So I've got this Trojan...atleast thats what I gather it is.
So I've got this Trojan...atleast thats what I gather it is.
Well when I booted my comp I got a massive slowdown, went through the processess, find this:
windrv0.exe
So I googled it, found pages in non-english with "TROJAN" beside it, so I manually went through removing it from the system processess...and things began going normally..So I tracked it down, obviously if deleting it was easy, I wouldn't have a problem, so...what now?
I want to nip this thing quick without needing to load up a sh*tload of AV software, or anything else that might slow my system down.
And FYI it wasn't like this when I last used it, I'm rather careful with everything I do. So I can very easily blame this on my niece and her penchant for surfing and clicking on anything that peaks her interest....I think maybe I should take the time to lock down my comp for family visits...but first I need this solved..
windrv0.exe
So I googled it, found pages in non-english with "TROJAN" beside it, so I manually went through removing it from the system processess...and things began going normally..So I tracked it down, obviously if deleting it was easy, I wouldn't have a problem, so...what now?
I want to nip this thing quick without needing to load up a sh*tload of AV software, or anything else that might slow my system down.
And FYI it wasn't like this when I last used it, I'm rather careful with everything I do. So I can very easily blame this on my niece and her penchant for surfing and clicking on anything that peaks her interest....I think maybe I should take the time to lock down my comp for family visits...but first I need this solved..
An avid collector of good animated avatars and signatures because I'm just that cool.
ODIN BOT UNIONS
*More will be added as they appear or change*
Suggestions to fix iSRO:
-Gold wipe
-Daily Bot bans
-Make SoX items acquirable only with Honor Points
ODIN BOT UNIONS
*More will be added as they appear or change*
Suggestions to fix iSRO:
-Gold wipe
-Daily Bot bans
-Make SoX items acquirable only with Honor Points
- LuV3r8o1
- Frequent Member
- Posts: 1194
- Joined: Thu Oct 19, 2006 2:09 am
- Quick Reply: Yes
- Location: Venice
- Contact:
Hmm...I didn't know this was a computer issues forum.
Anyway, check this out: http://forums.majorgeeks.com/showthread.php?t=35407
Its worked for me on multiple occasions.
Now quit looking at horse scat pr0n!
Anyway, check this out: http://forums.majorgeeks.com/showthread.php?t=35407
Its worked for me on multiple occasions.
Now quit looking at horse scat pr0n!
- JeSsi3JaiJai
- Regular Member
- Posts: 269
- Joined: Sat Dec 09, 2006 8:03 am
- Quick Reply: Yes
- Location: Venice
- 0000000000
- Valued Member
- Posts: 367
- Joined: Tue Mar 20, 2007 6:39 am
- Quick Reply: Yes
- Location: Netherways
- Sharp324
- Senior Member
- Posts: 4383
- Joined: Tue Jan 30, 2007 4:24 am
- Quick Reply: Yes
- Location: Off Topic
JeSsi3JaiJai wrote:the best and safe way to do it is format your pc..... i did it all the time......
formatting is the last option, ive spent hours removing trojans and over 100,000 spyware from a friends computer. Got them all out without a format, but the last once was imbedded in the win32 file and thats very tricky, could fix it and it cause a format anyway so i went ahead and format it then. But yeah formatting is a last resort..
------------------------------
Search for the SysInternals tools, specifically ProcExp and TCPView to determine what is calling it, and kill it and any processes spawned by it so it won't restart. You can also see what files this process uses, so you can identify what needs to be deleted.
Next, search for Startup Control Panel by Mike Lin, it is a VERY useful app for locating where a proc starts from, and after you kill the currently running proc, you can disable it from restarting. After that, you should reboot and check ProcExp again to see if it has come back or not, I've seen some sneaky things with that. If it is still not running, go ahead and delete or at least relocate the file so any autostarts will not be able to locate it.
Next, search for Startup Control Panel by Mike Lin, it is a VERY useful app for locating where a proc starts from, and after you kill the currently running proc, you can disable it from restarting. After that, you should reboot and check ProcExp again to see if it has come back or not, I've seen some sneaky things with that. If it is still not running, go ahead and delete or at least relocate the file so any autostarts will not be able to locate it.
- Matrixman__
- Active Member
- Posts: 773
- Joined: Sat Mar 17, 2007 2:24 pm
- Quick Reply: Yes
- Location: Olympus

