| Author |
Message |
Crooked_Ferret
VIP

Joined: 24 Feb 2008
Posts: 11121
Location: Da Interwebz
Status: Hidden
Reputation: 2180
|
| =$9artan= wrote: |
| I've got this,
windows\systems32\drivers\atapi.sys
according to google it's malware and it's a bastard to get rid of. Avast is the only program that detects it but wont delete it, move it or nothing. I'm going to try a
guide
i found here. Before i do anybody got any better suggestions? |
atapi.sys
ATAPI IDE Miniport Driver Windows Update
It's on every windows computer I've ever looked at.
here it is on my machine
|
_________________ There is no society in recorded history that ever suffered because its people became too reasonable. |
|
 |
bazzer101
VIP

Joined: 20 Jan 2010
Posts: 2525
Location: Ireland
Status: Hidden
Reputation: 578
|
| =$9artan= wrote: |
| I've got this,
windows\systems32\drivers\atapi.sys
according to google it's malware and it's a bastard to get rid of. Avast is the only program that detects it but wont delete it, move it or nothing. I'm going to try a
guide
i found here. Before i do anybody got any better suggestions? |
There is a legitimate atapi.sys driver, but this could be it and its infected, or it could malware thats using another atapi.sys filename. Just make sure its not a false positive your getting.
edit: ninja'd
what av is telling you its infected? Sounds like false positive. Try running with another program like malwarebytes
edit2: sorry i see youve said its AVast. Download and isntall and update malwarebytes and run full scan with it. See if that also flags it as malware? |
_________________
Last edited by bazzer101 on Tue Jun 21, 2011 9:23 am; edited 1 time in total |
|
 |
Crooked_Ferret
VIP

Joined: 24 Feb 2008
Posts: 11121
Location: Da Interwebz
Status: Hidden
Reputation: 2180
|
Or better yet what's the file data on it?
if the date and size matches mine it's a windows file. If it was recently changed there might be something going on. I've never heard of this particular file being viral though. |
_________________ There is no society in recorded history that ever suffered because its people became too reasonable. |
|
 |
=$9artan=
VIP

Joined: 10 Dec 2008
Posts: 1299
Location: In a tent waiting for God of War 4 !
Status: Hidden
Reputation: 335
|
Malwarebytes does not pick it up only Avast. In Avast in the log it says the threat is
Win32:Alureon-FQ
Then in the result bit it says
Error: the specified file is read only (6009)
Google is now telling me that this is some really bad shit, and it's a Trojan in my os. Also i had unusual activity on my gmail account and had to reset it.
Looks like this is bad guys. |
_________________
Need help with torrents? CLICK HERE!
|
|
 |
robmead
isoHunt Supporter

Joined: 19 Jun 2009
Posts: 11264
Location: ... lost for ever in a happy crowd ...
Status: Hidden
Reputation: 2015
|
|
 |
trollster
Old Man River Mod

Joined: 06 Jan 2008
Posts: 16377
Location: I live here
Status: Offline
Reputation: 3200
|
rob that was linked straight to a download  |
_________________
DILLIGAF
|
|
 |
robmead
isoHunt Supporter

Joined: 19 Jun 2009
Posts: 11264
Location: ... lost for ever in a happy crowd ...
Status: Hidden
Reputation: 2015
|
Sorry ! Must have copied the wrong link as I downloaded it aswell ........... |
_________________
|
|
 |
thetazzzz
isoHunt Supporter

Joined: 04 Oct 2008
Posts: 7506
Location: Area 51
Status: Hidden
Reputation: 1770
|
|
 |
Crooked_Ferret
VIP

Joined: 24 Feb 2008
Posts: 11121
Location: Da Interwebz
Status: Hidden
Reputation: 2180
|
it's also a root windows file. If it's been altered a secure file check should say so.
go to the start bar and run or search box depending on windows version
type cmd and hit enter
in the box that opens up type
SFC /Scannow
hit enter and let it run.
If a base windows file has been altered it will see it. |
_________________ There is no society in recorded history that ever suffered because its people became too reasonable. |
|
 |
WhiteGuru
Partially Experienced Newbie (tm)

Joined: 17 Feb 2009
Posts: 13
Status: Offline
Reputation: 23
|
| =$9artan= wrote: |
| I've got this,
windows\systems32\drivers\atapi.sys
according to google it's malware and it's a bastard to get rid of. Avast is the only program that detects it but wont delete it, move it or nothing. I'm going to try a
guide
i found here. Before i do anybody got any better suggestions? |
Just came across a page on: remove-malware.com/malware/malware-news/atapi-sys-rootkit-is-everywhere/
If you look down on the right bottom corner in"Related post" and choose "1 - Nasty new Rootkit Patches Atapi.sys. Hope this helps.
You might want to try Iobit new Malware Fighter V1.0
Good luck. |
|
|
 |
doobieman420
I'm new be nice to me PLZ!
Joined: 28 Jun 2011
Posts: 4
Location: Manila
Status: Offline
Reputation: 1
|
thanks for the post pacino23! |
|
|
 |
Blink182TW
Partially Experienced Newbie (tm)

Joined: 11 Jul 2011
Posts: 34
Location: USA
Status: Offline
Reputation: 13
|
Thanks man I found it very helpful! I am downloading the programs you recommended |
|
|
 |
boknoy
I'm new be nice to me PLZ!
Joined: 10 Sep 2011
Posts: 3
Status: Offline
Reputation: 2
|
Thank you guys, this gonna be a very useful informations, keep on sharing this such great informations.  |
|
|
 |
fingerlickentuna

I'm new be nice to me PLZ!
Joined: 19 Oct 2011
Posts: 3
Location: deborahlibby@gmail.com
Status: Offline
Reputation: 1
|
| boknoy wrote: |
Thank you guys, this gonna be a very useful informations, keep on sharing this such great informations.  |
peerblock and ultrasurf, not sure if it was mentioned. |
|
|
 |
rasungod
isoHunt Addict

Joined: 23 Jun 2009
Posts: 637
Location: Ancient Egypt
Status: Hidden
Reputation: 199
|
|
 |
|
|