cs92004j-(E-Mail Removed) wrote:
> I saw this module in the System process view in process explorer.
> According to process explorer it is located in system32\drivers but it
> is not really there, so I cannot submit it for analysis. When I
> launch Depends on this module it has the same attributes as atapi.sys
> - same file size, version number, date and time stamp, etc. When I
> view the module strings in the module properties in process explorer
> and compare them to the strings in atapi.sys they are exactly the same
> and in the same order. I did a google search on this but nothing came
> up. Has anyone else seen this or something similar and know what it is?
>
What is the malware/virus status of the machine? If you think it is
clean, what programs (and versions) did you use to determine this?
Be sure the computer is clean:
http://www.elephantboycomputers.com/...moving_Malware
Include scanning with David Lipman's Multi_AV and follow instructions to
do all scans in Safe Mode.
http://www.elephantboycomputers.com/page2.html#Multi-AV - instructions
http://pcdid.com/Multi_AV.htm - download
When all else fails, run HijackThis and post your log in one of the
specialty forums listed at the first link above (not here, please).
Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User