Win32 Atraps pf and Malware gen help

Please help avast is going crazy and i need support i read the other topics but i just dont want to lose any of the files or screw up my computer anymore >:(

Please can anyone help.

Sorry forgot to include the logs!

hey and welcome to the forum. a malware expert will check those logs and guide you from there. but until someone do that i suggest you complete the guide by running malwarebytes anti malware as well and see what that finds.

http://filehippo.com/download_malwarebytes_anti_malware/

good luck.

Hi do you want me to continue here or at G2G ?

thank you very much so i just download and scan? Post log?

Ummm its up to you i forgot to post logs at g2g

OK as I have the logs here I will close the G2G thread and continue here

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF

:OTL O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft) O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft) [2012/07/03 18:43:16 | 000,000,000 | ---D | C] -- C:\Users\Sullivans\AppData\Local\Best Buy pc app [2012/07/03 18:23:09 | 000,000,000 | ---D | C] -- C:\Users\Sullivans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy

:Files
ipconfig /flushdns /c
C:\Windows\Installer{f9af98a8-d13f-b577-d0ff-34bc96028e93}
C:\Users\Sullivan\AppData\Local{f9af98a8-d13f-b577-d0ff-34bc96028e93}
C:\Windows\assembly\GAC_32\Desktop.ini
C:\Windows\assembly\GAC_64\Desktop.ini

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Okay thanks ill try it so just run those does it reboot after combofix?

Yes combofix will automatically reboot for you

Okay if you are still there i have the 2 otl files now what do i do the combo fix thing?

yes now run combofix, that will take out the final element

How long do i disable the avast also do you know how i can save it to my desktop thru google chrome?

Right click the link and select save as… Then select the desktop as the target

Right click the Orange blob > Select Shield Control > Select disable till reboot

Combofix will complain about Avast but run it anyway

I am doing it right now but it might be stuck at stage 6 in the cmd window I’m not sure? Nevermind it moved just took a while!

If it does not move on soon let me know and we will take a different route

Nope it is good.

;D

It just rebooted but now whenever I try to open Internet it says error application deletion or something I’m on my phone.

Yes a reboot will clear that

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.