TargetSaver (Trojan Downloader)

  • Thread starter Thread starter Howard
  • Start date Start date
H

Howard

Removed by MS AntiSpyware Beta1 but seems to replicate
after removal. Here are the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\TSA
HKEY_LOCAL_MACHINE\SOFTWARE\TSA\update TSVersion 4.0.3.9
HKEY_LOCAL_MACHINE\SOFTWARE\TSA NewInstall 0

These are reported as removed but always appear in the
next scan(daily).
 
Howard said:
Removed by MS AntiSpyware Beta1 but seems to replicate
after removal. Here are the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\TSA
HKEY_LOCAL_MACHINE\SOFTWARE\TSA\update TSVersion 4.0.3.9
HKEY_LOCAL_MACHINE\SOFTWARE\TSA NewInstall 0

These are reported as removed but always appear in the
next scan(daily).

Try running MSAS in Safe Mode.
 
Go with Frank Saunders suggestion but i would like to
point out you are missing some area's , heres a copy of
my reply which i posted to a similar question (Its on the
same page as yours but further down the list)


Have you got a TSA entry on your add/remove screen if so
press it

This adware may include an uninstaller.

see if this file exists.

C:\Program Files\Common Files\tsuninst.exe.


If the file does exist, double-click it and follow any
prompts. After the uninstaller is finished, to make sure
that it has been removed, follow the instructions below.


Goto start then run and type:


regedit

Find this key,If you unsure either use the search feature
which you can get to by pressing "Edit" on the top bar
then "Find" or start with HKEY_LOCAL_MACHINE then click
the plus + beside it, Then find Software and click the
plus + and so on to you get to the Run folder.


HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersi
on\Run.


On the right, right-click the entry

Tsa

or

Tsa2

and choose 'Delete'.

It will look like this :

"Tsa2"="C:\PROGRA~1\COMMON~1\tsa\tsm2.exe"

Also check for and delete these :


HKEY_LOCAL_MACHINE\SOFTWARE\TSA
HKEY_LOCAL_MACHINE\SOFTWARE\Uninstall\TSA
HKEY_CURRENT_USER\SOFTWARE\TSA



Restart the computer and goto start then c\drive then
program files,then to the common files folder and
delte "tsa" if found

C:\Program Files\Common Files\tsa\
C:\Program Files\Common Files\tsa\rainbow



Andy
 
-----Original Message-----
Removed by MS AntiSpyware Beta1 but seems to replicate
after removal. Here are the registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\TSA
HKEY_LOCAL_MACHINE\SOFTWARE\TSA\update TSVersion 4.0.3.9
HKEY_LOCAL_MACHINE\SOFTWARE\TSA NewInstall 0

These are reported as removed but always appear in the
next scan(daily).
.it has installed a recycler that will keep regenerating
itself i have no definite solution i just reinstalled
windows when it happened to me that was the only way i
could get rid of it good luck there
 
sir if u are using xp try disabling system restore and
removing the spyware,other wise it may regenerate.
 
Back
Top