I Need Help With Possible Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by jac4123, Aug 24, 2013.

  1. jac4123

    jac4123 Private E-2

    Ok....I am not computer literate at all. So if you are kind enough to help me, please be as elementary as possible in your recommendations. I can't tell you how much I need the help and how much I appreciate your help.

    I can't seem to be able to download any windows updates. I have it set for automatic downloads, but when i look at the history of updates there are none. I also get a message of: ......windows update cannot currently check for updates because the service is not running.....

    Also, when i tried to download all of microsoft office (word, power point, etc) the download never started. Or at least that is the way it appeared to me. Bottom line is i could NOT get it to download.

    I have windows vista.....and I also have chrome, firefox, and IE.

    I may have viruses, worms, and malware preventing the updates and downloads. I have no idea. But maybe a big clean up to begin with.....then after that, I am not sure what will be needed.

    So, again, PLEASE, someone help me with this. I have to have this fixed ASAP. I am taking two online courses that require this.

    Thanks,

    JC
     
  2. jac4123

    jac4123 Private E-2

    I am not sure I have posted this in the correct location. if i have posted in the wrong spot, sorry, just tell me where to post it and I will.......I am a Grandpa here trying to figure out what is wrong.......and take a couple of college courses after fixing it......
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure you are having malware problems. Most problems with Windows Update are not due to malware. I may have to send you to the Software Forum but first we will check a couple things out.

    First try running Microsoft Fixit

    http://support.microsoft.com/fixit/

    Click the Windows button and in step 2 select the Install of upgrade software or hardware option in the left column of the form. Then on the right side select Windows Update. Now in step 3 you will see possible fixes with the Run Now buttons to try. Try the appropriate solution. Reboot after running any fixes before attempting to see if they worked.

    If that does not help, try the below.



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, test Windows Update again. If still not working, we will check to see if any malware is inteferring.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. jac4123

    jac4123 Private E-2

    Thank you Chaslang.......i ran the FIXIT, but it did not solve the problem. So I followed your instructions and ran the "WINDOWS REPAIR". It took almost 3 hours! So I am not sure I ran the repair in the correct way. But nonetheless I did and it seemed to do the trick.

    After running, and re-booting, I was able to run the windows update that I thought had been running automatic the way it was set up. But after the windows repair, the update found 86 updates that were needed. There is no telling what else needs to be done to this laptop in order to get it running properly.

    After another 2-3 hours of getting windows updates all seems to be ok. But I am POSITIVE if things were this bad (86 updates), then further cleaning probably would be wise. But again, I have no idea how to do any of it. I have run CCleaner, but that is about it. I have found that anti-virus (avast, etc) slows my laptop to a snails pace so I have opted not to have them.

    so, do you possibly have a little more time to spend with me to get this laptop in good shape? I am close to 60 years old and know enough to be dangerous about computers. I am taking 2 graduate courses with my daughter this semester and need a good, clean, fast computer in order to do this.

    I don't know if there are any worms, viruses, malware, adware, or any other WARES that could keep me from doing the work needed.

    Thank you so, so, so, much for getting me this far. I can't tell you how much you have helped me. Getting to take graduate courses at the University with my daughter is something I am looking forward to.

    thank you,

    JC
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just because you had 86 updates to install, it does not mean you had malware. It just means you had not been installing updates. However the fact that you do not have any protection installed could potentially be big trouble especially if you are not very careful about where you surf and what you download. If you use this PC for any online banking or other financial transactions, you are begging for trouble. It is not advisable to run without protection and it is a waste of our time to bother cleaning your PC if you are not going to properly protect it afterwards. Uninstalling other programs is a much better idea than uninstalling protection.

    If you wish to check for malware, you need to run the READ & RUN ME FIRST and attach the requested logs.
     
  6. jac4123

    jac4123 Private E-2

    I will run the read and run me first then post the logs when done, if i can figure how to do it. As for the protection, can you recommend protection that doesn't slow the system down completely?

    This laptop i purchased used and haven't had an issue with it with the exception you fixed for me.

    Thanks for the patience......

    JC
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All protection software can have a significant impact, but some less than others. Also depends on whether you use a full security suite or just an antivirus+antispyware. You could try the free Microsoft Security Essentials which is not as resource hungry as others but that comes at a price of not being as good too. ;) But better than nothing. Note all protection software will have an impact at bootup especially when it also requires updates to download. This is normal and necessary.

