winword.exe trojan

It's the only result that states that and it is blatant advertising for their product, you can rush in and buy it if you like but you'll probably end up with more viruses than you started with lol
 
AVG showed no viruses.

But are trojans viruses? I don't think so.


Will any of those programs remove winword.exe trojan?
 
run the online scans, I bet they'll find nothing either, close word, outlook and any office apps you have open, any apps that use word as their HTML editor, remove office from the start up folder, tell me which one gives the result.

Also go into task manager and end the process winword.exe

ddman said:
"Note: winword.exe is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system."

http://www.liutilities.com/products/wintaskspro/processlibrary/winword/
You selectively quoted that page but left out the crucial text that is above your quote.


Description:
winword.exe is the main executable for Microsoft Word, a word processing application which is bundled with the Microsoft Office Suite.


 
I opened up windows task manager and disabled winword.exe and my CPU usage went from 70 percent to 4 percent.

But i can't figure out how to disable it on startup, and i looked through hijackthis and msconfig...

Dang.... How do i remove this thing?
 
Uninstall Microsoft word, :D stop using apps that use word as their HTML editor for starters.

EDIT: You do realise that by "disabling" winword.exe rather than just ending the process word won't work now, don't you ??

Have you removed Office Quick Start from your start up folder?
 
I just pressed "ctrl-alt-dlt" and ended the process of winword.exe, and my CPU usage went from 70, to 4 percent.

I then loaded up microsoft word, and it loaded and worked fine, and my cpu usage is still at 4 percent like normal.

But i bet if i restart, the same damn winword.exe thing will be sucking back 70 percent.

I don't think i use apps that use word as their HTML editors.

What programs would those be?

I don't use outlook express.
 
Listen guys, what he is trying to say, is that he does have microsoft office, but he also has a trojan as an .exe with it that is taking up his processor resources.

My suggestion is to do a search for the original program, go to start, search and search winword.exe, when you find it, delete the one that ISNT microsoft word or any of its affiliates.

Microsoft Word would NOT take up 70% of processor resources.

But the trojan that is WINWORD.EXE would, you dont need to uninstall microsoft word.
 
xguynameddavex said:
Listen guys, what he is trying to say, is that he does have microsoft office, but he also has a trojan as an .exe with it that is taking up his processor resources.

My suggestion is to do a search for the original program, go to start, search and search winword.exe, when you find it, delete the one that ISNT microsoft word or any of its affiliates.

Microsoft Word would NOT take up 70% of processor resources.

But the trojan that is WINWORD.EXE would, you dont need to uninstall microsoft word.

Yeah, I realise that now, it's just the website that ddman provided looked a bit suss to me, but since doing some Google searching I found out about the winword.exe trojan... The below link describes how to get rid of it.

http://www.sophos.com/virusinfo/analyses/trojtorpidc.html

"Troj/Torpid-C is a downloader Trojan.

When run, Troj/Torpid-C copies itself to the Windows system folder as winword.exe and creates the following registry entry in order to run each time a user logs on:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
winword
<Windows system folder>\winword.exe

Troj/Torpid-C will attempt to close security-related windows, such as those generated by firewall and anti-virus applications.

The Trojan attempts to download and run the file "sys.exe" from twenty different sites. The file is downloaded to the user's Temp folder with a randomly generated six letter filename followed by the EXE file extension. "
 
Back
Top Bottom