<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Nasty New Rootkit Patches Atapi.sys</title> <atom:link href="http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/feed/" rel="self" type="application/rss+xml" /><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/</link> <description>Antivirus Reviews For 2011 / 2012, Tools and How To&#039;s</description> <lastBuildDate>Mon, 21 May 2012 21:20:00 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.2</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: Dean-o</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-6944</link> <dc:creator>Dean-o</dc:creator> <pubDate>Mon, 28 Jun 2010 03:24:23 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-6944</guid> <description>The one that got me was actually a rootkit that infected Windows\system32\drivers\disk.sys
I couldn&#039;t kill it. It kept coming back. It had amazing powers, like it could hide the primary disk from the Windows Disk Management tool, or disable a USB keyboard during bootup to prevent going into safe mode.
What finally got rid of it? tdsskiller.
What didn&#039;t work for me? Hitman Pro, Hijack This, AVG Free, Spybot Search and Destroy, Malwarebytes, and Symantec.
Good luck to all in fighting this!</description> <content:encoded><![CDATA[<p>The one that got me was actually a rootkit that infected Windows\system32\drivers\disk.sys<br
/> I couldn&#8217;t kill it. It kept coming back. It had amazing powers, like it could hide the primary disk from the Windows Disk Management tool, or disable a USB keyboard during bootup to prevent going into safe mode.<br
/> What finally got rid of it? tdsskiller.<br
/> What didn&#8217;t work for me? Hitman Pro, Hijack This, AVG Free, Spybot Search and Destroy, Malwarebytes, and Symantec.<br
/> Good luck to all in fighting this!</p> ]]></content:encoded> </item> <item><title>By: rich</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-6841</link> <dc:creator>rich</dc:creator> <pubDate>Tue, 08 Jun 2010 19:55:38 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-6841</guid> <description>it is a TDSS rootkit. extremely hard to remove. wont let you use any antivirus. superantispyware and a bootcd are your only hope</description> <content:encoded><![CDATA[<p>it is a TDSS rootkit. extremely hard to remove. wont let you use any antivirus. superantispyware and a bootcd are your only hope</p> ]]></content:encoded> </item> <item><title>By: Billy</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-6612</link> <dc:creator>Billy</dc:creator> <pubDate>Mon, 10 May 2010 23:01:14 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-6612</guid> <description>will a reformat get rid of this SOB???...i cant install combofix and kapersky root killer finds it but it comes back after the reboot</description> <content:encoded><![CDATA[<p>will a reformat get rid of this SOB???&#8230;i cant install combofix and kapersky root killer finds it but it comes back after the reboot</p> ]]></content:encoded> </item> <item><title>By: BuddyS</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-5679</link> <dc:creator>BuddyS</dc:creator> <pubDate>Thu, 18 Feb 2010 07:39:36 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-5679</guid> <description>MalwareBytes (free) includes FileAssassin, which can delete the file directly from within Windows.  Then you can replace the file with a fresh, clean copy.  (I&#039;m going to try using a copy from the sp3.cab on the same drive.)</description> <content:encoded><![CDATA[<p>MalwareBytes (free) includes FileAssassin, which can delete the file directly from within Windows.  Then you can replace the file with a fresh, clean copy.  (I&#8217;m going to try using a copy from the sp3.cab on the same drive.)</p> ]]></content:encoded> </item> <item><title>By: Captiosus</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-5559</link> <dc:creator>Captiosus</dc:creator> <pubDate>Fri, 29 Jan 2010 19:36:35 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-5559</guid> <description>the one i got came in a &quot;package&quot; with a whole slew of other viruses. After killing them off, the one in the atapi.sys file stayed behind.How i got rid of the SOB:
1. burn a linux live CD (get Puppy linux if you are impatient, only about 400MB)
2. memorize the location of atapi.sys, you will need to know this
3. get a working copy of windows on another machine or hard drive, navigate to the same directory ON THAT SYSTEM where the clean atapi.sys file is located, and copy to a flash drive
4. reboot the infected computer with the liveCD in it, it should load the disk.
5. open 2 windows in linux, 1 to the directory where the infected file is, and another to the flash drive.
6. copy the clean file OFF THE FLASH DRIVE to the directory where the infected file is, and overwrite it. Alternatively, delete the infected file first before copying.
7. reboot, and make sure the liveCD is out before it starts loading.thats what i did, and it worked like a charm.</description> <content:encoded><![CDATA[<p>the one i got came in a &#8220;package&#8221; with a whole slew of other viruses. After killing them off, the one in the atapi.sys file stayed behind.</p><p>How i got rid of the SOB:<br
/> 1. burn a linux live CD (get Puppy linux if you are impatient, only about 400MB)<br
/> 2. memorize the location of atapi.sys, you will need to know this<br
/> 3. get a working copy of windows on another machine or hard drive, navigate to the same directory ON THAT SYSTEM where the clean atapi.sys file is located, and copy to a flash drive<br
/> 4. reboot the infected computer with the liveCD in it, it should load the disk.<br
/> 5. open 2 windows in linux, 1 to the directory where the infected file is, and another to the flash drive.<br
/> 6. copy the clean file OFF THE FLASH DRIVE to the directory where the infected file is, and overwrite it. Alternatively, delete the infected file first before copying.<br
/> 7. reboot, and make sure the liveCD is out before it starts loading.</p><p>thats what i did, and it worked like a charm.</p> ]]></content:encoded> </item> <item><title>By: TwoCats</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-5389</link> <dc:creator>TwoCats</dc:creator> <pubDate>Fri, 15 Jan 2010 02:46:17 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-5389</guid> <description>Mine created a fake svchost.exe in win\temp every 5 minutes on the dot. There was extensive communication with a couple IP addresses registered to RIPE Network Coordination Centre. Some of the malware my (now ex-)AV software managed to catch were keyloggers.
If it weren&#039;t for the stupid redirects I&#039;m not so sure I would have even noticed this one. My &#039;security&#039; software sure didn&#039;t.</description> <content:encoded><![CDATA[<p>Mine created a fake svchost.exe in win\temp every 5 minutes on the dot. There was extensive communication with a couple IP addresses registered to RIPE Network Coordination Centre. Some of the malware my (now ex-)AV software managed to catch were keyloggers.<br
/> If it weren&#8217;t for the stupid redirects I&#8217;m not so sure I would have even noticed this one. My &#8216;security&#8217; software sure didn&#8217;t.</p> ]]></content:encoded> </item> <item><title>By: Martin</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-5383</link> <dc:creator>Martin</dc:creator> <pubDate>Thu, 14 Jan 2010 19:36:17 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-5383</guid> <description>Does anyone have extensive information on what this rootkit actually does? Does it only redirect searches or does it have other malicious uses as well?</description> <content:encoded><![CDATA[<p>Does anyone have extensive information on what this rootkit actually does? Does it only redirect searches or does it have other malicious uses as well?</p> ]]></content:encoded> </item> <item><title>By: TwoCats</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-5367</link> <dc:creator>TwoCats</dc:creator> <pubDate>Wed, 13 Jan 2010 02:42:12 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-5367</guid> <description>There are 2 instances of atapi.sys in Windows -&gt; in system\drivers AND system32\dllcache.  Both will be infected by this rootkit. If you don&#039;t overwrite both it&#039;ll keep coming back after every boot.</description> <content:encoded><![CDATA[<p>There are 2 instances of atapi.sys in Windows -&gt; in system\drivers AND system32\dllcache.  Both will be infected by this rootkit. If you don&#8217;t overwrite both it&#8217;ll keep coming back after every boot.</p> ]]></content:encoded> </item> <item><title>By: AndrewBrooklyn</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-5259</link> <dc:creator>AndrewBrooklyn</dc:creator> <pubDate>Tue, 05 Jan 2010 04:27:28 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-5259</guid> <description>Wow! Great news -- I&#039;ll certainly be looking forward to it!</description> <content:encoded><![CDATA[<p>Wow! Great news &#8212; I&#8217;ll certainly be looking forward to it!</p> ]]></content:encoded> </item> <item><title>By: malwarekilla</title><link>http://remove-malware.com/malware/malware-warnings/nasty-new-rootkit-patches-atapi-sys/#comment-5253</link> <dc:creator>malwarekilla</dc:creator> <pubDate>Tue, 05 Jan 2010 02:15:48 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=1930#comment-5253</guid> <description>AndrewBrooklyn - I&#039;m releasing a guide on this issue tomorrow morning (C.S.T)...it&#039;ll be called something like &quot;How To Remove and Clean Up the TDSS Malware Pack&quot;...somthin like that.   I would post it tonight but I&#039;m actually removing those infections on client PC&#039;s as week speak.  Stay tuned.</description> <content:encoded><![CDATA[<p>AndrewBrooklyn &#8211; I&#8217;m releasing a guide on this issue tomorrow morning (C.S.T)&#8230;it&#8217;ll be called something like &#8220;How To Remove and Clean Up the TDSS Malware Pack&#8221;&#8230;somthin like that.   I would post it tonight but I&#8217;m actually removing those infections on client PC&#8217;s as week speak.  Stay tuned.</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 1/7 queries in 0.003 seconds using disk: basic
Object Caching 583/586 objects using disk: basic

Served from: remove-malware.com @ 2012-05-22 23:20:01 -->
