Trojan.Downloader.TargetSavers keeps coming back

  • Thread starter Thread starter Dhanna
  • Start date Start date
D

Dhanna

Can anyone advise how this spyware/threat could be
blocked. It took several scans of MSAS (with modem
switched off) to clear it. HOWEVER soon as I accessed
internet, its back.

Regards Dhanna
 
Reboot in safe mode and run a deep scan
Run antivirus (with current definitions) while you are in safe mode.

Microsoft AntiSpyware is not meant for detecting trojans.

Also, right click My Computer > Properties > System Restore > check "Turn
Off System Restore" then restart the machine in safe mode and run the scan
with your Antivirus program.

Restart in Safe mode instructions:
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx
--
Andre
Extended64 | http://www.extended64.com
Blog | http://www.extended64.com/blogs/andre
http://spaces.msn.com/members/adacosta
FAQ for MS AntiSpy http://www.geocities.com/marfer_mvp/FAQ_MSantispy.htm
 
Download Ccleaner :

http://download.ccleaner.com/download119bin.asp


This adware may include an uninstaller. The uninstaller
file is usually

C:\Program Files\Common Files\tsuninst.exe.

Using Windows Explorer, see if this file exists.


If the file does exist, double-click it and follow any
prompts. After the uninstaller is finished, to make sure
that the threat has been removed, follow the instructions
below.If you cant find the file carry on with this for
manual removal :

If you do not feel confident using Registry Edit then try
using Spybot or Adaware SE in safe mode and they may
remove any files that are left .

Ad-Aware SE :

http://www.download.com/3000-2144-10045910.html?
part=69274&subj=dlpage&tag=button


Spybot S&D

http://fileforum.betanews.com/download/Spybot_Search_and_D
estroy/1043809773/1



Manual Removal


Reboot into safe mode(reboot and keep tapping F8 untill
you see the option page then choose safe mode)



Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Run


In the right pane, delete the value:

"Tsa2"="C:\PROGRA~1\COMMON~1\tsa\tsm2.exe"


Navigate to and delete the following keys:

HKEY_LOCAL_MACHINE\SOFTWARE\TSA
HKEY_LOCAL_MACHINE\SOFTWARE\Uninstall\TSA
HKEY_CURRENT_USER\SOFTWARE\TSA
HKEY_USERS\S-1-5-21-1801674531-412668190-682003330-1007
\Software\TSA


Exit the Registry Editor.


Search for this folder and delete if it still exists:


C:\Program Files\Common Files\TSA



While insafe mode run MS Antispy on a full system scan

Then use Ccleaner on all 3 settings (windows,apps &
issues) and remove anything found & reboot




That should fully remove Target Saver but if you have any
problems let me know



Andy
 
If you get this in the future, make certain that the
prefetch folder (c:\windows\prefetch) doesn't contain
files with names containing the trojan, if so, shred then
using a freeware file shredder from download.com (use the
highest shred setting). This should fix the problem.

Alan
 
Back
Top