videoati0.sys - Dangerous

%sysdir%\drivers\videoati0.sys

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

%sysdir%\drivers\videoati0.sys
VideoAti0.sys is rootkit Trojan.Nailuj-A.
VideoAti0.sys is used to hide files, processes and registry.
VideoAti0.sys is a kernel mode rootkit.
Rootkit contacts remote hacker server using HTTP session.
Related files:
%WinDir%\lib
%WinDir%\stdie.dll
%SysDir%\VideoAti0.dll
%SysDir%\VideoAti0.exe
%SysDir%\comctl3.srg
%SysDir%\delself.batd
%SysDir%\drivers\VideoAti0.sys
Added to registry:
HKCR\CLSID\(A3803141-3CF5-4D66-B7EA-8D2674FE152C)
HKCR\Interface\(13D90754-C6BC-4C7E-9E9E-399C211136EF)
HKCR\TypeLib\(9FD6C9E2-54F8-48A9-BEF6-964F9C221AE4)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\(A3803141-3CF5-4D66-B7EA-8D2674FE152C)

HKCR\Gogo.IEhlprObj.1\CLSID
(default)
(A3803141-3CF5-4D66-B7EA-8D2674FE152C)

HKCR\Gogo.IEhlprObj\CLSID
(default)
(A3803141-3CF5-4D66-B7EA-8D2674FE152C)

HKCR\Gogo.IEhlprObj

Remove videoati0.sys now!