atapi malware problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by paul4444, Mar 2, 2010.

  1. paul4444

    paul4444 Private E-2

    Hi to everyone:)
    My prevx scanner reports that i have these problems,

    1, atapi. sys in C:\windows\system32\drivers\ ( malware component)

    2, \REGISTRY\machine\system\controlset001\services\atapi ( infected entry image)

    3,\REGISTRY\machine\system\currentcontrolset\services\atapi ( infected entry image )

    4, atapi sys in C:\windows\winsx\x86\_mshdc.inf_31bf3856a ( malware component )

    5, atapi sys in C:\windows\system32\driverstore\filerepository ( malware component )

    6, atapi sys in C :\windows\erdnt\cache\ (Malware component)

    Please could you help,ive tried to follow your clean up instructions, but im not to clever regarding computers

    I have disabled user account but i can not get rootrepeal to finish, it stops at this point, C:\windows\winsxs\catalogs\x86_policy.4,1.microsoft.msxml2r_6bd6b9abf34.
    When i installed combofix, it has got rid of the AVG task tray icon.

    I also attach logs,
    Thankyou for your time
    Regards
    Paul
     

    Attached Files:

    Last edited by a moderator: Mar 2, 2010
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You neglected to attach the C:\Mglogs.zip from running C:\MGTools.exe Please do so and I can get to work on building a fix for you. :)
     
  3. paul4444

    paul4444 Private E-2

    Hi Kestral13
    Because you didnt want me to download MG tools to desktop i dont know how to start it, ive found files and pressed every exe there is, most only flash on very quickly to the command line scanner, but there is one report, i hope this is what you require : )
     

    Attached Files:

    Last edited by a moderator: Mar 2, 2010
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Afraid not, no. I would like for you to take a look at this link before we continue as I do not wish to waste any more time removing inline logs.


    HOW TO: Attach Items To Your Post


    Attaching logs is easy, and we avoid inline posting of logs due to the fact they simply clutter up search engine results, plus it's easier going for people on dial up if logs are attached. And easier on my eye ;)
    Correct, the R&R clearly tells you to download MGTools.exe and place it directly on the root drive (C:\) My computer > C Drive. This is also where you run it from. To run it you simply double click it. I am assuming you just haven't run it yet, so go back to the R&R and follow the instructions for doing so... and then attach the C:\Mglogs.zip into your next reply. Always be sure to read things carefully so that we can get through the cleaning process as smoothly as possible.
     
  5. paul4444

    paul4444 Private E-2

    Hi
    Sorry for my mistakes in the running of MGTOOLS :-o
    Right i followed the instructions to the letter ie, UAC off, ANTIVIRUS disabled,
    I right clicked GETLOGS BAT and ran it as Admin.
    It started and went all the way down the list until it got to Running process11.exe to find loaded DLLs, i ran it twice and waited around 2 hours, i couldnt stop the scan or my computer no cursor had to use button to switch off.
    To try and save you time ive attached a highjack this log.
    Thankyou for your time
    paul View attachment hijackthis.log
     
  6. paul4444

    paul4444 Private E-2

    Hi
    I have just had another threat warning from PREVX 3.0 scanner, saying

    atapi sys in C:\mgtools\temp\erdnt\

    Is this why MGTOOLS wont run completely

    Cheers
    Paul
     
  7. paul4444

    paul4444 Private E-2

    Hi Kestal13
    Because MGTOOLS didnt finish i didnt think to look for Mglogs but it has made some that i will attach, sorry :cry
    Regards
    Paul View attachment MGlogs.zip
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When i installed combofix, it has got rid of the AVG task tray icon.

    Please see this

    Adding programs to your start up folder.

    1. What is this file?

    C:\Users\eagles4\Desktop\cl33f1i0.exe

    2. I am seeing other files for malware removal tools in your logs. Why were you using TFC and avenger? Were you trying to apply a fix yourself? Are you having help at another forum somewhere? I really need to know to save any complications later on.

    3.
    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter ( the quotes are required).
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.


