Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus in hidden driver during startup used avenger


  • Please log in to reply

#1
Reallovely

Reallovely

    New Member

  • Member
  • Pip
  • 1 posts
Hello,

My system Windows XP , MCAfee Antivirus Plus got a virus this weekend. McAfee did pretty allright, but i als used the kaspersky virus removal tool.

This worked fine virus deleted, only today i found out that it was back. I used avenger to look at the problem.

Here s the avenger file:

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "ufcyjro" found!
ImagePath: system32\drivers\lthxztg.sys
Start Type: 0 (Boot)

Rootkit scan completed.


Warning: Invalid contents in ServiceGroupOrder key!
There may be a driver loading earlier than Avenger!


Completed script processing.

*******************

Finished! Terminate.



This hidden file is maybe the root of the virus. Unfortunately this file can t be found so I don t know how to delete it.

Can You help me with this please ???

New avenger file looks like this

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "SiSPort" found!
DisplayName: SIS PORT Driver
ImagePath: \??\C:\WINDOWS\SiSPort.sys
Start Type: 3 (Manual)

Rootkit scan completed.


Completed script processing.

*******************

Finished! Terminate.



Is this sisport a problem????

Edited by Reallovely, 05 April 2011 - 08:16 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP