Lyndra,Banker,Tanspy Trojans Detected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by creaflexi, Oct 27, 2008.

  1. creaflexi

    creaflexi Private E-2

    Hi,
    recently I have run Spyware Doctor Search on my computer and discovered that I had trojan Lyndra present (Password Stealer and Key Logger). I have removed this trojan but then I got worried and tried other Spyware/Malware detection tools. Using the Pest Block software I discovered that another instance of the trojan was present this time Banker and Tanspy.
    I am running modded XP install called Performance Edition. The reason why I have started to be worried is that one of the guys who also installed the Performance Edition XP has pointed out that this Lyndra trojan was actually included in the OS, however many people are claiming that it is just false alarm.
    Since I am very happy with the release of the OS I would like to keep it installed on my computer, I just want to make sure that no Trojans/ Malware is present on many machine. As I said I have tried many different tools and I am helpless, since every tool gives me different results.
    Hope you can help me and clarify if I have any infections or if it is just false alarm.
    Thank you,
     

    Attached Files:

  2. creaflexi

    creaflexi Private E-2

    MGTools.zip follows
    Once again, thank you
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    HI just to let you know, we are looking at your logs and will get back to you as soon as we possibly can. :)
     
  4. creaflexi

    creaflexi Private E-2

    Thank you:)
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    1) Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    2) Please disable the guest account if this hasn't already been done

    3) Please go to Add and Remove programs and uninstall the following software:

    • Java(TM) 6 Update 7
    4) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    5) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    6) Now Run Ccleaner!

    7) Install the latest version of Java available here at the below link:
    Java Runtime 6

    8) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited by a moderator: Oct 28, 2008
  6. creaflexi

    creaflexi Private E-2

    Thanks for the prompt reply.
    I have finished all the steps as you have advised me and encountered no problems.
    I am attaching the MGTools.zip file
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi


    1) Open notepad and copy and paste the following text in the quote box into the window:



    Save this as fix.bat
    Choose to save as "all files".
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    If the following line does not appear when you scan with Hijackthis just continue on with the next steps...

    2) Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    3) Then reboot and navigate to the following folder if it exists and delete:

    4) Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the below logs


    • C:\MGlogs.zip

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks
    Kes13!
     
  8. creaflexi

    creaflexi Private E-2

    Thanks, MGLogs.zip follows
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:

    Thanks
    Kes
     
  10. creaflexi

    creaflexi Private E-2

    Thank you for your help.
    Does this mean my system is clean now? I was scanning my PC before using PestBlocker (Don't know if it is any good) and that has found trojan Banker.
    I suppose if the tools you have suggested for me to use did not discover anything, this should be considered as false positive.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Please download and run Roque Remover.

    Did you complete the final steps I left you with? If so did you toggle system restore? If not please do so, and then if you are still having pestblock tell you it is finding trojan(s) you need to give me not only the infection name but give me the full file path of where pestblock is finding it. If this program generates a log of what it found, please upload it to us.

    Thanks
    Kestrel13!
     
    Last edited by a moderator: Oct 31, 2008
  12. creaflexi

    creaflexi Private E-2

    Hi, I have flushed the restore points as you suggested and run RR, this has found no infections on my pc.
    However using PestBlock I am still getting 2 infections. I am attaching a log file with more detailed info.
    Thanks.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    HI :)

    With regards to what "pestblock" found, there is nothing to worry about.

    The first item is being called a cookie and cookies are not problems. However a registry key is not a cookie anyway and this key is valid registry key anyway. The contents of this registry key is what is important.

    The second item is also a valid registry key. And again it would be the contents of this "load" registry key that is important. Since this key is empty, it is not a problem and does not indicate a Trojan TanSpy problem.

    Note: Spyware Doctor & NoAdware also (at least at one time) falsely reported this empty registry key as Trojan TanSpy.
     
    Last edited by a moderator: Nov 3, 2008
  14. creaflexi

    creaflexi Private E-2

    So now everything should be clean and spyware free:))?
    I was also wondering if you could advise me on anti spyware/ anti - virus program that is worth investing into. Can Spyware Doctor be trusted? I am asking because I have created a tweaked version of my original XP windows using nLite adding no extra stuff to the installation and after installing this on my VMWARE and running Spyware Doctor scan on the fresh install it reports Trojan Lyndra with following registry key

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS, ServiceDLL

    Just to clarify, the Original XP is clean version - no trojan/viruses. I have tried looking for this but cannot get any clues. Should this be considered as a False Positive?
    Thanks
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. That's exactly what it is. Your PC is clean and I would suggest you move on now and stop running additional unnecessary scans because each one is more than likely going to find something that is not really a problem. This is quite normal.

    In the future, please refrain from cross posting your problems to multiple forums. Resources like this on the internet are limited and should not be put to use in multiple locations try to work the same issue. We have notice that you had also posted this last issue with Spyware Doctor in the below forum a number of days ago and you were already told that this detection is incorrect.

    http://www.msfn.org/board/nLited-XP-TROJAN-LYNDRA-t125284.html&mode=linearplus

    Thanks
    Kes13!
     
  16. creaflexi

    creaflexi Private E-2

    I apologize if this has caused any problems. Will refrain from this in the future. Anyways huge thanks for your help!!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds