MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 08-02-12, 10:14
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Avira Pop-ups "TR/ATRAPS.Gen2

Have looked through the threads and found what appears to be the same problem - "TR/ATRAPS.Gen2".

I have followed the Redirect and Malware guides and still have the issue with Avira popping up - finding the above virus.

Also the virus' detected were as follows from Avira:
Object Detection
services.exe W32/Patched.UA
80000064.@ TR/ATRAPS.Gen2
Attached Files
File Type: log HitmanPro_20120802_0910.log (13.5 KB, 3 views)
File Type: txt mbam-log-2012-08-02 (08-30-16).txt (2.1 KB, 3 views)
File Type: zip MGlogs.zip (326.7 KB, 3 views)
File Type: txt RKreport[1].txt (3.3 KB, 3 views)
Reply With Quote
Sponsored links
  #2  
Old 08-02-12, 10:17
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

Additional files
Attached Files
File Type: txt QuarantineReport.txt (713 Bytes, 1 views)
File Type: txt TDSSKiller.2.7.48.0_02.08.2012_07.39.00_log.txt (241.3 KB, 1 views)
Reply With Quote
  #3  
Old 08-02-12, 14:14
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,432 Times in 1,355 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

Hello tantram61

Delete items using RogueKiller.

Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
When it opens, press the Scan button
Once the scan is complete, go to the Registry tab and checkmark everything except the below items:
  • [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0)
  • [HJ] HKLM\[...]\System : EnableLUA (0)
Now press the Delete button.
When it is finished, there should be a couple of new RogueKiller logs on your desktop.
Attach the latest one to your next message. (How to attach)

__

- Rescan with HitmanPro

This time if the below detections are found, choose the action I've listed below:
  • services.exe - Virus ==> Replace
  • Desktop.ini - Trojan ==> Delete
Ignore any other detections and click the Next button.
HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

__

Once you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro log. (How to attach)

__

Completely delete these two folders manually using Windows Explorer:
  • c:\windows\installer\{92fa28bf-84db-e36c-4a5c-94c008f958a7}
  • c:\users\nelida antram\appdata\local\{92fa28bf-84db-e36c-4a5c-94c008f958a7}

Let me know if you were successful or not.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #4  
Old 08-04-12, 10:04
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

I was able to run everything and I have attached the files. I don't have Avira popping up with virus finds - so I am keeping my fingers crossed. If Avira doesn't find any thing for the rest of the day I will let you know!
Attached Files
File Type: log HitmanPro_20120804_0959.log (5.1 KB, 2 views)
File Type: txt RKreport[3].txt (3.2 KB, 4 views)
Reply With Quote
  #5  
Old 08-04-12, 13:08
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,432 Times in 1,355 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

Hi,

I'd like to review the RogueKiller log that you pressed Delete with.
The one you attached is just another scan (with the infections present).

Also run this scan using this tool:

Please download OTL by OldTimer.
  • Save it to your desktop.
  • Right mouse click on the OTL icon on your desktop and select Run as Administrator
  • Check the "Scan All Users" checkbox.
  • Check the "Standard Output".
  • Change the setting of "Drivers" and "Services" to "All"
  • Copy the text in the code box below and paste it into the text-field.
    Code:
    activex
    netsvcs
    /md5start
    services.exe
    /md5stop
  • Now click the button.
  • One report will be created:
    • OTL.txt <-- Will be opened
  • Attach OTL.txt to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Sponsored links
  #6  
Old 08-07-12, 09:36
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

The fixes seem to be working. Sorry I couldn't respond sooner - I work a weird schedule.

I have attached the files for roguekiller and OTL.

