Forum Home
Press F1
 
Thread ID: 128965 2013-01-25 23:04:00 computer is insane ,_ Vince (406) Press F1
Post ID Timestamp Content User
1324948 2013-02-12 03:56:00 You may have an infected atapi.sys file? Is your computer crashing?

It is not crashing, but it is being very difficult.
Vince (406)
1324949 2013-02-12 04:00:00 I would select cure then reboot. Hopefully it boots after Speedy Gonzales (78)
1324950 2013-02-12 04:13:00 I would select cure then reboot. Hopefully it boots after

Cure isn't one of the options. They are Skip, Copy To Quarantine, and Delete. Presumably you mean 'Delete'
Vince (406)
1324951 2013-02-12 04:37:00 Was this tdsskiller?? I cant remember it having a delete option Speedy Gonzales (78)
1324952 2013-02-12 05:04:00 Was this tdsskiller?? I cant remember it having a delete option

Number 19 above!
Vince (406)
1324953 2013-02-12 05:11:00 Suppose you have to delete it then. Whether it reboots after tho is another matter. And whats Avafind Speedy Gonzales (78)
1324954 2013-02-12 07:19:00 Avafind is a very useful free-ware program that maintains an up to date database of all files on a computer.
It loads quickly and provides the location of every instance of files containing the letters you type in, without having to do a search. It is FAST!
Vince (406)
1324955 2013-02-12 07:39:00 Avafind ok I have used it for years on all my computers. zqwerty (97)
1324956 2013-02-15 13:09:00 Suppose you have to delete it then. Whether it reboots after tho is another matter. And whats Avafind

I found atapi.sys in lots of folders, so I copied a new one to the folder in question, after deleting the suspect one. I restarted and UnhacMe did a boot time scan. Then Tdsskiler did a scan. The result was that the .exe files listed below were found again!
They were not missing, they are invisible to the system. That is they were until they were deleted. Except for service atapi, which I am afraid to delete lest the computer wont start! Service atapi seems to be invisible as well.
My problems are still with me, unfortunatly.
O23 - Service: AVEPCOYVYOKME - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\AVEPCOYVYOKME.e xe (file missing)
O23 - Service: BJDW - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\BJDW.exe (file missing)
O23 - Service: DGRPGF - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\DGRPGF.exe (file missing)
O23 - Service: GFK - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\GFK.exe (file missing)
O23 - Service: HHBBYQGCDZ - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\HHBBYQGCDZ.exe (file missing)
O23 - Service: KTID - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\KTID.exe (file missing)
O23 - Service: LHCFBI - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\LHCFBI.exe (file missing)
O23 - Service: PRJDHPYM - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\PRJDHPYM.exe (file missing)
O23 - Service: YPPNSYUZIEB - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\YPPNSYUZIEB.exe (file missing)
O23 - Service: YXNJIBZ - Unknown owner - C:\DOCUME~1\VINCEN~1\LOCALS~1\Temp\YXNJIBZ.exe (file missing)
Vince (406)
1324957 2013-02-15 19:14:00 format it. That'll fix it Speedy Gonzales (78)
1 2 3 4