Request permission to post Hijackthis log: Win ME, scans completed

Discussion in 'Malware Help (A Specialist Will Reply)' started by zapp, Mar 7, 2005.

  1. zapp

    zapp Staff Sergeant

    Windows ME, all updates loaded.
    Norton updated, scanned, clean.
    Trend Micro Housecall run, came up empty handed [clean]
    Stinger run, came up clean
    Trojan remover run, found 5 trojans, cannot remove some [cabs]
    Adaware run, cleaned up
    Spybot run, cleaned up
    Hijack this run, cleaned a few of the obvious
    Startup list still includes what appears to be malicious code that cannot be defeated, and does not show up on Hijackthis log to my knowledge [if its there, the names are different than in the startup list]

    Have fresh Hijack log and would like to post

    Zapp
     
  2. RayDunne

    RayDunne Corporal

    Hi there, I am not one of the true experts in here, but I can tell you that they will not want to see you post the log unless you have completed all, or at least as many steps in this link >>> http://forum.majorgeeks.com/showthread.php?t=35407 <<< as possible. Also you will want to be sure that you have run HJT correctly as in this link >>> http://forum.majorgeeks.com/showthread.php?t=38752 <<<. I cannot stress enough emphasis on following these procedures in correct order. Read all information carefully and read it again to make sure. They will not want your log unless you have done as many steps and in correct order as possible. If you don't understand something or have problems with any steps, post back with specific details and be as clear as possible. These people can and will get you out of trouble, but you must follow directions exactly, or you waste valuable resources and make things frustrating for them. Good luck :)
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Sounds like you might have done the tutorial, did you scan from safe mode? If you ran the tutorial, please attach a log file and Chaslang, Philliephan, BJGarrick or myself will take a look.
     
  4. RayDunne

    RayDunne Corporal

    RayDunne,
    Hijack this was run properly. Please post when you can be of assistance, your posts come off as rude to me. Also, your adding 3-5 posts to a thread before assistance begins, it is making it confusing. Thanks for understanding.


    Major Attitude.
     
    Last edited by a moderator: Mar 7, 2005
  5. zapp

    zapp Staff Sergeant

    can't edit

    no edit button available.
    log attached
    I did run Hijack from a good location and in full windows mode not safe mode
     

    Attached Files:

  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Re: can't edit

    You have adware as well as possible trojans capable of remotely controlling your pc.

    Few to remove from safe mode:

    C:\WINDOWS\SYSTEM\QNLRBT.EXE
    R3 - Default URLSearchHook is missing
    O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\DLMAX.DLL
    O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\SYSTB.DLL
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\SYSTEM\winupdtl.exe
    O4 - HKLM\..\Run: [qnlrbt] c:\windows\system\qnlrbt.exe
    O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
    O4 - HKLM\..\Run: [FARMMEXT] C:\WINDOWS\FARMMEXT.exe

    See where this gets you, let us know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds