Problems with Generic Trojan TXN

ChinaCat

Member
Jul 14, 2002
55
0
0
I was out of town on business last night when my daughter calls with this problem. She was using google for some information, went to a site it had a check mark next to as safe, received a pop-up that was any thing but. It fooled her by suggesting her computer had an issue and to click "here". Ok, we all make stupid mistakes and she's a kid so life happens. She called my cell phone.

Once infected none of the .exe files would work so when I guided her to run Super Antispyware Pro, it wouldn't work. I calmed her down, reminded her it was just a computer and today when I returned I did the following but still having issues. It's a Windows XP 32bit OS.

I have AVG, Spybot Search & Destroy, and Super AntiSpyWare Pro loaded on her PC, in addition to the windows Firewall active.


1) Logged in normally and unable to execute any files, so not able to scan. I did get a AVG notice that there was a Generic Trojan 18 TXN, asked me if I wanted to continue to block (i said yes) and asked me to clean but would not execute the process.

2) Logged in Safe Mode as Admin. Was able to run AVG & Spy Bot and removed the Trogan.

3) Logged in normally as my daughter ran some more scans and the system was clean. Opened her preferred browser "Google Chrome" and unable to access the Internet. Icon for Internet Explorer exists but she doesn't use it and that short=cut opens Chrome so up to this point no browser working. Opened Firefox and that works. So only Internet access is through Firefox.

3) Noticed another very odd thing. I was able to update AVG & Spy Bot via the Internet and get new updates, but for the Supery Spyware Pro. program was unable to get updates. I tried every thing; uninstalled, reinstalled, re-registered, deleted it from Firewall, added it back in to exceptions. rebooted, etc., never able to get updates; it reads "Can't get updates, check firewall.

4) I notice her wireless is connect using Windows XP and I have a Linksys Router. This happens occasionally so not odd, but trying every thing I turn off the Windows XP wireless connection and enable the Linksys software to connect to the router through its software. That goes fine but did not ask me for the KEY. That has never happened before. I was able to connect to our wireless network without having to put the key in. Now perhaps her PC remembered it, but normally if she is connected via Windows XP and I change it to the Linksys software and connect it always prompts me for the key.

Clearly this computer is still messed up but I'm not sure what else to do. I'm concerned some stuff in the registry remains borked as well as some dll files.

I have downloaded the setup files for Google Chrome and IE, but haven't installed them. I'm thinking in the same way the Supervirus Spyware program is corrupted and remains so even after uninstall and reinstall, I'm expecting the same shit to happen with the browsers


When she first told me about this problem last night I asked her to run the Super Spyware Program, so perhaps by doing that the virus or computer is blocking its ports and that's why I can't get out to update it even after a reinstall. Perhaps because she was using Google Chrome while infected, some thing similar is occurring there. I'm real close to just backing up all her data and replacing her hard drive.

Should I try to restore to an earlier save point?

Any suggestions folks short of bringing this PC in to a shop?

Thank you -CC
 
Last edited:
May 11, 2008
20,055
1,290
126
I do not know much about these subjects (i have been using opera,nod32 virusscanner and sygate firewall for years and kept my computer save and secured).

With my experience, i can only suggest you try the nod32 virusscanner from eset. See if that reveals something. For some odd reason i have the feeling the pc is comprised.Maybe the software installed some proxy server in between ? I am out of my league here.

What i do know from nod32 is that actually the virussscanner installs itself in between your internet connection and your programs that use the internet like a browser. The nod32 virusscanner thus acts not only as a virusscanner and spyware scanner but also as an proxyserver. It filters all incoming and outgoing data before it is send to your browser or other program. Data like http or email.

Perhaps the trojan you described installed a proxy server of it's own. It would then be able to block certain programs while allowing others and would be able to send data itself. Maybe someone more familiar with these subject can help ypou better.

There is a 30 day trial :
http://www.eset.com/download

Eset has a complete anti spyware, virusscanner, email scanner, firewall suite.
And the fun part is, it is small and you sometimes wonder if it is actually running because of the low amount of cpu calculation time it needs. It has no 3d animations nothing. All it does is protect you computer.

http://www.eset.com/home/smart-security
 
Last edited:

mpilchfamily

Diamond Member
Jun 11, 2007
3,559
1
0
Bottom line... When something like this happens its best to wipe the drive and do a complete reinstall. These viruses bury themselves deep into system files. So if you are able to wipe it from the system key system files will be destroyed. As you have seen these things also block you from running anything that might be able to clear it from the system. Any part of it that gets left behind could get it reinstalled on the system. So wipe the drive and reinstall everything.

Hope you have backups
 

QueBert

Lifer
Jan 6, 2002
22,460
775
126
OP - run Hijackthis with the option to save a log, then Google Hijackthis Log, the first link should be a site that will analyize your log and you can see what shouldn't be in there. Now you sound pretty good on computers so you might be able to look at the log yourself and see what shouldn't be there. I haven't ever came across an infected PC I couldn't fix given enough time. I know doing a clean install of Windows on my box would take more time as me digging and doing every scan on earth to get it fixed. And I have some programs I have installed I'm not going to be able to re-install because I dunno where the CD's are at. I suggest Hijackthis + Trends Micro online Housecall (free virus scan) Do those and report back if you're still having issues.
 
Last edited:

MadScientist

Platinum Member
Jul 15, 2001
2,154
47
91
You may be at the point of no return and as mpilchfamily suggested you may have to do a complete re-install or a repair install.
http://michaelstevenstech.com/XPrepairinstall.htm

First try following the steps in John's security guide:
http://www.elitekiller.com/malware.htm

Download his Rogue removal kit and read his Readme.doc first.
The one extra step I do is first run RKill. Here's an explanation of what it does and download links: http://www.bleepingcomputer.com/forums/topic308364.html

Don't forget to back-up all important files first!!!
 

RebateMonger

Elite Member
Dec 24, 2005
11,588
0
0
Repairs of malware-infected PCs are getting more and more difficult to execute. Plus, it's difficult to be 100% sure that you've got everything, including potential rootkits.

For the future, consider keeping ongoing system backups, so that you can easily restore your system without having to re-install everything from scratch. It makes life a ton easier.
 

dfnkt

Senior member
May 3, 2006
435
0
76
She could try running both malwarebytes antimalware and combofix, i've had great luck with this combination.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |