PPRuNe Forums - View Single Post - Yet another (irremovable) trojan
View Single Post
Old 26th Sep 2005, 09:46
  #2 (permalink)  
Evo
 
Join Date: Sep 2002
Location: Chichester, UK
Posts: 1,650
Likes: 0
Received 0 Likes on 0 Posts
Note C : \ is deliberately spaced because without the spaces it is read as a smiley and I get shouted at for using too many!
Selecting Disable Smilies in This Post fixes that one.

As for the rest, you're not using the latest HJT (1.99.1) but I don't think that matters. I googled rdriv.sys and this looks helpful, although I haven't gone through it in detail. In particular:

The reason you are having trouble removing this virus is because ... rdriv.sys is just part of it.

We have this virus, and I have been able to remove it manually.

The actual virus is
O23 - Service: WIN32 (image) - Unknown owner - C:\WINDOWS\image.exe
edit: d'oh, forgot my own advice about disable smilies... :)

Last edited by Evo; 26th Sep 2005 at 13:39.
Evo is offline