Jump to content

MBAM Removed Conduit Search. Antivirus Still Won't Startup


Recommended Posts

  • Replies 67
  • Created
  • Last Reply

Top Posters In This Topic

  • Root Admin

I've asked one of the other Helpers if they can take over this topic so hopefully they will reply by early tomorrow.

 

As soon as you can though please find out about Trend as I think it's probably corrupted and a clean removal and reinstall will probably fix it.

 

 

Cheers

Link to post
Share on other sites

Hello Matllock,

 

I`m kevinf80 one of the helpers, i`ll be taking over whilst Ron is on vacation. Can you give me an update on the current status of the system, make me aware of any remaining issues or concerns.

 

Not sure how advanced you are with the uninstall of TM and install of Avast, if possible still remove TM, they do have a removal tool available at the following link:

 

http://esupport.trendmicro.com/Pages/How-do-I-remove-old-or-new-versions-of-Trend-Micro-products-in-my-comp.aspx

 

If possible do not install Avast, for now use the resident security Windows Defender. As the OS is Windows 8; Windows Defender differs to other versions available for Windows 7, Vista etc, W8 version does have Anti-Virus components, I use it myself. If you`ve progressed and installed Avast that is OK...

 

Kevin..

Link to post
Share on other sites

Hello Kevin,

 

I have uninstalled TM and updated WD. I think we were close to being clean, but TM wouldn't start and I keep dropping my internet connection. Also, I still see a couple of items that were identified during some of the scans, that Ron had me run, in the add/remove programs list. I just want to make sure the system. She is computer savvy, but not security savvy. I don't want to going through this again after returning it to her. So, I'm willing to start from scratch and run any scan you want to insure the system is clean. My answer to fighting virus and malware is a restore to build date, so I won't go through this twice. When it's returned to her, I'll educate her on security, backing up important data and will have MBAM Pro installed. 

 

Thanks for your assistance and I await your instruction.

Link to post
Share on other sites

The best start to make is remove/uninstall any software that is no longer used, such as Citrix. I see no reason to keep what is no longer needed.

 

When that action is completed run the following scan:

 

Download Zoek.zip from here http://www.hijackthis.nl/smeenk/220813/zoek.zip and save that zip file to your Desktop.

 

Double click zip file and extract to your  Desktop:

 

 

Zoekd.jpg

 

 

you will now have 3 versions of the tool on the Desktop:

 

 

Zoeke.jpg

 

Before running Zoek make sure all Browsers are closed and Security is turned OFF. Check at the following link: http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/]

 

Double click on each in turn until one version of Zoek will run (accept UAC) The following window will open:

 

 

Zoekb.jpg

 

 

Copy and paste the following script from the code box and paste into the field.

 

 

standardsearch;autoruns;autoclean;emptyclsid;emptyalltemp;installedprogs;

 

 

Select the "Run Script" tab. The following window will open:

 

 

 

Zoekc.jpg

 

 

 

Please be patient and do not use the PC when the scan is in progress.

 

When complete you maybe asked to re-boot your PC, if so please do

 

Zoekf.jpg

 

Post the produced log in your next reply, also give an update on any remaining issues or concerns....

 

I`m actually in the UK, my local time is 1:30 am, i`ll only be online maybe 30 mins then its sleepy time.... I will catch up later maybe 9:00 am my time...

 

Kevin....

Link to post
Share on other sites

Can only assume some setting/plugin within IE attempts to go back to Google, I would assume that will not be anything Malicious....

 

Go to this link; http://support.microsoft.com/kb/923737 expand the plus + options and run a reset of IE, restart and see how it responds..

 

Next,

 

Run Malwarebytes, check for updates, run a quick scan. Post that log.

 

Next,

 

Download OTL from any of the following links and save to your desktop.

 

http://itxassociates.com/OT-Tools/OTL.com

http://oldtimer.geekstogo.com/OTL.exe

http://www.itxassociates.com/OT-Tools/OTL.scr

 

Double click the OTL icon to start the tool. (Note: If you are running on Vista or Windows 7 accept UAC alert)

 


  When the window appears, underneath Output at the top, make sure Standard output is selected.
Select Scan all users
Change Drivers to All
Under the Extra Registry section, check Use SafeList
In the lower right corner, checkmark "LOP Check" and checkmark "Purity Check".
Click Run Scan and let the program run uninterrupted.
When the scan is complete, two text files will be created on your Desktop.
OTL.Txt <- this one will be opened
Extras.txt <- this one will be minimized

 

Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of OTL.Txt and the Extras.txt in your next reply.

 

Post those logs, let me know if you have any remaining issues or concerns...

 

Kevin


 

Link to post
Share on other sites

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.10.09

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16750
PurpleKat :: PURPLEKATPC [administrator]

1/10/2014 6:02:31 PM
mbam-log-2014-01-10 (18-02-31).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 208829
Time elapsed: 5 minute(s), 23 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.