Browsed redirect after following instructions - atapi.sys TDSS infection?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Leor, Apr 16, 2010.

  1. Leor

    Leor Private E-2

    Hello guys. Congratulations for the great forum you've got here. Really helpful and thorough, a beacon for rest of us.

    In the last few days I've been having a very annoying infection on my Windows XP, with Firefox constantly redirected to other websites, svchost.exe files magically appearing in the TEMP folder (and duly reported by Avast). I tried to follow the instructions of the other threads and have managed to clean my netbook from a few trojans and infections picked up god knows how.

    TDSSkiller finally reported that my atapi.sys file is infected by the lovely TDSS trojan, but couldn't remove it effectively after reboot. So in a final attempt before wiping the OS, I decided to write a post here. Thanks in advance for all the help, guys. My netbook is actually quite precious since I do a lot of travelling and my working life sort of depends on it.

    I followed all your cleaning instructions, with a couple of major problems:

    - running Combofix resulted in the computer crashing a couple of times, so I had to reboot it starting from the last safe point, otherwise Windows would just crash again. Bottom line: I couldn't run Combofix. This happened another couple of times in the past days, before resorting to following your cleaning instructions in the right sequence and posting this.
    - Unfortunately, after running Combofix (and after Superantispyware and Malwarebytes' Antimalware , I discovered that my internet connection was no longer working properly - neither through wi-fi nor through ethernet. I tried to "repair" the connection as suggested in your SAS guide, but nothing happened.

    So now I'm left with two huge problems: the possible atapi.sys infection and my Internet connection broken. Really hope you can help me with this. As you can imagine, without my netbook I'm quite lost when flying from a European country to another.

    Again, thanks in advance.

    Leonardo
     

    Attached Files:

  2. Leor

    Leor Private E-2

    And here's TDSSkiller's log, reporting atapi.sys as infected. Hope it helps. Thanks again!
    L.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    atapi.sys is likely not the problem which would explain why you may still be having problems after running TDSSkiller. New forms of TDSS are not properly detected by Kaspersky and they indite the wrong file as a result. If you still have redirection issues, after having run TDSSkiller many times (like you did) then it is not going to help you at this time until they can provide a proper update.

    Please run the below and attach the log from GMER.

    GMER - running with a random name


    For your internet connection issue, check to see if it is just the below:

    Proxy Server - Changing Settings
     
  4. Leor

    Leor Private E-2

    Thank you, Chas.

    Here you go, the GMER log

    As for the Internet issue, unfortunately fiddling around with the Proxy settings didn't help much.

    I'm beginning to think that maybe I should simply restore the OS... :tired
     

    Attached Files:

  5. Leor

    Leor Private E-2

    Hello again. I finally opted for restoring the OS, since the whole Internet thing made it impossible to use and the netbook was needed right away. But I wanted to thank you for taking the time to help. Really appreciated!
    Cheers.
    Leonardo
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds