks helpful, although I haven't gone through it in detail. In particular:

The reason you are having trouble removing this virus is because ... rdriv.sys is just part of it.

We have this virus, and I have been able to remove it manually.

The actual virus is
O23 - Service: WIN32 (image) - Unknown owner - C:\WINDOWS\image.exe
edit: d'oh, forgot my own advice about disable smilies... :)

Last edited by Evo; 26th September 2005 at 13:39.
Evo is offline