This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hldrrr.exe as always

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Some people are definitely sick. And those who are ingenious at the same time should be shot. I too was infected by that hldrrr.exe, well my bad, dont run .exe stuff from emule. Than it started kerio firewall informed me that hldrrr.exe is attempting to connect to internet. That was about last time I heard from kerio. Nextup BSOD with stuff writing to ram. My computer would never be the same. On next bootup there new programs in my system (hldrrr.exe, wintems, mbelk, srosa.sys)and some drvsyskit stuff, the firewall stopped working and avg antispyware too, not to mention hijackthis. Shame on me, I had no other anti malware utility installed. I tried everything possible, in vain. I appeared to be some improved version, no process was visible in task manager, only activeports showed hldrrr.exe happily connecting to the world (what microsoft wouldnt do for virus stealth). No antvirrus or stuff like icesword or gmer would work at that point, although the installation process appeared normal. At one point I managed to rollback the trojan to the point where he was not fully installed (livecd and delete what I could including the page.sys, changed the regedit) and I got NOD32, AVG antirootkit and icesword working. To no avail. NOD32 (shareware, most update) did not find anything suspicious except for one of the 769979.exe (created in meantime) in down directory which it put into carantene, meaning the file was from now on impossible to delete. Two things worked normally whole through: OTG2(i probably misspelled that utility) and very surprisingly unhackme. OTG2 achieved nothing, except I managed to zip the chief culprits into an archive(sorry, its lost). Unhackme seemed surprisingly good at first sight. It from time to time was able find all main trojan files and asked me to reboot. But upon reboot it only informed me that files (hldrrr and so on) werent there. It was obvious that the trojan destroys files known to him as antivirus/malware. So my advice: get some antirootkit (maybee avg, dunno) and rename the main exe. After the infection, it was kind of too late. The trojan later changed his attitude, started to bomb me(wintems) with messages about corrupted dll files. In want of a diskcheck. That one I provided which ended the whole story. Everybootit started to control my disk in a very suspective way andthe wintems messages about dlls went totally berserk. Seeing that the trojan might be writing to disk at random, I gave up, formatted and reinstalled the system.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI