Windows 8 / Conduit Search

Discussion in 'Malware Help (A Specialist Will Reply)' started by Joey Jiggles, Jul 11, 2013.

  1. Joey Jiggles

    Joey Jiggles Corporal

    Hey guys,

    I just bought a brand new ASUS computer and within a day I have this Conduit Search virus. It's with Windows 8 and I am so bad with it right now, especially for coming from a Mac.

    Please help!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  3. Joey Jiggles

    Joey Jiggles Corporal

    Thank you Tim for your quick response. I can't believe I just bought this $1,300 and already have a virus! I do want to say that I did try deleting anything conduit last night before I reached out to you guys and did a malwarebytes scan (which picked up nothing). Also, when I do a search for "conduit" a bunch of stuff still comes up but I can't delete any of it!! :cry

    See attached.
     

    Attached Files:

    • JRT.txt
      File size:
      8.9 KB
      Views:
      4
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. Joey Jiggles

    Joey Jiggles Corporal

    I did everything you told me, but I did make a mistake. I left my webroot on during all of the scans by accident. I did have some issues with getting MLogs to run, can't remember if I didn't run it as an admin. or not. Then I realized Webroot was on and turned it off. I then went into the file and right clicked on the .bat file to run as admin. and I think it worked. Let me know if I need to do the scans again since I left my protection on.

    Looking forward to your response.

    Thanks you.
     
  6. Joey Jiggles

    Joey Jiggles Corporal

    I didn't see my attachments so I am trying again.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, I do suggest that you not have Utorrent running at start up.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  8. Joey Jiggles

    Joey Jiggles Corporal

    Tim,

    You are going to hate me, but I got conduit search back. I think I figured out how to go about getting it off my computer but I do have some unintentional stuff in my program file that when I try to get rid of like "yahoo toolbar" or something called "webcake" it just keep saying "Please wait until the current program is finished uninstalling or being changed". I reset my computer and then it will let me uninstall something without that prompt but the program will never leave.

    Please help!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Tell me how things are running now.
     
  10. Joey Jiggles

    Joey Jiggles Corporal

    Thank you Tim!

    Find attached.
     

    Attached Files:

    • JRT.txt
      File size:
      4.9 KB
      Views:
      5
  11. Joey Jiggles

    Joey Jiggles Corporal

    Also, when I start my computer it says...

    RunDLL

    "There was a problem starting C:\Program Files (x86)\Conduit\CT328947\plugins\TBVerifier.dll

    The specified module could not be found."
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip
     
  13. Joey Jiggles

    Joey Jiggles Corporal

    Thank you Tim.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now tell me how things are running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds