also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

Hacktool.Rootkit Problem

Discussion in 'Virus and Malware Removal' started by Sycamor, Sep 28, 2005.

Thread Status:
Not open for further replies.
  1. Sycamor Newcomer, in training

    Hello,

    I read the sticky threads regarding removing Hacktool.Rootkit, but have had no success. Norton indicates that I have a Hacktool.Rootkit virus. However, I could find none of the malicious processes mentioned in the post (javapanel.exe, taskcntr.exe, xpjava.exe). I don't know if my particular problem has different processes and files associated with it and don't know how to identify them. A HJT log is posted and would appreciate any help as to what I should do next.

    Thank you very much. I appreciate the time you folks give to helping people with technical problems.
  2. RealBlackStuff Newcomer, in training

    Go to this thread, http://www.techspot.com/vb/topic33967.html
    and follow the LOCKX.EXE instructions. Do the same for POKAPOKA70.EXE
    C:\WINNT\system32\lockx.exe
    C:\WINNT\etb\pokapoka70.exe

    O4 - HKLM\..\Run: [stratas] lockx.exe
    O4 - HKLM\..\Run: [System service70] C:\WINNT\etb\pokapoka70.exe
    O4 - HKLM\..\RunServices: [stratas] lockx.exe
    O4 - HKCU\..\Run: [stratas] lockx.exe

    Fix ALL your O16 - DPF: entries

    Fix O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
  3. Sycamor Newcomer, in training

    Thank you very much. I did what you recommended and the problem seems to be fixed. I ran RootkitRevealer and nothing seems out of the ordinary. Thank you for your time and your help and your continued dedication. You are an invaluable resource.
Thread Status:
Not open for further replies.