Recurring Threats

D

Dennis

Every time I re-boot my laptop and log-on I get the same
threat message from MSAS.

It states that "Twain Tech" is tring to insatll, would I
like to remove it?

I answer yes, it removes "Twain Tech" and askes me to do
a complete scan.

I do a complete scan and two more threats are found,
Transponder.VX2.A Adware, and IEPlugin Spyware, which I
also remove. Transponder and IEPlugin are enties in my
registry.

One would assume, once these threats have been removed,
especially the registry entries, they would not appear
again in subsequent scans, however, this is a recurrence
each time I re-boot and log on.

I assume there is some other application that is causing
the re-installation of these threats.

I would be gratefull for any advice.

Thanks,
Dennis
 
A

Andre Da Costa

Restart the computer in safe mode, open Microsoft AntiSpyware, on scan page,
choose scan options > full system scan (check the boxes below) > click "Run
Scan Now".

Restart in safe mode instructions:
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx
--
Andre
Extended64 | http://www.extended64.com
Blog | http://www.extended64.com/blogs/andre
http://spaces.msn.com/members/adacosta
FAQ for MS AntiSpy http://www.geocities.com/marfer_mvp/FAQ_MSantispy.htm
 
A

AndyManchesta

Hi Dennis,


Twain Tech as you probably already know is Direct
Revenue/BetterInternet/VX2 etc... just under a different
alias.

The first step is remove Twain Tech from the add/remove
screen if it exists

Try searching for twain tech it may need unregistering
but it would help if you could find where it is ,Possibly
in the windows folder i think ?

If it is you can unregister it by going to start the run
and type cmd

then when the prompt screen opens copy and paste this
into it.

cd %WinDir%\System
regsvr32 /u "..\twaintec.dll"


Then reboot an find & delete the twaintec file


If you have XP SP2 Open a Internet window and goto manage
add ons .On this page check "Add-ons currently loaded in
IE" And disable any you do not know the name or publisher
for or any you find suspicious.


Run Ccleaner to remove any temp & unused files see if
that fixes it for you.



Theres alot of programs you can use on Direct Revenue's
Crap but it really depends exactly what they've
installed .Different Removers will all target Direct
Revenue but may not have all the variants stored in their
database so its really best to use a few removers to be
sure.

There is a uninstaller available from Direct Revenue at
mypctuneup.com but its not the safest way to do things as
its owned by the people who put the Adware in your system
Ive tested the remover on Aurora and it wasnt a clean
uninstall it left files all over my pc so i would not
recommend that anyone uses that site but thats just my
own view on them.


If the problems are still there or the add remove entry
doesnt exist Download these and run them in safe mode
(reboot and keep tapping F8 untill you see the options
list then choose safe mode)


Download Ad-Aware SE

http://www.download.com/3000-2144-10045910.html

Install and get all updates while in Normal Mode and run
in safe mode.


Lavasoft's VX2 Cleaner add-on(Again Run in Safe mode)

http://download.lavasoft.de.edgesuite.net/public/plvx2clea
ner.exe

Close Ad-Aware and Ad-Watch (if running)
Download the free VX2 Cleaner
Install the VX2 Cleaner & run with Ad-Aware in safe mode



Download the ABI Remover (Better Internet Remover)

http://andymanchesta.com/Downloads/ABIremover.zip




Download Symantecs BetterInternet Removal Tool :

http://securityresponse.symantec.com/avcenter/FixBinet.exe



Download Ccleaner to remove all temp & unused files:

http://download.ccleaner.com/download120bin.asp




Reboot Into safe mode





start with the ABIRemover.exe, press install, wait
(explorer window will disapear then its done)


Then Run Symantecs Removal Tool


Next Adaware on a full system scan and remove anything
found ,After the scan goto add-ons in the main list and
choose VX2 cleaner then "run tool" clear any thing
found.Run it twice if VX2 files are found to make sure
its showing clear the second time.

To be safe clear the prefetch folder as Direct Revenue
always leaves files in there

goto start the run and type

prefetch

delete the contents of this folder


Run Ccleaner and remove anything found also use the
issues button and fix and problems.


Reboot to normal mode and Twain Tech should be well
killed ;) You dont have to use all the removers any one
could remove it for you but alot of the time these can
regenerate if files are left on your system so wanted to
post a few programs to make it easier


All the Best

Andy
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top