videoati0.sys - Dangerous
%sysdir%\drivers\videoati0.sys
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
VideoAti0.sys is used to hide files, processes and registry.
VideoAti0.sys is a kernel mode rootkit.
Rootkit contacts remote hacker server using HTTP session.
Related files:
%WinDir%\lib
%WinDir%\stdie.dll
%SysDir%\VideoAti0.dll
%SysDir%\VideoAti0.exe
%SysDir%\comctl3.srg
%SysDir%\delself.batd
%SysDir%\drivers\VideoAti0.sys
Added to registry:
HKCR\CLSID\(A3803141-3CF5-4D66-B7EA-8D2674FE152C)
HKCR\Interface\(13D90754-C6BC-4C7E-9E9E-399C211136EF)
HKCR\TypeLib\(9FD6C9E2-54F8-48A9-BEF6-964F9C221AE4)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\(A3803141-3CF5-4D66-B7EA-8D2674FE152C)
HKCR\Gogo.IEhlprObj.1\CLSID
(default)
(A3803141-3CF5-4D66-B7EA-8D2674FE152C)
HKCR\Gogo.IEhlprObj\CLSID
(default)
(A3803141-3CF5-4D66-B7EA-8D2674FE152C)
HKCR\Gogo.IEhlprObj