Thanks
Attached Files
File Type: txt OTL 08072012.Txt (262.7 KB, 2 views)
File Type: txt RKreport[2].txt (1.5 KB, 1 views)
Reply With Quote
  #7  
Old 08-07-12, 14:03
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,432 Times in 1,355 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

From Programs and Features (via Control Panel), please uninstall the below:
  • Java(TM) 6 Update 31 (outdated)

__

Fix items using OTL by OldTimer

Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
Copy the text in the code box below and paste it into the text-field.
Code:
:otl
IE - HKLM\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found
IE - HKLM\..\SearchScopes\{38bc6857-67fa-4358-afae-28e0f9ad2128}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YXxdm002CVus&ptnrS=YXxdm002CVus&si=CO2Pu__9irECFc3MKgodrGG61Q&ptb=C8773B29-0972-4E5B-9A7F-1824C59AB753&ind=2012070817&n=77edc3a1&psa=&st=sb&searchfor={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1320680
IE - HKU\S-1-5-21-2013776147-152033503-3419086030-1000\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\S-1-5-21-2013776147-152033503-3419086030-1000\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found
IE - HKU\S-1-5-21-2013776147-152033503-3419086030-1000\..\SearchScopes\{38bc6857-67fa-4358-afae-28e0f9ad2128}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YXxdm002CVus&ptnrS=YXxdm002CVus&si=CO2Pu__9irECFc3MKgodrGG61Q&ptb=C8773B29-0972-4E5B-9A7F-1824C59AB753&ind=2012070817&n=77edc3a1&psa=&st=sb&searchfor={searchTerms}
IE - HKU\S-1-5-21-2013776147-152033503-3419086030-1000\..\SearchScopes\{435065FA-F736-4396-AC7F-EF3758518CE8}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKU\S-1-5-21-2013776147-152033503-3419086030-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1320680
IE - HKU\S-1-5-21-2013776147-152033503-3419086030-1000\..\SearchScopes\{D414A51F-550E-4B6D-9B97-B4AC4A9D6E25}: "URL" = http://www.fastbrowsersearch.com/results/results.aspx?q={searchTerms}&c=web&s=DSP&v=19&tid={6FADC9B6-EB47-4dfa-8A1F-98336031D00C}
FF - prefs.js..browser.search.defaultthis.engineName: "Free Ride Games Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Free Ride Games Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT1320680&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&q="
[2012/07/02 09:23:02 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\Nelida Antram\AppData\Roaming\Mozilla\Firefox\Profiles\jfh2te6h.default\extensions\plugin@yontoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {f92a9fe4-2850-4198-b9d5-279880e49b16} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
[2012/07/27 09:35:50 | 000,000,000 | -HSD | C] -- C:\windows\SysWow64\%APPDATA%
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:E2B0AAB4
:files
dir /s "C:\Users\Nelida Antram\AppData\Roaming\xsecva" /c
C:\Users\Nelida Antram\AppData\Roaming\xsecva
dir /s "C:\Users\Nelida Antram\AppData\Roaming\49E46447" /c
C:\Users\Nelida Antram\AppData\Roaming\49E46447
dir /s "C:\Users\Nelida Antram\AppData\Local\{8AB3491A-D7F7-11E1-8270-B8AC6F996F26}" /c
c:\users\nelida antram\appdata\local\{92fa28bf-84db-e36c-4a5c-94c008f958a7}
c:\windows\installer\{92fa28bf-84db-e36c-4a5c-94c008f958a7}
C:\Users\Nelida Antram\AppData\Roaming\wcser.dll
C:\windows\WLXPGSS.SCR
c:\windows\assembly\gac_32\desktop.ini
c:\windows\assembly\gac_64\desktop.ini
C:\Program Files (x86)\Yontoo /d
:commands
[emptytemp]
Now click the button.
If the fix needed a reboot please do it.
Click the OK button (upon reboot).
When OTL is finished, Notepad will open. Close Notepad.
A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Attach this log to your next message. (How to attach)

__


Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
This updates all of the logs inside MGlogs.zip.
When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #8  
Old 08-07-12, 16:05
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

deleted the Java update (31) and ran MGTools and OTL the files are attached.
Attached Files
File Type: log 08072012_153344.log (21.9 KB, 1 views)
File Type: zip MGlogs.zip (323.1 KB, 2 views)
Reply With Quote
  #9  
Old 08-07-12, 17:06
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,432 Times in 1,355 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure all the options are checked
  • Press Scan.
  • It will create a log (FSS.txt) in the same directory the tool was run.
  • Please attach FSS.txt to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #10  
Old 08-07-12, 18:33
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

I have ran Farbar and attached the file. Thanks
Attached Files
File Type: txt FSS.txt (4.8 KB, 4 views)
Reply With Quote
Sponsored links
  #11  
Old 08-07-12, 18:41
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,432 Times in 1,355 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
  • Now open Repair_Windows.exe
  • Go to the Start Repairs tab.
  • Press the Start button
  • Create a System Restore point if prompted.
  • In the Repair Options window, choose the following repairs:
    • Reset Registry Permissions
    • Repair Windows Firewall
  • Place a checkmark in Restart/Shutdown System When Finished
  • Fill in the Restart System bubble
  • Now click the Start button.
  • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #12  
Old 08-07-12, 18:45
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,432 Times in 1,355 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

  • Download each of the five files below onto the desktop of the computer with the issues:
  • Now double-click each of them, one at a time, and allow each one to merge into the Windows registry.
  • Let me know if you received a successful message for all five files.
  • If all were successful, reboot your computer.

__

Now scan with Farbar Service Scanner again and attach its latest log.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #13  
Old 08-08-12, 06:18
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

I ran the Windows Repair and it seemed to go ok. Ran the 5 files and each was successful. Rebooted. Ran Farbar and have attached the file.

Thanks
Attached Files
File Type: txt FSS.txt (2.0 KB, 2 views)
Reply With Quote
  #14  
Old 08-08-12, 06:24
tantram61 tantram61 is offline
Private E-2
 
Join Date: May 2011
Location: Waxahachie,TX
Posts: 11
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

I did notice that from a banking account when I tried to pick a date it would not allow me. Java script was void. Do I need to download Java and install?
Reply With Quote
  #15  
Old 08-08-12, 13:41
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,432 Times in 1,355 Posts
Default Re: Avira Pop-ups "TR/ATRAPS.Gen2

Quote:
Originally Posted by tantram61 View Post
Do I need to download Java and install?
Yes but remember to keep it up to date. Malware creators often exploit old versions of Java, Adobe Reader, and Adobe Flash Player.
P.S. Is there a reason you are using such an old version of Mozilla Firefox?

Now install the current version of Sun Java from: here

Your latest FSS.txt looks perfect

If you are not having any other malware related problems, it is time to do our final steps:
  • Any programs we had you download and/or install can be removed at this time.
  • If we had you download and run ComboFix, here is how to uninstall it:
    • Press and hold the Windows key and then press the letter R on your keyboard.
    • This opens the Run dialog box.
    • Copy and paste the below text inside the text-field:
      • "%userprofile%\desktop\ComboFix" /uninstall
    • Now press ENTER
    • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
  • You can re-enable your Disk Emulation software at this time via DeFogger.
  • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
  • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
  • Now we will toggle System Restore to remove any infected system restore points.
  • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
  • Be safe
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Sponsored links
Reply

Tags
atraps, gen2, tr/atraps.gen2

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help! My computer has something called TR/ATRAPS.gen2! Sorenius Malware Removal 3 07-20-12 11:43
TR/ATRAPS.Gen2 and W32/Patched.UA (0.Access?!) nicklow Malware Removal 1 07-12-12 00:17
TR/ATRAPS.gen2 trojan NevTheTreeSurgeonYorkUK Malware Removal 22 06-24-12 17:23
Internet very sluggish - Avira finds TR/ATRAPS.Gen - Hidden Processes? grawr! zelda2727 Malware Removal 5 05-12-09 15:08
AVIRA "Found Application Error" rodell Software 0 03-09-09 14:01


All times are GMT -5. The time now is 00:53.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger