HLDRRR.EXE - Remove Spyware-Virus (wintems.exe, srosa.sys)

HLDRRR.EXE It is known to most anti-virus as spyware or Trojan-Downloader.Win32.Bagle.snBut escaped time and still get rid of anti-virus widely known as Norton si Avira.
The other day I had a great experience with this executable - virus. If you come across it on your PCs you need to be sure that You virused computer and you need a seriously. 

Where does hldrrr.exe.

This executable on your PC comes most often when downloads and installs a Toolbar for Internet Explorer to access and warnStrange programs installed on Infected sites or open executable files coming through e-mail / spam ca attachment. It is known as the virus without minimum experience in computers, which installs any program open pop-up and do not know to beware of misleading advertisements and emails.

Along with executable hldrrr.exe longer appear in the system and the following: wintems.exe, srosa.sys plus the "down" and "downld" folders.

Kaspersky Anti-Virus Report

Trojan software : Trojan-Downloader.Win32.Bagle.sn   / Trojan.Tooso.R
: C: WINDOWSsystem32drivershldrrr.exe
threat level: High

In my case, hldrrr.exe appeared in the folder "% System% WINDOWSsystem32drivers"but this executable can also be found in other folders of system32 or even in the root of this system folder.

Remove Virus File - hldrrr.exe

1. If anti-virus you detect this virus but can not delete it, watch the scan and see exactly where the file is located hldrrr.exe. Open Task Manager (Ctrl + Shift + Esc), go to the tab Processes and give kill hldrrr.exe process.

2. Open Command Prompt and give commands (after each command press Enter)

cd C: WINDOWSsystem32drivers (to get to the folder)

del hldrrr.exe

del down

del downld

Other files that accompany hldrrr.exe, wintems.exe si srosa.sys are located in "system32".

cd .. (to get to the "parent" folder of the current folder.)

del wintems.exe

del srosa.sys

3. After I deleted malware files we need to clean the registry ().

Open registry editor and go to:


Plus do click on the folder and search software FirstRRRun. Right-click and Delete.

We go to the next registry to delete the key "drvsyskit"

HKEY_CURRENT_USER> Software> Microsoft>Windows> CurrentVersion> Run

In the list on the right we look for and delete "drvsyskit".

4. Restart the computer.

Normally after the above operations should get rid of this virus, but to make sure that there are other malware on your computer is recommended good to scan your computer.

*I found this virus on an operating system protected by Avira AntiVir Personal. The detailed report of the virus and devirus was made with Kaspersky Anti Virus 2010.

HLDRRR.EXE - Remove Spyware-Virus (wintems.exe, srosa.sys)

About the author

Stealth LP

Founder and editor Stealth SettingsIn 2006 date.
Experience on Linux operating systems (especially CentOS), Mac OS X, Windows XP> Windows 10 and WordPress (CMS).

Leave a Comment