Tojan Nextgen/smallgen

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wararchon, Sep 16, 2008.

  1. Wararchon

    Wararchon Private E-2

    A few days ago my firewall expired and avira said that it detected a virus. My dad clicked delete the virus, and then suddenly explorer closed and the internet no longer worked. Later, i used the task manager to run Superantispyware and found a trojan called nextGen and smallGen. I deleted them, but explorer.exe still won't work. I tried to fix the registry with CC cleaner and Glary, but nothing got better. Now when i start the computer, it says that winsocket is missing or something and i can't connect to the internet. Whats even worse, all of a sudden, i can't execute ANY programs. No control pannel, no documents, no antispyware, and not even restarts or shutdowns (it just says that i don't have the permission to do it, even though i have an admin account). My dvd drive stopped working due to a baby, so programs of cds are out of the picture (probably can't launch them either). Is there hope or is a new hard drive and reformatting the only way?

    And if i have to start anew, is there a way to retrieve data from the hard drive without the trojan spreading?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Can you boot in safe mode using the Administrator account?

    How are you going to reinstall without a working CD drive anyway?

    Did your PC come with a built-in recovery partition on the hard disk?


    You could take this hard drive out and put it into another PROPERLY PROTECTED PC as a slave drive and only copy the personal data you require. Do not copy any executable files since they could be infected.
     
  3. Wararchon

    Wararchon Private E-2

    Actually, it seems that an account under safe mode can actually access executable files, which is nice since i used superantispyware to run a few scans.
    The main problem seems to be the cd drive, which i am going to remove from the computer and try to use another one. (Trojans can't be spread through dvd drives can they?) If i can get a working drive, i will try to clean my comp using the method posted in the forum. But for now, all i have is comodo firewall (its defense setting doesn't work in safe mode, not sure about normal startup), CCleaner, glary utilities, Super, hijack this, and windows defender.

    As for now, windows protector and super have been giving clean scans, but i'm nervous about going back into normal startup. The registry damage seems to have taken its toll, since my internet is screwed up (it says winsocket fails to initialize or somehting) and many programs don't work anymore.

    About the built-in recovery platform, i'm not really sure, because we bought the HD years ago.
     
  4. Wararchon

    Wararchon Private E-2

    Update on the situation. I was able to get the cd drive working again using the manual opening hole in the drive. I did a normal startup and logged in, but i was still denied permission to execute any programs. I have, however, found a loop hole. It seems that using run from task manager can execute programs, so i will be using this and another comp to download the programs needed to clean the comp. I will post logs when finished.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job! ;)

    Just attach the logs when you finish.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds