![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
HI, i'm having all sorts of issues getting rid of some of this stuff that got on my computer. I have followed all the instructions in the read me first folder. All scans are done, and here are my logs.
thanks in advance for any help clearing some of this stuff out. Sarah RKreport[1]_S_01142013_02d1142.txt HitmanPro_20130114_1159.log mbam-log-2013-01-14 (11-44-10).txt MBRCheck_01.14.13_10.52.25.txt MGlogs.zip |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Uninstall the below:
Conduit Engine Vuze Remote Toolbar If you do not find the above to uninstall, just continue on. Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file) O3 - Toolbar: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file) O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [{91120000-0030-0000-0000-0000000FF1CE}] C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [{91120000-0030-0000-0000-0000000FF1CE}] C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'Default user') After clicking Fix, exit HJT. Please download OTM by Old Timer and save it to your Desktop.
Code:
:Processes
explorer.exe
:Files
C:\Windows\83B952C7F8F34CA3B4C533C85B24E478.TMP
C:\PROGRA~2\CONDUI~1
C:\Windows\TEMP\*.*
C:\Users\Champs\AppData\Local\Temp\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF]
[-HKEY_USERS\S-1-5-21-2918329194-2069250384-2540450748-1001\Software\Ask.com]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"{91120000-0030-0000-0000-0000000FF1CE}"=-
"{91120000-002F-0000-0000-0000000FF1CE}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"=-
"{30F9B915-B755-4826-820B-08FBA6BD249D}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
:Commands
[purity]
[EmptyTemp]
[start explorer]
[Reboot]
saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
Thanks so much for the help!
When I try to uninstall Vuze I get a could not open INSTALL.LOG file notice Conduit engine does nothing when I try to uninstall for some reason. I did everything else you suggested. I still have privatize VPN in my search engine, and it takes me to a searchab site. Here are my logs: |
|
#4
|
||||
|
||||
|
With which browser? My last fix should have removed it from IE. If your problem is with Chrome, just remove it from the search engines. Click the wrench icon and select Settings. On the Settings page click the Manage seach engines button. Locate the Privatize VPN item and select it it. Then click the X to the far right to delete that search engine.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 01-19-13 at 19:49.. Reason: typo |
|
#5
|
|||
|
|||
|
that did it! Thanks so much
![]() Sarah |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
You're welcome.
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| IE issues | twinmms | Software | 5 | 07-31-09 19:42 |
| I'm still having issues.... | nordn8 | Malware Removal | 1 | 12-14-08 22:37 |
| XP boot issues - MBR issues - Long History | okn0tok | Software | 42 | 08-28-08 12:26 |
| Fresh install of XP-pro, issues issues issues... | Trikster | Software | 16 | 06-14-06 23:44 |
| about:blank issues..........real big issues | IAmThurt | Malware Removal | 13 | 01-23-05 17:37 |