Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

TR/ATRAPS.Gen2 problem.. Need help! :( [Solved]


  • This topic is locked This topic is locked

#1
gabry0988

gabry0988

    Member

  • Member
  • PipPip
  • 19 posts
Hello

I read this topic http://www.geekstogo...psgen2-removal/ and thank to this topic I have removed this trojan. but when I scan with antivir, it says that there are 2 files infected with TR/ATRAPS.Gen2... C:\Windows\assembly\GAC_32\Desktop.ini and C:\Windows\assembly\GAC_64\Desktop.ini

I can't remove these files with antivir because they are protected. How can I do to completely remove this virus?

Thanks alot!
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there lets remove them for you and ensure that all the rest have gone

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

  • 0

#3
gabry0988

gabry0988

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
OTL.txt


Spoiler


Extra.txt

Spoiler



Antivir Full Scan

Spoiler


Thanks!

Edited by gabry0988, 16 June 2012 - 04:51 AM.

  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there I will need a bit of additional data - could you give the full path of the windows installer file that you deleted e.g. C:\Windows\Installer\{0e15582b-9a3d-5cb2-6072-738409e19f28} the main data I need is the numbers/leters in the curly bracket

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
To disable MBAM
Open the scanner and select the protection tab
Remove the tick from "Start with Windows"
Reboot and then run OTL
Posted Image

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Files
    ipconfig /flushdns /c
    C:\Windows\assembly\GAC_64\Desktop.ini
    C:\Windows\assembly\GAC_32\Desktop.ini
    netsh int ip reset reset.log hit /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#5
gabry0988

gabry0988

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Spoiler

  • 0

#6
gabry0988

gabry0988

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
I look with Antivir if it's removed, but it is still there...


C:\Windows\assembly\GAC_32\Desktop.ini
[RILEVAMENTO] Si tratta del cavallo di Troia TR/ATRAPS.Gen2
C:\Windows\assembly\GAC_64\Desktop.ini
[RILEVAMENTO] Si tratta del cavallo di Troia TR/ATRAPS.Gen2

Avvio della disinfezione:
C:\Windows\assembly\GAC_64\Desktop.ini
[RILEVAMENTO] Si tratta del cavallo di Troia TR/ATRAPS.Gen2
[AVVISO] Il file č stato ignorato.
C:\Windows\assembly\GAC_32\Desktop.ini
[RILEVAMENTO] Si tratta del cavallo di Troia TR/ATRAPS.Gen2
[AVVISO] Il file č stato ignorato.
  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK this is becoming quite regular now the wshelper dll is missing ... Lets search for it

Run OTL and copy paste the following into the custom scans and fixes box

/md5start
WSHELPER.*
/md5stop

Press quick scan and post the resultant log please
  • 0

#8
gabry0988

gabry0988

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Spoiler

  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets try again :cool:

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
To disable MBAM
Open the scanner and select the protection tab
Remove the tick from "Start with Windows"
Reboot and then run OTL
Posted Image

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Files
    ipconfig /flushdns /c
    C:\Windows\system32\wshelper.dll|C:\Windows\SysWOW64\wshelper.dll /replace
    %windir%\System32\regsvr32.exe %windir%\System32\wshelper.dll /c
    netsh int ip reset reset.log hit /c

    :Commands
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#10
gabry0988

gabry0988

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
it gives me an error: Impossibile caricare la seguente DLL dell'helper: WSHELPER.DLL.

This is the log

Spoiler

  • 0

Advertisements


#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets try another route... This is one of my many attempts to try and repair this damage caused by the malware but, I just need to get the right format to make it work

Download the following zip folder and extract the file to C:\windows\system32

[attachment=58425:wshelper.zip]

Run OTL again with this fix

:Files
ipconfig /flushdns /c
%windir%\System32\regsvr32.exe %windir%\System32\wshelper.dll /c
netsh int ip reset reset.log hit /c

  • 0

#12
gabry0988

gabry0988

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
I can't copy that because there is another file in system32 named wshelper and is protected
  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK I am now checking it out on my system

Run OTL with the following scan please


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh /s
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NetSh /s

  • 0

#14
gabry0988

gabry0988

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Spoiler

  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Bear with me please I will need to run some comparisons
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP