Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Monday, December 7, 2009

How to fix atapi.sys Packed.Protector.C trojan warning by Avg?

I got some virus called av_dm.exe. Check your startup programs with msconfig to find where it is located, delete it from everywhere and untick these entries from msconfig startup.

It fixed the process which ate the CPU, but AVG still complained about a trojan in atapi.sys


I didn't know what to do with it, because AVG couldn't remove it, so I downloaded the service pack for XP manually (search for it on Google), and renamed it to .cab, so I can look into it. Renamed the trojan atapi.sys to .bak in case the fix doesn't work, copied atapi.sys from the service pack and rebooted.

This eliminated the warnings by AVG. Let me know if it works for you or if you have a better idea how to deal with this pest.

Thursday, September 3, 2009

exiap6415386.exe creeped into my windows startup

During browsing the computer suddenly rebooted itself. This was suspicious, I instantly thought some badware installed itself and rebooted, so it can hook into the boot process. When Windows restarted something started to eat the CPU. Windows firewall warned about Conficker.C. Downloaded Conficker cleaners, they found nothing.

Booted into safe mode, checked startup with msconfig and exiap6415386.exe was there. Removed it and also svchost which was added to startup, but it wasn't there previously as far as I remember. Is my svhcost infected? >:-/

Now things seems okay, but I checked online exiap6415386. It is some new variant, antivirus tools don't even recognize it yet apparently.

Update: Spybot says it's SmitFraud.C Or is it a different one which also creeped in? :P

Update2: Make sure you always have a Live CD at home for situations like this, so you have a clean system to get info from the net about removing the badware. Using the infected OS is not a good idea. I used an Ubuntu Live CD, but any other will do.


Also, check out the comments here. There is good info there.