Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [In Progress] HiJackThis! Logs
Register for a Free Account

[In Progress] HiJackThis! Logs - unable to complete step 1 of prework posted in the Security & Safety forums; Perfect. Nothing malicious. But, your OTL shows a ton of malicious entries. Download OTM by Old Timer and save it to your Desktop. Double-click OTM.exe to run it. Paste the ...


Reply
Free PC Performance Scan
Old 09-23-2009   #8
Tech Support Team
 
Crush's Avatar
 
Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112
PC Experience: Always Learning New Things
Default Re: unable to complete step 1 of prework

Perfect. Nothing malicious. But, your OTL shows a ton of malicious entries.

Download OTM by Old Timer and save it to your Desktop.

Double-click OTM.exe to run it.
  • Paste the following code under the area. Do not include the word Code.
Code:
:Files
c:\windows\rdr_1253272783.exe
c:\windows\fdgg34353edfgdfdf
c:\windows\bk23567.dat
c:\windows\rdr_1253272686.exe
c:\windows\0101120101465050.xe
c:\windows\mmsmark2.dat
c:\windows\0101120101465354.xe
c:\windows\010112010146116101.xe
c:\windows\010112010146101105.rx
c:\windows\system32\drivers\lvuvc.hs

:Commands
[emptytemp]
[Reboot]
  • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
  • Push the large button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.

NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
__________________
Crush aka Chris
[Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate]
I am in fact, quite cool. My graphing calculator confirms this

Crush is offline   Reply With Quote
Advertisement - Register to Remove

Old 09-25-2009   #9
Bronze Member
 
webparatus's Avatar
 
Join Date: Sep 2009
Posts: 15
PC Experience: Some Experience
Default Re: unable to complete step 1 of prework

Sorry bother... is there anything else I need to do?
webparatus is offline   Reply With Quote
Old 09-25-2009   #10
Tech Support Team
 
Crush's Avatar
 
Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112
PC Experience: Always Learning New Things
Default Re: unable to complete step 1 of prework

Can I see the log generated by OTM please?
__________________
Crush aka Chris
[Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate]
I am in fact, quite cool. My graphing calculator confirms this

Crush is offline   Reply With Quote
Old 09-26-2009   #11
Bronze Member
 
webparatus's Avatar
 
Join Date: Sep 2009
Posts: 15
PC Experience: Some Experience
Default Re: unable to complete step 1 of prework

Sorry about that I didn't see the additional instructions


All processes killed
========== FILES ==========
c:\windows\rdr_1253272783.exe moved successfully.
c:\windows\fdgg34353edfgdfdf moved successfully.
c:\windows\bk23567.dat moved successfully.
c:\windows\rdr_1253272686.exe moved successfully.
File/Folder c:\windows\0101120101465050.xe not found.
File/Folder c:\windows\mmsmark2.dat not found.
File/Folder c:\windows\0101120101465354.xe not found.
File/Folder c:\windows\010112010146116101.xe not found.
c:\windows\010112010146101105.rx moved successfully.
c:\windows\system32\drivers\lvuvc.hs moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Brittani
->Temp folder emptied: 874721877 bytes
->Temporary Internet Files folder emptied: 251259349 bytes
->Java cache emptied: 30057466 bytes
->FireFox cache emptied: 86261653 bytes
->Google Chrome cache emptied: 198969090 bytes

User: Corey
->Temp folder emptied: 774723365 bytes
->Temporary Internet Files folder emptied: 123773952 bytes
->Java cache emptied: 12720597 bytes
->FireFox cache emptied: 65962921 bytes
->Google Chrome cache emptied: 91470049 bytes

User: Daddy
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 117740187 bytes
->Java cache emptied: 37343063 bytes
->FireFox cache emptied: 87017931 bytes
->Google Chrome cache emptied: 111617452 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Mommy
->Temp folder emptied: 1693264878 bytes
->Temporary Internet Files folder emptied: 104569876 bytes
->Java cache emptied: 12336996 bytes
->FireFox cache emptied: 97365421 bytes
->Google Chrome cache emptied: 363912453 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
C:\Windows\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
File delete failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be deleted on reboot.
Windows Temp folder emptied: 381816749 bytes
RecycleBin emptied: 15567362842 bytes

Total Files Cleaned = -372.44 mb


OTM by OldTimer - Version 3.0.0.6 log created on 09252009_200927

Files moved on Reboot...
DllUnregisterServer procedure not found in C:\Windows\temp\logishrd\LVPrcInj01.dll
C:\Windows\temp\logishrd\LVPrcInj01.dll NOT unregistered.
File move failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.

Registry entries deleted on Reboot...

webparatus is offline   Reply With Quote
Old 09-26-2009   #12
Tech Support Team
 
Crush's Avatar
 
Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112
PC Experience: Always Learning New Things
Default Re: unable to complete step 1 of prework

Can I please see a new DDS log?
__________________
Crush aka Chris
[Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate]
I am in fact, quite cool. My graphing calculator confirms this

Crush is offline   Reply With Quote
Old 09-28-2009   #13
Bronze Member
 
webparatus's Avatar
 
Join Date: Sep 2009
Posts: 15
PC Experience: Some Experience
Default Re: unable to complete step 1 of prework

Here it is. Didn't know if you needed the attach log or not
Attached Files
File Type: txt DDS.txt (22.4 KB, 1 views)
File Type: txt Attach.txt (9.7 KB, 0 views)
webparatus is offline   Reply With Quote
Old 09-28-2009   #14
Tech Support Team
 
Crush's Avatar
 
Join Date: Sep 2008
Location: Caldwell, New Jersey
Posts: 10,112
PC Experience: Always Learning New Things
Default Re: unable to complete step 1 of prework

Webparatus,

There is a potentially unwanted pieces of software I have detected on your PC called AskBarDis

More information here:
AskBarDis - Virtual Dr Forums-Computer Tech Support

We usually deem this optional to remove. But, I strongly suggest you do so by going to Control Panel > Add / Remove Programs and uninstalling it. Reboot your PC after uninstallation is complete.

Then, navigate to the following directory and delete it if it is still present:
C:\Program Files\AskBarDis
======================================

Next, lets download ComboFix.exe. This will give me a better view to the files running, those that are hidden, and also those in the registry..Please download from one of these webpages .

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
Combofix -> Anti-malware Tools -> Downloads


* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with our tools.

Double-click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.Recovery Console can be installed from your disc if you have Vista if you wish.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.





Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:





Click on Yes to continue scanning for malware.

When finished, it shall produce a log for you. Please include the ComboFix.txt in your reply.
__________________
Crush aka Chris
[Prework][Afterwork][PCHF Rules][BSOD's][SFC][Screenshots][PC Specs][Donate]
I am in fact, quite cool. My graphing calculator confirms this

Crush is offline   Reply With Quote

Reply

Bookmarks

Tags
complete, prework, rootrepeal, step, unable, unable to start prework
Similar discussions...
Thread Thread Starter Forum Replies Last Post
Pending: New logs: Prework complete Ilovequentin [Pending] HJT Logs 17 05-28-2009 05:27 AM
Information: How To Install Vista: Step By Step Guide Jelly Bean Windows Tutorials 0 01-16-2009 10:27 AM
Spyware issues - HiJackThis log attached, and PreWork is complete r_cypher Windows XP/2000 2 01-21-2008 03:27 AM
[Answered] unable to complete the operation on application interface unknown AMDPhenomX4 Windows XP/2000 1 09-10-2007 02:08 AM
[Tech News] Make Internet Explorer as secure as possible with this step-by-step guide Newsie IT News 0 10-24-2005 09:32 PM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 06:42 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2