Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Atapi.sys infected by a Trojan Horse Packed.Protector.C  (Read 24563 times)

0 Members and 2 Guests are viewing this topic.

Mermaid123

    Topic Starter


    Rookie

    Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
    « Reply #30 on: December 19, 2009, 10:15:16 AM »
    Here is the Zip file, that's what you wanted correct?

    [Saving space, attachment deleted by admin]

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
    « Reply #31 on: December 19, 2009, 04:40:19 PM »

    Download OTM by OldTimer to your desktop.

    Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator.

    * Save it to your Desktop.
    * Double-click OTM.exe to run it.
    * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

    Code: [Select]
    :Processes
    explorer.exe

    :services

    :reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Regedit32"=-

    :files
    C:\WINDOWS\temp\

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    * Click the red Moveit! button.
    * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

    * Close OTM

    Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

    Mermaid123

      Topic Starter


      Rookie

      Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
      « Reply #32 on: December 19, 2009, 05:25:39 PM »
      I did it twice, because I thought I did it wrong the first time(blame the beer), so the first log disappeared but here it's the last one;

      [Saving space, attachment deleted by admin]

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
      « Reply #33 on: December 19, 2009, 06:07:59 PM »
      How is the computer now?

      Mermaid123

        Topic Starter


        Rookie

        Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
        « Reply #34 on: December 19, 2009, 07:01:57 PM »
        As far as I can c it's good!

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
        « Reply #35 on: December 19, 2009, 07:06:08 PM »
        Time to clean up.

        * Click START then RUN
        * Now type Combofix /Uninstall in the runbox
        * Make sure there's a space between Combofix and /Uninstall
        * Then hit Enter.

        The above procedure will:
        * Delete: ComboFix and its associated files and folders.
        * Reset the clock settings.
        * Hide file extensions, if required.
        * Hide System/Hidden files, if required.
        * Set a new, clean Restore Point.

        ----------

        1. Double click OTM to launch it.
        Vista users right click and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
        5. When finished exit out of OTM.

        ----------

        Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

        Mermaid123

          Topic Starter


          Rookie

          Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
          « Reply #36 on: December 19, 2009, 08:55:18 PM »
          During this steps I got several messages from my system saying that Services.exe wants to restart the PC, because of the code "-1073741819". And then it did, sometimes i got bluescreen. Sometimes it happend again.

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
          « Reply #37 on: December 19, 2009, 10:08:33 PM »
          Quote
          because of the code "-1073741819".

          I need the complete error code/message.

          Mermaid123

            Topic Starter


            Rookie

            Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
            « Reply #38 on: December 19, 2009, 10:51:57 PM »
            Alright. Will try to write it up since my PC locks up and i only have 60 secs to write it down it might take a while.
            While in the restarting progress my AVG found more Packed.Protector.C in C:\\WINDOWS\system32\driver\cdrom.sys and C:\\WINDOWS\system32\dllcache\cdrom.sys. Tho I could choose as option to remove them in AVG this time, not sure that is enough tho?
            And my DAEMON tools tells me; "You need at least Windows 2000 with SPTD 1.51 or higher. Karnel debugging have to be inactivated" every start up.

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
            « Reply #39 on: December 20, 2009, 09:10:11 AM »
            Download GMER Dootkit Detector and save it your desktop.
             
            * Extract it to your desktop and double-click GMER.exe
            * Click the Rootkit tab and then Scan.
            * Don't check the Show All box while scanning in progress!
            * When scanning is finished click Copy.
            * This copies the log to clipboard
            * Post the log in your reply.

            Mermaid123

              Topic Starter


              Rookie

              Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
              « Reply #40 on: December 20, 2009, 09:52:47 PM »
              So I ran the scan and it had ran for 4-5 hour's when I got a bluescreen. So I will try to run it again asap. Tho there was a log file created on my desktop. It says it was made the 19Th tho. But I'm pretty sure it's new;

              Edit*
              The 2nd scan was alot faster infact I got passed the files i struck a bluescreen on in mather of seconds tho I got a blue screen again so no log now either.

              [Saving space, attachment deleted by admin]
              « Last Edit: December 21, 2009, 08:35:24 AM by Mermaid123 »

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
              « Reply #41 on: December 21, 2009, 09:25:37 AM »
              Do you have an XP CD?

              If so, place it in your CD ROM drive and follow the instructions below:
              • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
                • Let this run undisturbed until the window with the blue  progress bar goes away
              SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

              Mermaid123

                Topic Starter


                Rookie

                Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
                « Reply #42 on: December 23, 2009, 11:47:08 AM »
                I took some time to get hold of an CD but now that's done.

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
                « Reply #43 on: December 23, 2009, 01:44:12 PM »
                And were any errors found/fixed?

                Mermaid123

                  Topic Starter


                  Rookie

                  Re: Atapi.sys infected by a Trojan Horse Packed.Protector.C
                  « Reply #44 on: December 23, 2009, 05:36:07 PM »
                  How where u suppose to c that?