    Many people who say that there protection software is slowing them down a lot are really having the problem for reasons like below:
    • Not enough memory to properly run their PC.
    • Older slower micro processor styles that just do not have the horsepower to handle modern day applications.
     
  8. jac4123

    jac4123 Private E-2

    Thank you very much for your help. I am a grandpa and it feels as if i have no knowledge of technology at all. My daughter and grandkids live a good days travel by air so this is vital to me in pictures, videos, and skype calls to them daily. So thank you for helping me.

    I apologize for not getting back with you on this problem I had. But a couple days after your last post, I was hospitalized and had major back surgery. I just now am home from the rehab hospital. So I am sorry for not at least letting you know the problem was solved. Thanks.

    My laptop is used and I have only had it for a few months. I don't know much about who had it before but I would love to do some sort of....general cleaning on it if possible. I am sure there are things on here that slow down the laptop as a whole. Also, there seems to be something that causes my laptop to just freeze and give a ...... loud beep....as it locks up.

    It releases it's hold after about 30 seconds and all is well. But I did notice every time this happens I see a small message at the bottom left of the screen that says, "ad.yieldmanager."

    I know you are busy and have much better things to do than help a grand dad stay in touch with his family. But if you can find some time to help me clean the laptop up and get rid of this ad.yieldmanager....I really would be in debt to you.

    I don't have much, but I would gladly make a donation for the help. It will be small. But I need the help. I will apologize up front, but even the terminology you may use will be foreign to me. And as last time, some processes you tell me to do that are basic, I have never done. So I guess treat me like I am a 6 year old kid when telling me what to do.

    Although most 6 year olds know more than I do.....

    Thanks again,

    JC
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to hear about your back. Hope you are doing better now.


    I have to refer you back to what I posted in my first message to you which was
    To properly continue with any support, we will need the logs from this process.
     
  10. jac4123

    jac4123 Private E-2

    I have attached the five logs requested.......i hope it is correct

    jc
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is just a little bit of junk to remove.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Program Files\Conduit
    C:\ProgramData\Conduit
    C:\Users\Owner\AppData\Local\Conduit
    C:\Users\Owner\AppData\Local\temp\*.*
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ConduitFloatingPlugin_nemfjadlboooiffmcelkafilagddogim"=-
    [HKEY_USERS\S-1-5-21-823311705-3733584610-3011476573-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "ConduitFloatingPlugin_nemfjadlboooiffmcelkafilagddogim"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{E18CAA8A-CAA8-461C-A5C0-203B1ACC2506}"
    "ShowSearchSuggestionsInAddressGlobal"=dword:00000001
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{E18CAA8A-CAA8-461C-A5C0-203B1ACC2506}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1E55EA9D-1F16-4710-BDA4-6CDE192E7F7D}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{97470E74-E80F-4AEE-86C4-599839A55C75}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    NOTE: Your PC could use another 2 GB of memory to help improve performance.
     
  12. jac4123

    jac4123 Private E-2

    You may have already taken care of all of this.....but I wanted to at least let you know of a few things I was either worried about or things that appeared on this laptop for no reason in the last few days. The following were on here before the last cleansing so to speak:

    realdownloader 1.3.3 - on my programs list when looking through the control panel at the programs under install/uninstall

    oggcodecs 0.71.0946 by illminible - on my programs list when looking through the control panel at the programs under install/uninstall

    system requirement Lab for Intel - on my programs list when looking through the control panel at the programs under install/uninstall

    shockwave crashes - when watching a video, the video will sometimes just stop playing as will any other video I have loading/playing simultaneously. I then get a message stating there was a problem or something to the effect flash or shock crashed. I just can't remember which one. It doesn't happen every time I watch a video, but it does the majority of the time watching videos. It happens every time I have two or more going at the same time.

    Something called search.conduit.com - Again, You may have already fixed this. And when I look for this, it doesn't show up anywhere I can locate. All I can tell you is whenever I would open another tab (I use chrome) a screen would come up that was almost exactly like the Google home page. The only thing missing is the word "Google" under the search box.

    Also, I remember seeing in the bottom left corner of the screen a phrase saying, ad.yieldmanager.......or conduit search manager.......or maybe it was search.conduit.com. I just don't remember.

    When I open a new tab now (after the fixes you helped with) only the history of sites I have visited comes up. The screen that it brings up now is a snapshot of eight websites, with a visual of that site, and nothing in the address bar.

    conduit toolbar - A toolbar had been coming up underneath the normal Google toolbar. The toolbar now doesn't seem to come up, or it hasn't since the last fix you instructed. But there is a new addition to the bookmark bar.

    This new addition says, "Apps", and is the very first bookmark overall. When I click on the "Apps" on this bookmark bar a screen comes up with what appears to be a Google Chrome logo with the word, "store" underneath it. I have NOT clicked on the “store” as of yet for fear of the unknown.

    Again, THANK YOU, THANK YOU, THANK YOU, for your patience and knowledge with this. I can't tell you how much I appreciate it. I am on a fixed income without any expendable funds. Which is why I had to get another used laptop, but when all this gets done, I WILL find a way to send some kind of money. I just wish I had more. Your service you provide is impeccable and very, very, valuable. THANK YOU once again.

    I have the logs you requested along with the zip file attached. I hope what I sent is correct.

    Thank you again,

    JC
     

    Attached Files:

  13. jac4123

    jac4123 Private E-2

    As mentioned in my previous post, I am having an issue with what appears to be some sort of rouge search engine at times when i open a new tab while on chrome.

    Here is what I copied from the address bar when it happened:

    http://search.conduit.com/?ctid=CT3289663&SearchSource=48&CUI=UN18905148782079797&UM=2

    I don't know what this search.conduit.com is............but i know it isnt supposed to be there. is this something that is compromising not only the laptop but passwords, credit info, etc. ?"???


    help.....

    jc
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No.

    Try the below:
    • Click the Customize and Control Google Chrome button ( the 3 parallel lines down below the X button used to close the window ).
    • Then on the pop down form select Settings.
    • Now under the Search heading, click the Manage Search Engines button
      • Look in here for anything related to Conduit and select it and delete it by clicking the X button to the far right side.
      • Make sure that you look in both the Default Search Engines and Other Search Engines areas and delete any Conduit junk.
      • Select the default search engine you want ( like Google ) and click the Make Default button.
      • When finished, click the Done button
    • Now back on the Settings page to the top left you should see an Extensions selection, click on it to bring up the installed extensions.
    • Look for any undesired extension ( like Conduit or anything else you did not install ) and if found, click the Trash Can icon to delete the extension.
    • Now close the Extensions/Setting tab to get back to normal view
    • Exit Chrome and reopen.
    • Are you still having a problem with Conduit?
     
  15. jac4123

    jac4123 Private E-2

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes the easiest thing to do is uninstall Chrome when it gets infected like this. So let's do the below:
    • Backup your Chrome bookmarks
    • Uninstall Chrome and then reboot your PC
    • After reboot, delete the below folders to finish removing junk that may be hiding there
    C:\Users\Owner\AppData\Local\Google\Chrome
    C:\Program Files\Google\Chrome


    • Now download and reinstall Chrome from here >>. Chrome
    • Restore your bookmarks and then see how it is working.
     
  17. jac4123

    jac4123 Private E-2

    OK, not sure what I did was right, but I went back to the settings and this time opened advanced settings. At the Advanced Settings -- Open with -- tabl, Conduit.com was still there. And it was enabled to be used upon opening up chrome.

    I am not sure this completely wiped the laptop clean, but I hope it did.

    Do you now think it is safe to go to my bank website and pay bills as well as go to my credit card company site to do the same?

    I researched the conduit and found information that this as well as the others you helped me with was used to capture passwords and credit information.

    Think it is clean and safe now?

    thanks

    jc
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Conduit is just a junk search engine/adware. It does not steal passwords. So you should be good to go after doing the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  19. jac4123

    jac4123 Private E-2

    all seems to be ok. except for one thing.

    something called: ad.yieldmanager

    still is slowing everything down.....i notice the banner in the lower left corner of the screen.

    thanks again.

    JC
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you talking about in Chrome? If yes, please do what I requested in message # 16.

    Typically this has not been a malware problem. We have seen people having problems with this with address redirection software that Dell and a few others have installed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds