infected by Rouge:Win32/FakeYak

infected by Rouge:Win32/FakeYak
« on: August 27, 2011, 10:09:44 AM »
Good afternoon folks,

I generally browse a lot of sites randomly, and I seem to have picked up this trojan. I actually looked online and tried some of the procedures there before stumbling onto this site.
FYI, I ran Windows Defender. It located the infection and seems to remove it (gives me a green signal) but when I looked up, the file was still there under a different name. I also ran sfc /scannow and it apparently fixed a lot of things but not this problem. I can post the log details if you'd need it.

My task manager always disappears and so does the process explorer from sysinternals. I keep getting warning icons on the task bar but they disappear in a flash.

This is an official laptop so I'd rather not format it. External drives are disabled by policy so I can only backup to a D: drive.
eTrust ITM and Checkpoint are installed.

I'd really appreciate any help in removing this.

Ok here's the HJT scan log:
Re: infected by Rouge:Win32/FakeYak
« Reply #1 on: August 27, 2011, 10:57:11 AM »
What exactly do you mean by "This is an official laptop" we only give assistance with personal systems, that is Forum Policy....

The intention of this forum is not to replace a company's IT department or outsource staff, nor can we anticipate alterations or configurations that may have been made to a business machine, or how it will interact with the tools commonly used in the removal of malware.

More than one machine could be at stake, possibly even the server. If sensitive material has been compromised by an infection, the company could be held liable.

To prevent any possible loss or corruption of company information, please inform your IT department or Supervisor when a workplace computer has been infected, that should be done immediately.

It may be in the company's best interest to re-image the machine.



Re: infected by Rouge:Win32/FakeYak
« Reply #2 on: August 27, 2011, 11:08:08 AM »
Ok thanks. Could you remove this post please?


Re: infected by Rouge:Win32/FakeYak
« Reply #3 on: August 28, 2011, 05:10:03 AM »
This topic has been closed due to the machine belonging to a business.
Assistance cannot be provided in this case as stated in the Forum Rules.
Never stop learning - visit the SpywareHammer Knowledgebase