BleepingComputer.com: Google search results redirected - Solved by ComboFix

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Google search results redirected - Solved by ComboFix

#1 User is offline   Rich Pasco 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 21-January 10
  • Location:San Jose CA & Land O Lakes FL

  Posted 21 January 2010 - 11:31 PM

Today I too fell victim to the common malware which hijacks Firefox so that clicking on Google search results leads to a page of advertising instead of the intended target. Following the instructions here I was able to use Combofix to remove the infection. I am very grateful. However, I do have a question about a message in the results log. It read,
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p

My question is, exactly what is meant by the phrase "Kitty ate it :p" in this context? From where did Combofix get the uncorrupted version of atapi.sys? or does this mean that Combofix was able to un-patch the file on my system so as to remove the malicious code?

- Rich

#2 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,513
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 22 January 2010 - 10:50 AM

It means CF found an infected atapi.sys and restored a good copy it found in another location on your system such as c:\windows\ServicePackFiles\i386\ or c:\windows\system32\dllcache.

Kitty ate it was the developer's way of adding humor to the infected file going bye, bye.

Although your issue has been resolved, it is not a safe practice to be following specific instructions provided to someone else especially if they were given in the HijackThis forum. Those instructions were most likely given under the guidance of a trained staff helper to fix that particular member's problems, NOT YOURS after careful evaluation of the malware involved. Before taking any action, the helper must investigate the nature of the infection and then formulate a fix for the victim. Although your problem may be similar, the solution could be different based on the kind of hardware, software, system requirements, etc. and the presence of other malware. Using someone else's fix instructions could lead to disastrous problems with your operating system.

If you need assistance in the future, it's best that you tell us what specific issues YOU are having rather than point to someone else. That's what this forum is for so feel free to start your own topic anytime and someone will assist you with your issues specifically.

Thanks for your cooperation.
The BC Staff
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users