also @ TechSpot: Apple iOS 'Absinthe' jailbreak: 1 million downloads and counting

TechSpot

Problem: Malware in registry

Discussion in 'Virus and Malware Removal' started by Ventress, Nov 19, 2009.

Thread Status:
Not open for further replies.
  1. kimsland Ex-TechSpotter

    Did you run IE Reset, (as requested) 2 days ago? (^^ up there)
    Because many entries look to be individualized in your log
    You may want to do it again, with IE closed

    You can also open HJT scan only, and fix the following 3 entries:
    Then re-open Internet Explorer and run through the standard initial configurations by MS

    My biggest concern is this:
    But Kaspersky online scanner detected nothing
    We can just as easily copy another Atapi.sys from another computer, but do you have another computer running Windows Vista?
    If so, here is the command to copy Atapi.sys to your USB Flash Drive, from the other computer (please substitute F for your Flash drive drive letter)
    cmd /c copy C:\WINDOWS\system32\drivers\atapi.sys F:\ >log.txt&log.txt
    You will get notified: "1 file(s) copied"
    We can then copy this new file to your C:\, overwriting the old one
    But, do you have another computer to do this in the first place?

    Please run the following command, on the possible still infected computer:
    cmd /c dir /a c:\atapi.sys >log.txt&log.txt
    A text file opens, please post the content.
  2. Ventress Newcomer, in training

    I reseted IE again and fixed the 3 entries. I don't have another computer with Vista. Am I supposed to write cmd /c dir /a c:\atapi.sys >log.txt&log.txt in the command prompt? If I am then the file is not found.
  3. kimsland Ex-TechSpotter

    Lets just go with "fixmbr" for Vista ;) (this will not upset your files, but its always best to backup first)
    1. Boot from your Vista Disc
    2. Select "Repair your computer"
    3. Choose "Command prompt"
    4. Type in: bootrec /FixMbr and then press Enter
    Once completed then type Exit, and Restart

    Run another Combofix, and provide the log as an Attachment
  4. Ventress Newcomer, in training

    Did the fix and here's the combofix log.

    Attached Files:

  5. kimsland Ex-TechSpotter

    That looks better :grinthumb

    The fault before, actually (I believe) came from DAEMON Tools Lite
    All seems ok now, but if you do not use this program any longer, please uninstall it.

    Can I ask why you use "F-Secure" Antivirus?
    It is not one of the big players in the world (although been around for years) I don't feel that it has protected you this time
    If "F-Secure" Antivirus is nearing the end of its subscription (paid service) I would suggest uninstall it, and update to a better (IMO) Antivirus, such as the one I use (and have used for a long time) Free Avira Antivirus (oh and its free ;))

    Un-install Combofix
    • Click START [IMG] then RUN
    • Now type Combofix /uninstall in the runbox and click OK
    • Any popup errors about Antivirus just ok or close
    Note: 1 space after ComboFix in that uninstall command


    Remove old System Restore Points

    • Open System by clicking the Start button [IMG], right-clicking Computer, and then clicking Properties.
    • In the left pane, click System protection [IMG]. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
    • Under Protection Settings, click the disk, and then click Configure.
    • Click Turn off system protection, click OK, and then click OK again.
    Then turn it back on again.


    Restart, and let me know how its performing
  6. Ventress Newcomer, in training

    I've done everything you've asked so in other words I uninstalled Daemon tools lite when you first asked.
    The merchants here recommended F-Secure as the best in the market. Looks to me that it's a piece of crap. Well actually I'm certain that it's at least better than Norton. Unfortunately I have still 10 months left of subscribtion with F-Secure.
    I did what you requested in that last reply and everything seems to run without problems.
    Now I really appreciate how you've helped me get rid of these viruses and whatnot but I still have the same issue in msconfig. Under programs there still is this damn registry. Don't I need to worry about it? I would still want it to disappear from msconfig. What if I accidentally run it.
  7. kimsland Ex-TechSpotter

    Oh lol :) That thing, I forgot about that :D

    Download Msconfig Cleanup Tool
    And cleanup all disabled entries in there

    Note: I answered this without reading back on what the hec you were talking about :D
    But I'm pretty sure this will fix it

    Please Restart after running
  8. Ventress Newcomer, in training

    It's good that you didn't, got a lot of cleaning done. Msconfig Cleanup did the trick. Thank you kimsland! :)
  9. kimsland Ex-TechSpotter

    No probs :)

    I must go (I needed to go 15mins ago :( )
Thread Status:
Not open for further replies.