ndisfilter.sys - Dangerous

%sysdir%\ndisfilter.sys

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

%sysdir%\ndisfilter.sys
ndisfilter.sys is rootkit Proxy-ProxList.sys.
ndisfilter.sys is a kernel mode rootkit.
ndisfilter.sys is used to hide the existence of the pfplg*.dll file.
Rootkit hooks into the kernel's System Service Descriptor Table (SSDT).
Rootkit affects the addresses corresponding to the function "NTQueryDirectoryFile".
Rootkit contacts remote hacker server using HTTP session.
Related files:
%SysDir%\drivers\ndisfilter.sys
%SysDir%\pfplgflt.dll
%SysDir%\pfplgnfo.dll
%SysDir%\pfplgprx.dll
%SysDir%\pfplgscn.dll
Added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisFilter
Type: 0x00000001
Start: 0x00000002
ErrorControl: 0x00000000
ImagePath: "\??\%SYSTEMDIR%\drivers\ndisfilter.sys"
DisplayName: "NdisFilter"
Group: "Base"

Remove ndisfilter.sys now!