<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Nasty New Rootkit Patches Atapi.sys</title>
	<atom:link href="http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/feed/" rel="self" type="application/rss+xml" />
	<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/</link>
	<description></description>
	<lastBuildDate>Wed, 17 Mar 2010 05:57:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: BuddyS</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5679</link>
		<dc:creator>BuddyS</dc:creator>
		<pubDate>Thu, 18 Feb 2010 07:39:36 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5679</guid>
		<description>MalwareBytes (free) includes FileAssassin, which can delete the file directly from within Windows.  Then you can replace the file with a fresh, clean copy.  (I&#039;m going to try using a copy from the sp3.cab on the same drive.)</description>
		<content:encoded><![CDATA[<p>MalwareBytes (free) includes FileAssassin, which can delete the file directly from within Windows.  Then you can replace the file with a fresh, clean copy.  (I&#8217;m going to try using a copy from the sp3.cab on the same drive.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Captiosus</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5559</link>
		<dc:creator>Captiosus</dc:creator>
		<pubDate>Fri, 29 Jan 2010 19:36:35 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5559</guid>
		<description>the one i got came in a &quot;package&quot; with a whole slew of other viruses. After killing them off, the one in the atapi.sys file stayed behind.

How i got rid of the SOB:
1. burn a linux live CD (get Puppy linux if you are impatient, only about 400MB)
2. memorize the location of atapi.sys, you will need to know this
3. get a working copy of windows on another machine or hard drive, navigate to the same directory ON THAT SYSTEM where the clean atapi.sys file is located, and copy to a flash drive
4. reboot the infected computer with the liveCD in it, it should load the disk.
5. open 2 windows in linux, 1 to the directory where the infected file is, and another to the flash drive.
6. copy the clean file OFF THE FLASH DRIVE to the directory where the infected file is, and overwrite it. Alternatively, delete the infected file first before copying.
7. reboot, and make sure the liveCD is out before it starts loading.

thats what i did, and it worked like a charm.</description>
		<content:encoded><![CDATA[<p>the one i got came in a &#8220;package&#8221; with a whole slew of other viruses. After killing them off, the one in the atapi.sys file stayed behind.</p>
<p>How i got rid of the SOB:<br />
1. burn a linux live CD (get Puppy linux if you are impatient, only about 400MB)<br />
2. memorize the location of atapi.sys, you will need to know this<br />
3. get a working copy of windows on another machine or hard drive, navigate to the same directory ON THAT SYSTEM where the clean atapi.sys file is located, and copy to a flash drive<br />
4. reboot the infected computer with the liveCD in it, it should load the disk.<br />
5. open 2 windows in linux, 1 to the directory where the infected file is, and another to the flash drive.<br />
6. copy the clean file OFF THE FLASH DRIVE to the directory where the infected file is, and overwrite it. Alternatively, delete the infected file first before copying.<br />
7. reboot, and make sure the liveCD is out before it starts loading.</p>
<p>thats what i did, and it worked like a charm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TwoCats</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5389</link>
		<dc:creator>TwoCats</dc:creator>
		<pubDate>Fri, 15 Jan 2010 02:46:17 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5389</guid>
		<description>Mine created a fake svchost.exe in win\temp every 5 minutes on the dot. There was extensive communication with a couple IP addresses registered to RIPE Network Coordination Centre. Some of the malware my (now ex-)AV software managed to catch were keyloggers.  
If it weren&#039;t for the stupid redirects I&#039;m not so sure I would have even noticed this one. My &#039;security&#039; software sure didn&#039;t.</description>
		<content:encoded><![CDATA[<p>Mine created a fake svchost.exe in win\temp every 5 minutes on the dot. There was extensive communication with a couple IP addresses registered to RIPE Network Coordination Centre. Some of the malware my (now ex-)AV software managed to catch were keyloggers.<br />
If it weren&#8217;t for the stupid redirects I&#8217;m not so sure I would have even noticed this one. My &#8217;security&#8217; software sure didn&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5383</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Thu, 14 Jan 2010 19:36:17 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5383</guid>
		<description>Does anyone have extensive information on what this rootkit actually does? Does it only redirect searches or does it have other malicious uses as well?</description>
		<content:encoded><![CDATA[<p>Does anyone have extensive information on what this rootkit actually does? Does it only redirect searches or does it have other malicious uses as well?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TwoCats</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5367</link>
		<dc:creator>TwoCats</dc:creator>
		<pubDate>Wed, 13 Jan 2010 02:42:12 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5367</guid>
		<description>There are 2 instances of atapi.sys in Windows -&gt; in system\drivers AND system32\dllcache.  Both will be infected by this rootkit. If you don&#039;t overwrite both it&#039;ll keep coming back after every boot.</description>
		<content:encoded><![CDATA[<p>There are 2 instances of atapi.sys in Windows -&gt; in system\drivers AND system32\dllcache.  Both will be infected by this rootkit. If you don&#8217;t overwrite both it&#8217;ll keep coming back after every boot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AndrewBrooklyn</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5259</link>
		<dc:creator>AndrewBrooklyn</dc:creator>
		<pubDate>Tue, 05 Jan 2010 04:27:28 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5259</guid>
		<description>Wow! Great news -- I&#039;ll certainly be looking forward to it!</description>
		<content:encoded><![CDATA[<p>Wow! Great news &#8212; I&#8217;ll certainly be looking forward to it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: malwarekilla</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5253</link>
		<dc:creator>malwarekilla</dc:creator>
		<pubDate>Tue, 05 Jan 2010 02:15:48 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5253</guid>
		<description>AndrewBrooklyn - I&#039;m releasing a guide on this issue tomorrow morning (C.S.T)...it&#039;ll be called something like &quot;How To Remove and Clean Up the TDSS Malware Pack&quot;...somthin like that.   I would post it tonight but I&#039;m actually removing those infections on client PC&#039;s as week speak.  Stay tuned.</description>
		<content:encoded><![CDATA[<p>AndrewBrooklyn &#8211; I&#8217;m releasing a guide on this issue tomorrow morning (C.S.T)&#8230;it&#8217;ll be called something like &#8220;How To Remove and Clean Up the TDSS Malware Pack&#8221;&#8230;somthin like that.   I would post it tonight but I&#8217;m actually removing those infections on client PC&#8217;s as week speak.  Stay tuned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AndrewBrooklyn</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5250</link>
		<dc:creator>AndrewBrooklyn</dc:creator>
		<pubDate>Mon, 04 Jan 2010 23:25:20 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5250</guid>
		<description>Okay --

