BAD: KB977165 - uninstall or do not install VIRUS: Still none found. My Windows 7 cd does not allow for the work-around suggested here. Click Save. Reinstalling Windows will erase everything from your hard drive, allowing you to start again with a fresh system. have a peek here

Rootkit taking over my system, atapi.sys BSODvirus Bybchung Jun 30, 2012

Bsod stop:0x0000008E ATAPI.sys - address F749459D base at F748A000, datestamp 4110764d. To manually repair your Windows registry, first you need to create a backup by exporting a portion of the registry related to ATAPI.SYS (eg. Also, an infected atapi.sys will generally redirect most of your searches to seemingly random assures and attack sites.

DO NOT hit ENTER yet! It may take a little longer for the Desktop to appear than it does when you start your computer normally. Security vendor Kaspersky Lab has released a standalone utility that removes the TDSS infection, however.Users must first remove the rootkit from their hard drive before they can repair the issue or So it is usefull ...

Richard Reddy can be infected by Backdoor.tidserv!inf Wildfire (further information) Microsoft patch KB977165 or MS10-015 (Feb'10) originally caused BSOD if this file was infected by the Allureon rootkit. Atapi.sys Windows 10 I close my topics if you have not replied in 5 days. Contents of the 'Scheduled Tasks' folder . 2012-06-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 04:51] . 2011-06-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 00:57] . 2012-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cd06d69c0c3a6c.job - c:\program System works now.

The free file information forum can help you determine if atapi.sys is a Windows system file or if it belongs to an application that you can trust. Jul 2, 2012 #21 bchung TS Rookie Topic Starter Posts: 38 I tried aswMBR, and sadly it did not work. You can use PowerSuite Golden to fix Atapi.sys Blue Screen error Kategori Bilim ve Teknoloji Lisans Standart YouTube Lisansı Daha fazla göster Daha az göster Yükleniyor... web Cureit, Kaspersky tdsskiller, Hitman Pro are good choices for "fixes".

Once the computer is totally clean, I'll certainly let you know. R0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys [6/10/2011 11:44 PM 135032] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [3/11/2012 9:13 PM 494968] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [3/11/2012 9:13 PM 31704] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011

Microsoft) device drivers or critical system files that come as part of the Windows operating system. navigate here If there is no internet connection after running Combofix, then restart your computer to restore back your connection. BetaFlux 3.554.761 görüntüleme 6:36 Fix: Stop 0×0000007A KERNEL_DATA_INPAGE_ERROR Win32k.SYS by Britec - Süre: 9:19. A widely held myth says Google eavesdrops on your life to improve search results. What Does Atapi Sys Do

May be you just found yet another variant/generation. BSoD at startup! - Süre: 1:30. Windows XP Home Edition Blue Screen - STOP: 0x0000007A__ATAPI.sys__physical memory dump Technical Info: ***STOP: 0x0000007A (0xC03E13C0, 0xC000000E, 0xF84F0302, 0x1FE29860) ***ATAPI.sys - Address F84F0302 base at F84DF000, DateStamp 4802539d Beginning dump of Check This Out Antivirus Version Last Update Result a-squared4.5.0.502010.02.13- AhnLab-V35.0.0.22010.02.12- AntiVir7.9.1.1602010.02.12- Antiy-AVL2.0.3.72010.02.13- Authentium5.2.0.52010.02.13- Avast4.8.1351.02010.02.12- AVG9.0.0.7302010.02.12- BitDefender7.22010.02.13- CAT-QuickHeal10.002010.02.13- ClamAV0.96.0.0-git2010.02.13- Comodo39202010.02.13- DrWeb5.0.1.122222010.02.13- eSafe7.0.17.02010.02.11Win32.Rootkit eTrust-Vet35.2.73002010.02.12- F-Prot4.5.1.852010.02.12- F-Secure9.0.15370.02010.02.13- Fortinet4.0.14.02010.02.13- GData192010.02.13- IkarusT3. Jiangmin13.0.9002010.02.08- K7AntiVirus7.10.9722010.02.12- Kaspersky7.0.0.1252010.02.13- McAfee58902010.02.12- McAfee+Artemis58902010.02.12- McAfee-GW-Edition6.8.52010.02.13- Microsoft1.54062010.02.13-

I don't think it halted since pc clock is running. Jun 30, 2012 #2 bchung TS Rookie Topic Starter Posts: 38 Hello, Thanks for replying. Midway thought the scan, about 10% in, I get a BSOD.

It is a Windows system file.

or use 64bit modern Windows ;) Hitman Pro guy made this post http://www.wilderssecurity.com/showthread.php?t=265297 saying 75% of the cleaned computers had updated AV. Privacy Policy

Login _ Social Sharing Find TechSpot on... Permalink Submitted by Juanjo (not verified) on Sat, 02/13/2010 - 06:43 I don't get it... These sites distribute SYS files that are unapproved by the official ATAPI.SYS file developer, and can often be bundled with virus-infected or other malicious files.

Save it to your desktop. Tony used for optical drives, ie. Today I had four machines that exhibited symptoms that pointed to a MS security updates being the cause. this contact form Even if you are experienced at finding, downloading, and manually updating drivers, the process can still be very time consuming and extremely irritating.

It downloads different versions of trojans and itself comes in different flavors. Using the site is easy and fun. Malwarebytes Anti-Malware detects and removes sleeping spyware, adware, Trojans, keyloggers, malware and trackers from your hard drive. The Windows Update dialog box will appear.

scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet005\Services\epstwnt] "ImagePath"="System32\Drivers\epstwnt.mpd" . [HKEY_LOCAL_MACHINE\System\ControlSet005\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-1210614011-2585739803-2429135735-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-1210614011-2585739803-2429135735-1006\Software\Policies\Microsoft\SystemCertificates\AddressBook*] UPDATE: An atapi.sys infection may not be the only cause of this blue screen.