Trojan.PWS.Tanspy and Trojan.Generic

Discussion in 'Malware Help (A Specialist Will Reply)' started by carbonrose, Dec 15, 2007.

  1. carbonrose

    carbonrose Private E-2

    Hello,

    System specs are:
    XPpro, SP2, P4-2.4, 1.5gRam, 640g HDD, 250mgVC
    Sec Programs:
    Spyware Guard, AVG Spyware/Antivirus, ZoneAlarm (free), BHODemon, Ad-Aware, Ccleaner, Cleanup, Spybot S&D and the prog's mentioned in the Malware Removal Guide.

    I have logged a request for help with the forum Tech Support Guy on the 10.12.07. But as yet I have recieved no response at all.
    I know that in these types of forums most are volunteers and it is almost Christmas day so many may be away with Families or preparing to do so. And also you are all very busy recently with the amount of requests for help.
    I have explained these points as I do not want to appear to be posting indiscriminantly to Help forums. If I recieve help from here, I will close my request on the above mentioned site immediately. This way there will be no confusion and irritation created by following advice from two different sources. But I need if possible. Thankyou in Advance for your understanding.

    Now to my issue at hand,

    I initially had an issue with my pc which can be seen at this address for reference (NB:currently Tech Support Guy website is down for maintenance repairs. I will insert links to previous posts when site is up).

    After fixing an issue with my pc I had run the trial version of Spyware Doctor and it came up with 2 infections.
    Trojan.PWS.Tanspy and Trojan.Generic
    I have been searching the net since the 10th putting away hours to try and resolve this issue myself but have come up short. ONLY spyware Doctor can see this Trojan. No other scans either system installed or online scan has reported this Trojan as existing.

    Can you assist me in locating and removing this threat if it actually IS there.
    As a note, I have followed the Malware removal Guide process on this site but came up with no results for this Trojan.

    With sincere regards,

    CR.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    Also attach a log that shows exactly what Spyware Doctor is finding.
    Is your copy of Spyware Doctor a paid version or trial copy? If it is a paid version, you should be complaining to them about not fixing what it finds. If it is a trial, you should uninstall it after we finish your cleanup as it is a waste of system resources to have it running because it will not fix anything for you.
     
  3. carbonrose

    carbonrose Private E-2

    Hello chaslang,

    Thankyou for your reply.
    Firstly I made a mistake in the name of the Trojan. It is actually Trojan-PWS.Tanspy
    Spyware Doctor was a trial version only. I could find no option for a text report so have copied an image of the desktop display.

    I have run all scans again according to the removal guide.
     

    Attached Files:

  4. carbonrose

    carbonrose Private E-2

    Last 2 to attach...
     

    Attached Files:

  5. carbonrose

    carbonrose Private E-2

    Link to Techguy support site (if needed) to see my previous help from an earlier problem which led me to the discovery of the existing Trojans http://tinyurl.com/342zuk
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This image is not helpful since it does not give info needed. Click the + signs by the Registry Key text to expand the info so the keys can be seen. Hopefully they fit on the screen but I doubt it. You may need to scroll or highlight the info and copy elsewhere. It could just be a false positive as I don't see any signs of this Trojan in your logs.

    Let's correct a few minor things that I do see.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - AutorunsDisabled - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    O24 - Desktop Component 0: (no name) - (no file)

    After clicking Fix, exit HJT.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  7. carbonrose

    carbonrose Private E-2

    Hello chaslang,

    Well I have followed your advice below and you will find the attachments there including one from a program called NoAware which interestingly enough also found Trojan-PWS.Tanspy.

    About messenger/Msn messenger. I ran the program to remove messenger. I do understand the difference between the 2. However I have found that it has removed MSN version 4.7 that I was using. Hmm.. Should it have done that?

    As for Spyware Doctor I could not highlite to paste the text so have expanded the strings (which I should have done before, sorry) to show the locations given

    Thankyou for your help.

    My pc works fine and never noticed any problems before the issue with the Explorer tools show/hide options or after it was fixed. However if there are this many trojans or issues it was of concern to me as I need to use online banking again which I have not used for awhile now. And am also worried that if this Trojan does exist and does take passwords and the like as is usually stated then it is cause for concern that I may be compromised and steps wil need to be taken. I wanted to ensure that there was no false positives. All scans I have done either online scans or through apps that I have installed on this system come up with nothing. yet Spyware Doctor and NoAdware do. Strange.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NoAdware and Spyware Doctor have never been on my list of things to use. Main reason is for false positives and that is what you are seeing those registry keys shown in your snapshot are valid registry keys appearing on almost all PCs. They are even on mine. It is not those registry keys that are problems. It is what malware could put under them that could be problems.