    4. Your location is in the UK, yet I am seeing the following line in your HJT which indicates New Delhi in India. Are you aware of this?
    5. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    plasservice
    
    File::
    C:\Users\eagles4\AppData\Local\Temp\JETAE9.tmp
    C:\Users\eagles4\AppData\Local\Temp\JETB65.tmp
    C:\Users\eagles4\AppData\Local\Temp\JETBC3.tmp
    C:\Users\eagles4\AppData\Local\Temp\RMS9760.tmp
    C:\Users\eagles4\AppData\Local\Temp\RMS9761.tmp
    C:\Users\eagles4\AppData\Local\Temp\TMP64FA.tmp
    C:\Users\eagles4\AppData\Local\Temp\TMPA534.tmp
    C:\Users\eagles4\AppData\Local\Temp\TMPB56A.tmp
    C:\Users\eagles4\AppData\Local\Temp\TMPC1E8.tmp
    c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe
    
    Folder::
    c:\programdata\ParetoLogic Anti-Virus PLUS
    c:\program files\Common Files\ParetoLogic
    C:\Users\eagles4\AppData\Local\Temp\Low
    C:\Users\eagles4\AppData\Local\Temp\{4eaa4066-1dc5-4328-9704-d71b51f39406}
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "combofix"=-
    
    RegLock::
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and TDSSKiller.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how your PC is behaving.
     
  9. paul4444

    paul4444 Private E-2

    Hello :)
    Sorry for the delay in posting, but yes i work in the travel industry and i am in india at the moment but in Goa not Delhi.
    YES i did try and get some help on another forum before,but they said that the PREVX warnings were FALSE POSITIVES, but my computer was behaving so oddly i thought i should try some where else.The exe you refer to is GMER exe with a changed exe name to help it to run.TDSS killer would not run at first,so i proceeded with the combofix,i tried TDSS killer again and this time it appears to have worked.:-D
    I have these strange symbols $AVG,$RECYCLE.BIN,$RECYCLE(0).BIN in C drive, D drive and even on my external drive, i dont remember seeing them before.
    I thank you again
    Logs attached
    Paul View attachment TDSSKiller.2.2.7.1_05.03.2010_12.09.13_log.txt

    View attachment combofix log.txt
     
  10. paul4444

    paul4444 Private E-2

    Hi
    Sorry forgot to tell you how my computer is running, it is slow at start up.
    Yesterday it kept freezing, forcing me to manually closing the machine.
    Cheers
    Paul
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You missed this step :)
     
  12. paul4444

    paul4444 Private E-2

    Hi :)
    Here is the log, i hope, View attachment MGlogs.zip because computer kept totally freezing up.
    Can you tell me, what we are dealing with here,IE are my financial transactions safe.

    As always i admire your patience,
    Thankyou
    Paul
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\MGtools\temp\ERDNT\atapi.sys | C:\Windows\System32\drivers\atapi.sys
    
    Driver::
    ZeppelinService
    
    File::
    c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe
    
    DirLook::
    C:\Users\eagles4\AppData\Local\temp(27)
    
    Folder::
    c:\program files\Common Files\ParetoLogic
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. or avenger

    Is Prevx still reporting infected atapi.sys?
     
  14. paul4444

    paul4444 Private E-2

    Hello
    Prevx still reporting threats:(
    will i have to do a reinstall (DAMN AND BLAST) i wonder how compromised the computer is ?
    See what you see in the logs anyway
    Thanks

    Regards


    Sorry for sending this log in this way but it woulnt let me send this as an attachment.

    Here are the other two. View attachment MGlogs.zip

    View attachment ComboFix.txt
     

    Attached Files:

    Last edited by a moderator: Mar 6, 2010
  15. paul4444

    paul4444 Private E-2

    Hi
    I realise that you are busy,but just checking that you havent forgotten me.
    thanks
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Because your post got caught up in moderation (it has of course been approved now) but it did cause it to slip by unnoticed, yes. I'm going to put the kettle on and take a look soon.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you create this temp folder yourself?
    Empty all of the contents of it, and then do the below:

    GMER - running with a random name

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from GMER.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  18. paul4444

    paul4444 Private E-2

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\Windows\System32\drivers\atapi.sys
    • At the upload site, click the browse button.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Delete this folder too:

    c:\users\eagles4\AppData\Local\temp(27)
     
  20. paul4444

    paul4444 Private E-2

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I suspected, Prevx is giving you false positives. Also if the program is not paid for then it is not going to be able to fix anything anyway, so if that is the case then I would advise you to uninstall it.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. paul4444

    paul4444 Private E-2

    Hello :)
    I would like to say thankyou for your time and effort regarding this matter.
    I have uninstalled PREVX,it caused me much worry, and yourself a lot of grief.
    Regards
    PAUL :celebrate
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. safe surfing :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds