dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
545
adamP51D
join:2005-05-29
North Las Vegas, NV

adamP51D

Member

rdriv.sys Trojan Pain in the Butt

Hello...New member here.
I have a rdriv.sys virus. I can kill it for a sitting.
I have been getting around it by going in to task manager (R click on desk top Time select task mngr) and ending task on svchost.exe There are two of them, the one to kill is the one that is taking up 19,000k of memory. This only works BEFORE your online. But it does make my browser a little unstable and it comes back when the comp is restarted. Please can someone tell me how to kill it forever!!?

adamp51@netscape.com

Thanks again

TheJoker
MVM
join:2001-04-26
Charlottesville, VA

TheJoker

MVM

Click on the link »Security »I think my computer is infected or hijacked. What should I do? and follow the steps it lists.

NanDog
The Pup Was Female, I'M Not
Premium Member
join:2003-12-28
Bremerton, WA

NanDog to adamP51D

Premium Member

to adamP51D
A fairly recent and quite long thread on this bugger:

»Rdriv.sys the only virus I cannot get rid of

Hope the info there helps!
martiniano
join:2005-05-31

martiniano to adamP51D

Member

to adamP51D
Hi. First at all: excuse my english. I've removed this trojan with "Ewido Security Suite". I have Win XP.
1.Run this soft without been conected to the net. It detects a trojan (an exe file) that NAV 2005 could not. I can't remember the name now but it seems to be a variation of w32.spybot.ncx that makes work the rdriv.sys file.
2.Remove the file with the soft (Ewido)
3.Disable the "restore system" option from your WINXP
4.Reboot in safe mode
5.Delete the rdriv.sys file
6.Then remove this entries from the registry (in the left panel):
HKLM/System/currentcontrolset/rdriv
HKLM/System/currentcontrolset/wscsvc
7.Reboot normal
8.Scan the folder that used to contain the rdriv.sys with NAV 2005 to check if everything is alright
9.Enable "restore system"
I can't guarantee positive resuts but it works for me: i have not this file any more and my pc run just fine with all process