Austech  


Go Back   Austech > Technology > Security and Privacy
Register Forum RulesiTrader Mark Forums Read

Security and Privacy Spyware , Proxies , all security and privacy issues and software.

Reply
 
LinkBack Thread Tools Display Modes
Old 14-11-09, 10:30 AM   #1 (permalink)
Senior Member
 
me_ashman's Avatar
 
Join Date: Jan 2008
Posts: 268
Thanks: 26
Thanked 0 Times in 0 Posts
Rep Power: 8
me_ashman is on a distinguished road
Default atapi.sys Olmarik.PY virus

Nod picked this up yesterday morning and I cant seem to clean it. Anyone come across this before?

Win7

Ash
me_ashman is offline   Reply With Quote
Old 14-11-09, 12:22 PM   #2
Super Moderator
 
ssrattus's Avatar
 
Join Date: Jan 2008
Posts: 2,614
Thanks: 86
Thanked 165 Times in 104 Posts
Rep Power: 25
ssrattus is a name known to allssrattus is a name known to allssrattus is a name known to allssrattus is a name known to allssrattus is a name known to allssrattus is a name known to all
Default

Have you tried booting into safe mode (press f9 on boot) and cleaning it in safe mode? Malwarebytes has a good cleaner...
ssrattus is offline   Reply With Quote
Old 15-11-09, 02:55 PM   #3
Senior Member
 
me_ashman's Avatar
 
Join Date: Jan 2008
Posts: 268
Thanks: 26
Thanked 0 Times in 0 Posts
Rep Power: 8
me_ashman is on a distinguished road
Default

yeah tried it..I'll keep reading
me_ashman is offline   Reply With Quote
Old 15-11-09, 03:56 PM   #4
Super Moderator
 
ssrattus's Avatar
 
Join Date: Jan 2008
Posts: 2,614
Thanks: 86
Thanked 165 Times in 104 Posts
Rep Power: 25
ssrattus is a name known to allssrattus is a name known to allssrattus is a name known to allssrattus is a name known to allssrattus is a name known to allssrattus is a name known to all
Default

You are probably going to have to boot from your OS CD (what is it xp or vista?) into recovery console and expand atapi.sys from the cd and replace the existing atapi.sys.

From the recovery console cmd window check where the infected atapi.sys is, ie it should be c:\windows\system32\drivers\


Then from the recovery console cmd window change directory to the i386 directory on the cd and type in "expand -r atapi.sy_ c:\windows\system32\drivers\", without the quotes and this will write the clean atapi.sys over the infected atapi.sys.


If this works reset your system restore to stop windows restoring it in the future...

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
ssrattus is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
virus fighter malo Security and Privacy 0 23-12-08 11:14 AM
Virus Fighter crowbar Security and Privacy 7 23-08-08 04:08 PM
Virus help =S jimbahh PC Software 7 13-03-08 04:37 PM


All times are GMT +11. The time now is 04:21 AM.


Powered by vBulletin™
Copyright © vBulletin Solutions, Inc. All rights reserved.
Ad Management plugin by RedTyger