ComboFix got rid of the bad ATAPI.SYS, but when I rebooted, I just got the blue screen of death. 

Found out that atapi.sys was missing from the \windows\system32\drivers directory. 

I put it back using recovery console. I booted up with no problems.

However, atapi.sys keeps deleting itself from the drivers directory, and every time I boot my machine, I have to go into recovery console and copy the file over again. Frustrating to say the least!

Any ideas?</description>
		<content:encoded><![CDATA[<p>Okay &#8211;</p>
<p>ComboFix got rid of the bad ATAPI.SYS, but when I rebooted, I just got the blue screen of death. </p>
<p>Found out that atapi.sys was missing from the \windows\system32\drivers directory. </p>
<p>I put it back using recovery console. I booted up with no problems.</p>
<p>However, atapi.sys keeps deleting itself from the drivers directory, and every time I boot my machine, I have to go into recovery console and copy the file over again. Frustrating to say the least!</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gordo</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5216</link>
		<dc:creator>Gordo</dc:creator>
		<pubDate>Fri, 01 Jan 2010 04:46:11 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5216</guid>
		<description>I got zapped with this trojan which messed up my atapi.sys file. Combofix has been helpful but my IE7 and Firefox search engines are still being redirected and I am being attack every 20 minutes or so from this ip address 212.117.174.176 

Malwarebytes has also been helpfull and removed a handfull of viruses and trojans. But the atapi.sys infection is a nasty one to fix.

In the mean time I&#039;ve down loaded a very cool keystroke encrytor called Keyscambler which I highly recommend. I got it from Majorgeeks.com 

I need a clean machine as I am unemployed and use it for job searching and submitting resumes. Glad to get 2009 over with. Bring on the new decade.

Happy New Years!</description>
		<content:encoded><![CDATA[<p>I got zapped with this trojan which messed up my atapi.sys file. Combofix has been helpful but my IE7 and Firefox search engines are still being redirected and I am being attack every 20 minutes or so from this ip address 212.117.174.176 </p>
<p>Malwarebytes has also been helpfull and removed a handfull of viruses and trojans. But the atapi.sys infection is a nasty one to fix.</p>
<p>In the mean time I&#8217;ve down loaded a very cool keystroke encrytor called Keyscambler which I highly recommend. I got it from Majorgeeks.com </p>
<p>I need a clean machine as I am unemployed and use it for job searching and submitting resumes. Glad to get 2009 over with. Bring on the new decade.</p>
<p>Happy New Years!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/comment-page-1/#comment-5207</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Thu, 31 Dec 2009 05:51:36 +0000</pubDate>
		<guid isPermaLink="false">http://remove-malware.com/?p=1930#comment-5207</guid>
		<description>I have the same problem, apprently it is the &#039;win32:Alureon&#039; virus. 
I just hope it havent send any of my passwords to its source</description>
		<content:encoded><![CDATA[<p>I have the same problem, apprently it is the &#8216;win32:Alureon&#8217; virus.<br />
I just hope it havent send any of my passwords to its source</p>
]]></content:encoded>
	</item>
</channel>
</rss>
