Settings & History
  • You can use boolean operators (-, |, OR), wildcards (*, ?), and phrase search (") in your query
  • For BitTorrent: Paste in a 40 characters info_hash, to search for that particular torrent and get all trackers for it
Browse|Add this search and API to your site



<< Post  Technical problem please help   ::   720 size and quality  Post >>

Author Message
Crooked_Ferret

VIP


Joined: 24 Feb 2008
Posts: 11121
Location: Da Interwebz

Status: Hidden
Reputation: 2180

Post Posted: Tue Jun 21, 2011 9:16 am Reply with quote   Back to top    

=$9artan= wrote:
I've got this, windows\systems32\drivers\atapi.sys according to google it's malware and it's a bastard to get rid of. Avast is the only program that detects it but wont delete it, move it or nothing. I'm going to try a guide i found here. Before i do anybody got any better suggestions?



atapi.sys
ATAPI IDE Miniport Driver Windows Update

It's on every windows computer I've ever looked at.

here it is on my machine

Image

_________________
There is no society in recorded history that ever suffered because its people became too reasonable.
View user's profile  Send private message    Visit poster's website        
bazzer101

VIP


Joined: 20 Jan 2010
Posts: 2525
Location: Ireland

Status: Hidden
Reputation: 578

Post Posted: Tue Jun 21, 2011 9:20 am Reply with quote   Back to top    

=$9artan= wrote:
I've got this, windows\systems32\drivers\atapi.sys according to google it's malware and it's a bastard to get rid of. Avast is the only program that detects it but wont delete it, move it or nothing. I'm going to try a guide i found here. Before i do anybody got any better suggestions?


There is a legitimate atapi.sys driver, but this could be it and its infected, or it could malware thats using another atapi.sys filename. Just make sure its not a false positive your getting.

edit: ninja'd

what av is telling you its infected? Sounds like false positive. Try running with another program like malwarebytes

edit2: sorry i see youve said its AVast. Download and isntall and update malwarebytes and run full scan with it. See if that also flags it as malware?

_________________
Image

Last edited by bazzer101 on Tue Jun 21, 2011 9:23 am; edited 1 time in total
View user's profile  Send private message            
Crooked_Ferret

VIP


Joined: 24 Feb 2008
Posts: 11121
Location: Da Interwebz

Status: Hidden
Reputation: 2180

Post Posted: Tue Jun 21, 2011 9:23 am Reply with quote   Back to top    

Or better yet what's the file data on it?
if the date and size matches mine it's a windows file. If it was recently changed there might be something going on. I've never heard of this particular file being viral though.

_________________
There is no society in recorded history that ever suffered because its people became too reasonable.
View user's profile  Send private message    Visit poster's website        
=$9artan=

VIP


Joined: 10 Dec 2008
Posts: 1299
Location: In a tent waiting for God of War 4 !

Status: Hidden
Reputation: 335

Post Posted: Tue Jun 21, 2011 1:25 pm Reply with quote   Back to top    

Malwarebytes does not pick it up only Avast. In Avast in the log it says the threat is Win32:Alureon-FQ

Then in the result bit it says Error: the specified file is read only (6009)

Google is now telling me that this is some really bad shit, and it's a Trojan in my os. Also i had unusual activity on my gmail account and had to reset it.

Looks like this is bad guys.

_________________
Need help with torrents? CLICK HERE!
View user's profile  Send private message            
robmead

isoHunt Supporter


Joined: 19 Jun 2009
Posts: 11264
Location: ... lost for ever in a happy crowd ...

Status: Hidden
Reputation: 2015

Post Posted: Tue Jun 21, 2011 5:45 pm Reply with quote   Back to top    

See if this is any help ....

http://www.computerforum.com/172355-i-have-trojan-win32-alureon-fq.html

Read about it on a few forums and apparently a programme called "Hitman Pro" gets rid of it ....... the link below is for Hitman Pro, it's free for thirty days.

http://www.surfright.nl/en linked edited by mod

_________________
Image

Image
View user's profile  Send private message            
trollster

Old Man River Mod


Joined: 06 Jan 2008
Posts: 16377
Location: I live here

Status: Offline
Reputation: 3200

Post Posted: Tue Jun 21, 2011 6:03 pm Reply with quote   Back to top    

rob that was linked straight to a download Rolling Eyes

_________________
DILLIGAF
View user's profile  Send private message  Send e-mail          
robmead

isoHunt Supporter


Joined: 19 Jun 2009
Posts: 11264
Location: ... lost for ever in a happy crowd ...

Status: Hidden
Reputation: 2015

Post Posted: Tue Jun 21, 2011 6:09 pm Reply with quote   Back to top    

Sorry ! Must have copied the wrong link as I downloaded it aswell ...........

_________________
Image

Image
View user's profile  Send private message            
thetazzzz

isoHunt Supporter


Joined: 04 Oct 2008
Posts: 7506
Location: Area 51

Status: Hidden
Reputation: 1770

Post Posted: Tue Jun 21, 2011 6:21 pm Reply with quote   Back to top    

For all the size of the file you try and upload it to one of these sites

virustotal

http://www.virustotal.com/

jotti

http://virusscan.jotti.org/en-gb

If it is bad and you have to remove the file you could try removing it with
malwarebytes fileassassin or Unlocker
http://www.emptyloop.com/unlocker/

Also Spybot Search & Destroy has options to see if things look dodgy in the startup ..

Image

_________________
Image
Image
Learn how to spot fake torrents
View user's profile  Send private message    Visit poster's website        
Crooked_Ferret

VIP


Joined: 24 Feb 2008
Posts: 11121
Location: Da Interwebz

Status: Hidden
Reputation: 2180

Post Posted: Tue Jun 21, 2011 6:27 pm Reply with quote   Back to top    

it's also a root windows file. If it's been altered a secure file check should say so.


go to the start bar and run or search box depending on windows version
type cmd and hit enter
in the box that opens up type
SFC /Scannow
hit enter and let it run.
If a base windows file has been altered it will see it.

_________________
There is no society in recorded history that ever suffered because its people became too reasonable.
View user's profile  Send private message    Visit poster's website        
WhiteGuru

Partially Experienced Newbie (tm)


Joined: 17 Feb 2009
Posts: 13

Status: Offline
Reputation: 23

Post Posted: Wed Jun 22, 2011 3:44 am Reply with quote   Back to top    

=$9artan= wrote:
I've got this, windows\systems32\drivers\atapi.sys according to google it's malware and it's a bastard to get rid of. Avast is the only program that detects it but wont delete it, move it or nothing. I'm going to try a guide i found here. Before i do anybody got any better suggestions?



Just came across a page on: remove-malware.com/malware/malware-news/atapi-sys-rootkit-is-everywhere/
If you look down on the right bottom corner in"Related post" and choose "1 - Nasty new Rootkit Patches Atapi.sys. Hope this helps.

You might want to try Iobit new Malware Fighter V1.0
Good luck.
View user's profile  Send private message            
doobieman420

I'm new be nice to me PLZ!


Joined: 28 Jun 2011
Posts: 4
Location: Manila

Status: Offline
Reputation: 1

Post Posted: Tue Jun 28, 2011 10:23 pm Reply with quote   Back to top    

thanks for the post pacino23!
View user's profile  Send private message        Yahoo Messenger    
Blink182TW

Partially Experienced Newbie (tm)


Joined: 11 Jul 2011
Posts: 34
Location: USA

Status: Offline
Reputation: 13

Post Posted: Sat Jul 16, 2011 4:42 pm Reply with quote   Back to top    

Thanks man I found it very helpful! I am downloading the programs you recommended
View user's profile  Send private message            
boknoy

I'm new be nice to me PLZ!


Joined: 10 Sep 2011
Posts: 3

Status: Offline
Reputation: 2

Post Posted: Sun Sep 11, 2011 12:58 pm Reply with quote   Back to top    

Thank you guys, this gonna be a very useful informations, keep on sharing this such great informations. Smile Very Happy
View user's profile  Send private message            
fingerlickentuna

Currently banned

I'm new be nice to me PLZ!


Joined: 19 Oct 2011
Posts: 3
Location: deborahlibby@gmail.com

Status: Offline
Reputation: 1

Post Posted: Wed Oct 19, 2011 7:21 pm Reply with quote   Back to top    

boknoy wrote:
Thank you guys, this gonna be a very useful informations, keep on sharing this such great informations. Smile Very Happy


peerblock and ultrasurf, not sure if it was mentioned.
View user's profile  Send private message      AIM Address  Yahoo Messenger  MSN Messenger  
rasungod

isoHunt Addict


Joined: 23 Jun 2009
Posts: 637
Location: Ancient Egypt

Status: Hidden
Reputation: 199

Post Posted: Mon Nov 21, 2011 11:39 am Reply with quote   Back to top    

some mod should know that in Comment #4523533 of the torrent http://isohunt.com/torrent_details/354120741/anno+2070?tab=comments a user posts a link to a virus claiming its a crack/serial for the video game listed on that torrent.

_________________
Image
View user's profile  Send private message            
Display posts from previous:       

<< Post  Technical problem please help   ::   720 size and quality  Post >>

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

This site features search engines on metadata only. It is a service independent of the IRC and BitTorrent networks. Use at your own risk.


Powered by phpBB :: All times are GMT - 7 Hours



-ADVERTISEMENT-
BTGuard - Download Anonymously

VIP

membership is only $1/month, with perks like turning off all annoying ads. We dislike ads as much as you do!

BTGuard - Download Anonymously



Random Poll
Do you talk while watching a movie?
Yes! I always wanna know what's happening,w-
ho's that guy, who needs a soda?
No! I wish a had a gun pointed at anyone who even try to breathe loudly.
Don't ask that kind of question,it depends on the movie.

New Posts

Friends
TorrentBox
Podtropolis

TorrentFreak
Torrents.to

FAC, CMCC
Defend Fair Use
Neutrality.ca

This site features search engines on metadata only. It is a service independent of the IRC and BitTorrent networks. Use at your own risk.
Canadian Coalition for Electronic Rights - CCER.CA   Lighttpd   Get Firefox   FF Plugins, Toolbar & Widgets

Page generation: 1.8s (4% in 10 SQLs) on b04, loadavg: 2.75       © isoHunt Inc. | Privacy & Copyright Policies