    Uninstall both Spyware Doctor and NoAdware now. They are not helping you if they are only trials and they are giving you false information.

    No. It should only affect Windows Messenger. Windows Messenger was such an issue that Microsoft even finally removed it with certain updates to Win XP SP2. Also it was totally excluded from Vista. You should get the current version of MSN Messenger installed anyway. 4.7 is way out of date. Last I remember it was at least into the 7.5 area or above. And there is also Windows Live Messenger which is 8.+ Old version of tools are security risks.

    Based on your HJT log I still see Windows Messenger trying to be loaded. You can fix the below line with HJT:

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background



    As I stated above, these are definitely false positives. Those registry keys are in all PCs and are not problems. If there were subkeys underneath them, you would then have to check to see what they were to know if the subkeys were valid. You don't have any subkeys so there is no issue.


    You could delete the below file that NoAdware pointed out:
    C:\WINDOWS\unin.exe

    It is not really an issue either. It is just an uninstall program for something you installed but a few programs think it is something called WinSpy. You don't really need the file so you can simplye delete it. The other items in the log from NoAdware are false positives.
     
  9. carbonrose

    carbonrose Private E-2

    Thankyou very much for taking the time to help me out chaslang.
    I appreciate the added information supplied. False positives was what I was worried about. I do try to keep this system as clean as possible at all times. I will go through the Sticky about protecting against malware as well.

    Just a question but only if you can spare the time,
    What programs can you recommend to use, for as complete protection that can be. (No doubt youve been asked this a zillion times before)
    Paid for programs are fine. I have no issue paying for a program if it does provide a more secure system than a combination of free ones.
    It gets a little daunting when they ALL say that they are the one program and shelling out for whatever does not sound like a practical approach.

    But aside from this thankyou again for your time and effort. Much appreciated.

    Have a great Christmas and NewYear.

    CR.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    There is no one program that provides complete protection. That is why you see all the different categories under the How to Protect yourself from malware! thread that you mentioned.

    Many companies offer packages often referred to as internet security suites. These are their attempt at providing a complete package. The problem is that they have multiple issues:
    1. the largest problem is that they are all massive resource hogs which will dramatically slow your PC down
    2. they give a pile of really unnecessary programs that just compound # 1
    3. they don't really provide any real advantage over individual applications especially when you choose only what you really need as in the How to protect youself link
    4. due to their complex nature they seem to always run into problems where malware or even just their own software bugs causes them to stop working properly. And they can be very difficult to fix. Sometimes a total uninstall and then reinstall is necessary. And sometimes even that may not work.
    5. many of these security suites are more difficult to get properly uninstalled then malware. Thus when you inevitably decide to get rid of them, it can be very difficult and typically results in you unknowingly have multiple security suites installed at the same time which will make your system even slower.
    6. add to all the above that you have pay a bunch of money only to discovery all of the above issues for yourself over a period of time.
    As far as your question about paying for tools. Yes there are good tools. It is just a little difficult to say what is good for any individual. The difficulty arises due to facts like below:
    • Everyone has differing levels of expertise with PCs, software, system administration and the concept of protection. So while one program may be really great for an expert user, it could prove too complex for an average user or novice even though this complex program could offer the best protection.
    • Each PC has different specs like processor type and speed, the amount of RAM, and how many and what type of other applications are being run. Thus what runs fine on one PC, could put too great a demand on resources of another PC.
    Sounds depressing doesn't it? ;) Don't worry just follow the How to protect yourself thread instructions and you will be just fine. A multi-layered approach is what you will see in this link and also a great deal of how safe you will be is based on your own education in computer security and your surfing habit (all explain in the link).

    Happy Holidays to you too! :)
     
    Last edited: Dec 19, 2007
  11. carbonrose

    carbonrose Private E-2

    Thankyou for the time given. I had pretty much the same thoughts and am aware of many of the points you mentioned. It is good to have someone who is in the industry (Not company related) to give there professional opinon. Many thanks.

    Cr
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds