My HJT Log - Have Had Some Troubles

By LuK3
Apr 24, 2006
Topic Status:
Not open for further replies.
  1. Please Tell Me If I Am Infected, I Followed Some Instructions And Scanned With KaperSky (I Have Report) And I Downloaded Look2Me - Destroyer And Followed The Instructions :D Please Help Me :p
  2. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Hello and welcome to Techspot.

    Your version of HJT is out of date.

    Go HERE and follow the instructions exactly.

    Post a fresh HJT log, only after doing the above.

    Regards Howard :wave: :wave:
  3. LuK3

    LuK3 Newcomer, in training Topic Starter

    Thanks Howard. I've had a few problems along the way, but I think it's all done now. could you please take a look again? :)
  4. Spike

    Spike Newcomer, in training Posts: 2,371

    I've helped Luk3 with problems installing files and did some scans (hence the instance of sessmgr.exe). If there's anything major left in the log, it's probably my fault. It's pretty reasonable now though, but I got the logs posted here just for a double check for his own peace of mind. :) Feel free to pick me up if I've missed something - it is late at night here right now after all ;)

    edit: I should probably add that the antivirus and firewall issue (lack of) has been taken under advisement, and rock.exe was not present in the windows or system32 folder, nor was it detected by ewido or kaspersky as being nasty.
  5. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Well done. Your system is almost clean.

    Boot into safe mode. See how HERE. http://www.bleepingcomputer.com/forums/tutorial61.html

    Turn off system restore.(XP/ME only) See how HERE. http://www.bleepingcomputer.com/forums/tutorial56.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE. http://www.bleepingcomputer.com/forums/tutorial62.html

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    rock.exe

    Close task manager.

    Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O4 - HKLM\..\Run: [rock] rock.exe

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold file.

    rock.exe

    Reboot into normal mode and turn system restore back on.

    Regards Howard :)
  6. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Hiya Spike.

    rock.exe is a trojan and needs to be got rid of.

    Regards Howard :)
  7. Spike

    Spike Newcomer, in training Posts: 2,371

    That's cool. I didn't recognise the file as a trojan (not seen that one before), and it wasn't detected, so after checking the usual places I left it there just in case it was part of a legit program and assumed someone such as yourself might know better it if it was malware. Plus it's exceedingly late, it was all RA, and I'm tired. (Thats my excuse, and I'm sticking to it! lol)

    Thanks Howard - much appreciated for that, as no doubt Luk3 will be when he checks back :)
  8. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    It`s actually, well according to Symantec anyway, a worm by the name of VBS.Slip@mm.

    See HERE for more info. It`s the seventh entry from the bottom of the list.

    Regards Howard :)
  9. Spike

    Spike Newcomer, in training Posts: 2,371

    Thanks. :) The one obvious location I didn't check too. lol. That's all-nighters for you! :blush: :blush:
  10. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Yeah, I know the feeling mate lol.

    I`ll get some sleep myself, one of these days.

    Thanks for the pm BTW.

    Regards Howard :)
  11. DragonMaster

    DragonMaster Newcomer, in training Posts: 430

    Infected by a 2002 virus...
     
  12. LuK3

    LuK3 Newcomer, in training Topic Starter

    Thanks Spike and Howard For All Your Help. I Followed Your Instructions And Here Is My HJT Log, Hopefully I Am 100% Clean :D
  13. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Yes. Your HJT log is clean.

    Regards Howard :)
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.