What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
4 Pages V  < 1 2 3 4 >  
Closed TopicStart new topic
> [Resolved] I think I have a virus., bsod when I insert media in my optical drive
Tomk
post Nov 20 2009, 09:08 PM
Post #16


Forum God / Classroom Admin Assistant
Group Icon

Group: Classroom Teacher
Posts: 12,314
Joined: 27-December 07
From: Sisters, OR
Member No.: 75,503
Operating System: xp



RPinney,

Several hours aren't unusual.
Go to the top of the page
 
+Quote Post
RPinney
post Nov 20 2009, 10:10 PM
Post #17


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



Finally, here it is

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Friday, November 20, 2009
Operating system: Microsoft Professional (build 7600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, November 21, 2009 00:13:37
Records in database: 3252592
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
F:\

Scan statistics:
Objects scanned: 113583
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 01:39:31


File name / Threat / Threats count
C:\Windows\System32\drivers\atapi.sys Infected: Rootkit.Win32.TDSS.u 1

Selected area has been scanned.
Go to the top of the page
 
+Quote Post
Tomk
post Nov 20 2009, 10:19 PM
Post #18


Forum God / Classroom Admin Assistant
Group Icon

Group: Classroom Teacher
Posts: 12,314
Joined: 27-December 07
From: Sisters, OR
Member No.: 75,503
Operating System: xp



RPinney,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    CODE
    :filefind
    *atapi.sys

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Go to the top of the page
 
+Quote Post
RPinney
post Nov 20 2009, 10:44 PM
Post #19


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 22:43 on 20/11/2009 by Ryan Pinney (Administrator - Elevation successful)

========== filefind ==========

Searching for "*atapi.sys"
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E
C:\Windows\System32\drivers\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] CC866C9DACA268746BEC8FF6A084FC44
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E

-=End Of File=-
Go to the top of the page
 
+Quote Post
Tomk
post Nov 20 2009, 11:13 PM
Post #20


Forum God / Classroom Admin Assistant
Group Icon

Group: Classroom Teacher
Posts: 12,314
Joined: 27-December 07
From: Sisters, OR
Member No.: 75,503
Operating System: xp



RPinney,

Please open Notepad

  1. Click Start , then Run
  2. Type notepad.exe in the Run Box.
    Copy and Paste everything from the Quote box into Notepad:

    QUOTE
    @echo off
    COPY /Y/B/V C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys C:\atapi.sys
  3. Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes. Once saved, the icon to click should look like this on your desktop:
  4. Double click fix.bat.


1. Please download The Avenger by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

CODE
Files to move:
C:\Atapi.sys|C:\Windows\System32\drivers\atapi.sys


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply.


Then

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    CODE
    :filefind
    *atapi.sys

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Go to the top of the page
 
+Quote Post
RPinney
post Nov 21 2009, 12:22 AM
Post #21


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\Atapi.sys" not found!
File move operation "C:\Atapi.sys|C:\Windows\System32\drivers\atapi.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.


________________________________________________________________________________

And now SystemLook
________________________________________________________________________________




SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 00:19 on 21/11/2009 by Ryan Pinney (Administrator - Elevation successful)

========== filefind ==========

Searching for "*atapi.sys"
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E
C:\Windows\System32\drivers\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] CC866C9DACA268746BEC8FF6A084FC44
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E

-=End Of File=-

This post has been edited by RPinney: Nov 21 2009, 12:33 AM
Go to the top of the page
 
+Quote Post
RPinney
post Nov 21 2009, 12:29 AM
Post #22


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



edit: nevermind I have nothing to say. Thanks for helping me along so far =)

This post has been edited by RPinney: Nov 21 2009, 12:33 AM
Go to the top of the page
 
+Quote Post
Tomk
post Nov 21 2009, 12:44 AM
Post #23


Forum God / Classroom Admin Assistant
Group Icon

Group: Classroom Teacher
Posts: 12,314
Joined: 27-December 07
From: Sisters, OR
Member No.: 75,503
Operating System: xp



RPinney,

I know this is a bit of a dumb question, but did you run fix.bat ?
Go to the top of the page
 
+Quote Post
RPinney
post Nov 21 2009, 08:16 PM
Post #24


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



Yes, I ran fix.bat
Go to the top of the page
 
+Quote Post
Tomk
post Nov 21 2009, 10:15 PM
Post #25


Forum God / Classroom Admin Assistant
Group Icon

Group: Classroom Teacher
Posts: 12,314
Joined: 27-December 07
From: Sisters, OR
Member No.: 75,503
Operating System: xp



RPinney,

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    CODE
    :filefind
    *atapi.sys

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Go to the top of the page
 
+Quote Post
RPinney
post Nov 22 2009, 11:45 PM
Post #26


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 23:44 on 22/11/2009 by Ryan Pinney (Administrator - Elevation successful)

========== filefind ==========

Searching for "*atapi.sys"
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E
C:\Windows\System32\drivers\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] CC866C9DACA268746BEC8FF6A084FC44
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys --a--- 21584 bytes [23:11 13/07/2009] [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E

-=End Of File=-
Go to the top of the page
 
+Quote Post
Tomk
post Nov 23 2009, 11:42 AM
Post #27


Forum God / Classroom Admin Assistant
Group Icon

Group: Classroom Teacher
Posts: 12,314
Joined: 27-December 07
From: Sisters, OR
Member No.: 75,503
Operating System: xp



RPinney,

Please open Notepad

  1. Click Start , then Run
  2. Type notepad.exe in the Run Box.
    Copy and Paste everything from the Quote box into Notepad:

    QUOTE
    @echo off
    COPY /Y/B/V C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys C:\atapi.sys
  3. Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes. Once saved, the icon to click should look like this on your desktop:
  4. Double click fix.bat.



1. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

CODE
Files to move:
C:\Atapi.sys|C:\Windows\System32\drivers\atapi.sys


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.

3. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
4. Please copy/paste the content of c:\avenger.txt into your reply.


Then

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    CODE
    :filefind
    *atapi.sys

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Go to the top of the page
 
+Quote Post
RPinney
post Nov 25 2009, 02:14 AM
Post #28


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



CODE
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error:  file "C:\Atapi.sys" not found!
File move operation "C:\Atapi.sys|C:\Windows\System32\drivers\atapi.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Completed script processing.

*******************

Finished!  Terminate.


and

CODE
SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 02:08 on 25/11/2009 by Ryan Pinney (Administrator - Elevation successful)

========== filefind ==========

Searching for "*atapi.sys"
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys    --a--- 21584 bytes    [23:11 13/07/2009]    [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E
C:\Windows\System32\drivers\atapi.sys    --a--- 21584 bytes    [23:11 13/07/2009]    [01:26 14/07/2009] CC866C9DACA268746BEC8FF6A084FC44
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys    --a--- 21584 bytes    [23:11 13/07/2009]    [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E

-=End Of File=-


also note (just to update) I'm still having the same problem. Whenever I insert any type of media into my optical drive I get a blue screen. Using driver genius professional all my drivers are up to date.

This post has been edited by RPinney: Nov 25 2009, 02:16 AM
Go to the top of the page
 
+Quote Post
Tomk
post Nov 25 2009, 10:24 AM
Post #29


Forum God / Classroom Admin Assistant
Group Icon

Group: Classroom Teacher
Posts: 12,314
Joined: 27-December 07
From: Sisters, OR
Member No.: 75,503
Operating System: xp



RPinney,

I can't seem to get the batch file to copy the file you need. We are going to have to copy it by hand.

Please navigate to the C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81 folder and find the atapi.sys file. Right click on it and select copy.

Then go back to your desktop, right click anywhere in an open space on your desktop and select paste.

Then try running Avenger again using this script:

CODE
Files to move:
%userprofile%\desktop\atapi.sys|C:\Windows\System32\drivers\atapi.sys
Go to the top of the page
 
+Quote Post
RPinney
post Nov 25 2009, 09:34 PM
Post #30


Authentic Member
**

Group: Authentic Member
Posts: 75
Joined: 28-March 09
Member No.: 84,910
Operating System: Vista Home Premium



CODE
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error:  could not move file "C:\Users\Ryan Pinney\desktop\atapi.sys"
File move operation "C:\Users\Ryan Pinney\desktop\atapi.sys|C:\Windows\System32\drivers\atapi.sys" failed!
Status: 0xc0000022 (STATUS_ACCESS_DENIED)


Completed script processing.

*******************

Finished!  Terminate.


and

CODE
SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 21:31 on 25/11/2009 by Ryan Pinney (Administrator - Elevation successful)

========== filefind ==========

Searching for "*atapi.sys"
C:\Users\Ryan Pinney\Desktop\atapi.sys    --a--- 21584 bytes    [23:07 25/11/2009]    [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys    --a--- 21584 bytes    [23:11 13/07/2009]    [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E
C:\Windows\System32\drivers\atapi.sys    --a--- 21584 bytes    [23:11 13/07/2009]    [01:26 14/07/2009] CC866C9DACA268746BEC8FF6A084FC44
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys    --a--- 21584 bytes    [23:11 13/07/2009]    [01:26 14/07/2009] 338C86357871C167A96AB976519BF59E

-=End Of File=-
Go to the top of the page
 
+Quote Post

4 Pages V  < 1 2 3 4 >
Closed TopicStart new topic

 


RSS Time is now: 18th March 2010 - 07:24 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy