1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

DLL missing after I ran Adw cleaner

Discussion in 'Virus & Other Malware Removal' started by johnnyo34, Dec 27, 2013.

Thread Status:
Not open for further replies.
Advertisement
  1. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    I ran an Adw scan & clean, & now every time I reboot my computer I get the following message, ::
    Windows had troubles starting
    C:\USERS\JOHN\APPDATA\Local\conduit\Background container\.Background Container.DLL
    The specified module cannot be found.

    Obviously it removed the DLL, how can I put it back in..??
    Thanks.
     
  2. Hermitt43

    Hermitt43

    Joined:
    Jun 26, 2009
    Messages:
    753
    < content removed by moderator as incorrect advice in this situation >
     
  3. Mark1956

    Mark1956 Malware Specialist

    Joined:
    May 7, 2011
    Messages:
    14,142
    You do not want to put it back. The missing .dll is from an item of Adware which Adwcleaner only partially removed, running the system file checker will not fix the problem, we need to make sure the remaining entries for the Conduit Adware are fully removed to fix the problem.

    I will have this moved to the Malware forum so only Malware staff can reply.

    Please run Adwcleaner again and post the new log.
     
  4. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    Well I ran Adwcleaner again, but can't find the log anywhere. It used to show up on my desktop, but not now.. ran it twice.
     
  5. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    # AdwCleaner v3.005 - Report created 26/12/2013 at 13:17:27
    # Updated 22/09/2013 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
    # Username : John - JOHN-PC
    # Running from : I:\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****


    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16750


    -\\ Mozilla Firefox v17.0.1 (en-US)

    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\98n13ipy.default\prefs.js ]


    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\ln1zt7pd.default\prefs.js ]


    -\\ Google Chrome v31.0.1650.63

    [ File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\preferences ]

    Deleted : keyword

    *************************

    AdwCleaner[R0].txt - [5192 octets] - [12/11/2013 10:13:09]
    AdwCleaner[R1].txt - [14154 octets] - [15/11/2013 15:19:49]
    AdwCleaner[R2].txt - [2605 octets] - [15/11/2013 15:30:33]
    AdwCleaner[R3].txt - [3780 octets] - [16/11/2013 18:40:52]
    AdwCleaner[R4].txt - [1454 octets] - [16/12/2013 22:59:21]
    AdwCleaner[R5].txt - [1591 octets] - [26/12/2013 13:15:47]
    AdwCleaner[S0].txt - [5447 octets] - [12/11/2013 10:15:25]
    AdwCleaner[S1].txt - [14513 octets] - [15/11/2013 15:21:04]
    AdwCleaner[S2].txt - [2668 octets] - [15/11/2013 15:31:48]
    AdwCleaner[S3].txt - [3946 octets] - [16/11/2013 18:42:02]
    AdwCleaner[S4].txt - [1515 octets] - [16/12/2013 23:00:44]
    AdwCleaner[S5].txt - [1514 octets] - [26/12/2013 13:17:27]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [1574 octets] ##########
    # AdwCleaner v3.005 - Report created 28/12/2013 at 07:23:56
    # Updated 22/09/2013 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
    # Username : John - JOHN-PC
    # Running from : I:\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****


    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16750


    -\\ Mozilla Firefox v17.0.1 (en-US)

    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\98n13ipy.default\prefs.js ]


    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\ln1zt7pd.default\prefs.js ]


    -\\ Google Chrome v31.0.1650.63

    [ File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\preferences ]

    Deleted : keyword

    *************************

    AdwCleaner[R0].txt - [5192 octets] - [12/11/2013 10:13:09]
    AdwCleaner[R1].txt - [14154 octets] - [15/11/2013 15:19:49]
    AdwCleaner[R2].txt - [2605 octets] - [15/11/2013 15:30:33]
    AdwCleaner[R3].txt - [3780 octets] - [16/11/2013 18:40:52]
    AdwCleaner[R4].txt - [1454 octets] - [16/12/2013 22:59:21]
    AdwCleaner[R5].txt - [3242 octets] - [26/12/2013 13:15:47]
    AdwCleaner[S0].txt - [5447 octets] - [12/11/2013 10:15:25]
    AdwCleaner[S1].txt - [14513 octets] - [15/11/2013 15:21:04]
    AdwCleaner[S2].txt - [2668 octets] - [15/11/2013 15:31:48]
    AdwCleaner[S3].txt - [3946 octets] - [16/11/2013 18:42:02]
    AdwCleaner[S4].txt - [1515 octets] - [16/12/2013 23:00:44]
    AdwCleaner[S5].txt - [3168 octets] - [26/12/2013 13:17:27]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [3228 octets] ##########
     
  6. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    # AdwCleaner v3.005 - Report created 28/12/2013 at 07:38:47
    # Updated 22/09/2013 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
    # Username : John - JOHN-PC
    # Running from : C:\Users\John\Desktop\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****


    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16750


    -\\ Mozilla Firefox v17.0.1 (en-US)

    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\98n13ipy.default\prefs.js ]


    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\ln1zt7pd.default\prefs.js ]


    -\\ Google Chrome v31.0.1650.63

    [ File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\preferences ]


    *************************

    AdwCleaner[R0].txt - [5192 octets] - [12/11/2013 10:13:09]
    AdwCleaner[R1].txt - [14154 octets] - [15/11/2013 15:19:49]
    AdwCleaner[R2].txt - [2605 octets] - [15/11/2013 15:30:33]
    AdwCleaner[R3].txt - [3780 octets] - [16/11/2013 18:40:52]
    AdwCleaner[R4].txt - [1454 octets] - [16/12/2013 22:59:21]
    AdwCleaner[R5].txt - [3242 octets] - [26/12/2013 13:15:47]
    AdwCleaner[R6].txt - [1713 octets] - [28/12/2013 07:37:01]
    AdwCleaner[S0].txt - [5447 octets] - [12/11/2013 10:15:25]
    AdwCleaner[S1].txt - [14513 octets] - [15/11/2013 15:21:04]
    AdwCleaner[S2].txt - [2668 octets] - [15/11/2013 15:31:48]
    AdwCleaner[S3].txt - [3946 octets] - [16/11/2013 18:42:02]
    AdwCleaner[S4].txt - [1515 octets] - [16/12/2013 23:00:44]
    AdwCleaner[S5].txt - [3308 octets] - [26/12/2013 13:17:27]
    AdwCleaner[S6].txt - [1634 octets] - [28/12/2013 07:38:47]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S6].txt - [1694 octets] ##########
     
  7. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    I found the above 2 logs.
     
  8. Mark1956

    Mark1956 Malware Specialist

    Joined:
    May 7, 2011
    Messages:
    14,142
    Ok, all the logs are clean so we need to search for the remnants of Conduit and then remove them.

    Please download SystemLook from the following link below and save it to your Desktop.



    • Double-click SystemLook.exe to run it.
    • Vista/Windows 7 users right-click and select Run As Administrator.
    • Copy and paste everything in the codebox below into the main textfield:
      Code:
      :filefind
      conduit
      :folderfind
      conduit
      :regfind
      conduit
      
    • Click the Look button to start the scan.
    • When finished, a Notepad window will open SystemLook.txt with the results of the search and save a copy on your Desktop.
    • Please copy and paste the contents of that log in your next reply.
     
  9. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    SystemLook 30.07.11 by jpshortstuff
    Log created at 10:23 on 28/12/2013 by John
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "conduit"
    No files found.

    ========== folderfind ==========

    Searching for "conduit"
    C:\AdwCleaner\Quarantine\C\Program Files\Conduit d------ [21:21 15/11/2013]
    C:\AdwCleaner\Quarantine\C\ProgramData\Conduit d------ [21:21 15/11/2013]
    C:\AdwCleaner\Quarantine\C\Users\John\AppData\Local\Conduit d------ [21:21 15/11/2013]
    C:\AdwCleaner\Quarantine\C\Users\John\AppData\LocalLow\Conduit d------ [21:21 15/11/2013]

    ========== regfind ==========

    Searching for "conduit"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\BackgroundContainer\LogicFileManager]
    "LogicFilePath"="C:\Users\John\AppData\Local\Conduit\BackgroundContainer\TBUpdaterLogic_1.0.0.1.dll"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.ebay.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'ebay'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window['WAJAM_SOCIAL_ADS'] = false;window['WAJ
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.encryptedgoogle.wajam_google_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'google'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window['WAJAM_SOCIAL_ADS'] =
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.google.wajam_google_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'google'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window['WAJAM_SOCIAL_ADS'] = false;
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.youtubesearch.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'youtubesearch'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window['WAJAM_SOCIAL_ADS'] =
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.yahoo.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'yahoo'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window['WAJAM_SOCIAL_ADS'] = false;window['W
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.ask.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'ask'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window['WAJAM_SOCIAL_ADS'] = false;window['WAJAM
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{524DECDB-C97E-40B4-847F-CA7E3F138070}]
    "URL"="http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3315828&CUI=UN11789565311665373&UM=2"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{524DECDB-C97E-40B4-847F-CA7E3F138070}]
    "SuggestionsURL_JSON"="http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{524DECDB-C97E-40B4-847F-CA7E3F138070}]
    "FaviconURL"="http://search.conduit.com/favicon.ico"
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\AppDataLow\Software\BackgroundContainer\LogicFileManager]
    "LogicFilePath"="C:\Users\John\AppData\Local\Conduit\BackgroundContainer\TBUpdaterLogic_1.0.0.1.dll"
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.ebay.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'ebay'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.encryptedgoogle.wajam_google_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'google'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] =
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.google.wajam_google_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'google'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.youtubesearch.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'youtubesearch'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] =
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.yahoo.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'yahoo'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';wind
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Wajam]
    "supported_sites.ask.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'http://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'http://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'http://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.21'; window['WAJAM_AFFILIATE'] = '6801';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'ask'; window['WAJAM_SERVER_VERSION'] = '1.00258.0'; window['WAJAM_SUPPORT_CRC32_MAPPING'] = '0'; window['WAJAM_SHOULD_SEE_ADS'] = true; window['WAJAM_ID_USER'] = '0'; window['WAJAM_LATITUDE'] = '29.5073';window['WAJAM_LONGITUDE'] = '-98.5747';window['
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\SearchScopes\{524DECDB-C97E-40B4-847F-CA7E3F138070}]
    "URL"="http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3315828&CUI=UN11789565311665373&UM=2"
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\SearchScopes\{524DECDB-C97E-40B4-847F-CA7E3F138070}]
    "SuggestionsURL_JSON"="http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}"
    [HKEY_USERS\S-1-5-21-3470371619-1438766809-3008890385-1000\Software\Microsoft\Internet Explorer\SearchScopes\{524DECDB-C97E-40B4-847F-CA7E3F138070}]
    "FaviconURL"="http://search.conduit.com/favicon.ico"

    -= EOF =-
     
  10. dvk01

    dvk01 Derek Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    47,880
    If you use the updated version of adwcleaner not one that is 4 months out of date, it will find the entry causing the problem and fix it

    The entry causing the problem is the windows tasks scheduler entry and adwcleaner was updated to deal with this version of conduit about 3 months ago

    delete your existing adwcleaner from your computer &
    Click on this link to download : ADWCleaner Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop. Do not click on any links in the top Advert.

    See the screenshot where the proper download buttons are highlighted
    [​IMG]

    NOTE: If using Internet Explorer and you get an alert that stops the program downloading click on Tools > Smartscreen Filter > Turn off Smartscreen Filter then click on OK in the box that opens. Then click on the link again.

    Close your browser and double click on this icon on your desktop:

    [​IMG]

    You will then see the screen below, click on the Scan button (as indicated), accept any prompts that appear and allow it to run, it may take several minutes to complete, when it is done, you will get a message saying "PENDING" , Ignore that & click on the Clean button, accept any prompts that appear and allow the system to reboot. You will then be presented with the report, Copy & Paste it into your next post.


    [​IMG]
     
  11. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    # AdwCleaner v3.016 - Report created 28/12/2013 at 13:55:28
    # Updated 23/12/2013 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
    # Username : John - JOHN-PC
    # Running from : C:\Users\John\Desktop\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : C:\Program Files\Toolbar Cleaner
    Folder Deleted : C:\Program Files\Vuze
    File Deleted : C:\Program Files\Mozilla Firefox\nsprotector.js
    File Deleted : C:\Windows\System32\Tasks\BackgroundContainer Startup Task

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{06964321-3D69-4C80-A081-089A4A78F652}
    [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06964321-3D69-4C80-A081-089A4A78F652}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasapi32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasmancs
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
    Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
    Key Deleted : HKLM\Software\Toolbar Cleaner
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF

    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16750


    -\\ Mozilla Firefox v17.0.1 (en-US)

    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\98n13ipy.default\prefs.js ]


    [ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\ln1zt7pd.default\prefs.js ]


    -\\ Google Chrome v31.0.1650.63

    [ File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\preferences ]


    *************************

    AdwCleaner[R0].txt - [5192 octets] - [12/11/2013 10:13:09]
    AdwCleaner[R1].txt - [14154 octets] - [15/11/2013 15:19:49]
    AdwCleaner[R2].txt - [2605 octets] - [15/11/2013 15:30:33]
    AdwCleaner[R3].txt - [3780 octets] - [16/11/2013 18:40:52]
    AdwCleaner[R4].txt - [1454 octets] - [16/12/2013 22:59:21]
    AdwCleaner[R5].txt - [3242 octets] - [26/12/2013 13:15:47]
    AdwCleaner[R6].txt - [1713 octets] - [28/12/2013 07:37:01]
    AdwCleaner[R7].txt - [3984 octets] - [28/12/2013 13:54:24]
    AdwCleaner[S0].txt - [5447 octets] - [12/11/2013 10:15:25]
    AdwCleaner[S1].txt - [14513 octets] - [15/11/2013 15:21:04]
    AdwCleaner[S2].txt - [2668 octets] - [15/11/2013 15:31:48]
    AdwCleaner[S3].txt - [3946 octets] - [16/11/2013 18:42:02]
    AdwCleaner[S4].txt - [1515 octets] - [16/12/2013 23:00:44]
    AdwCleaner[S5].txt - [3308 octets] - [26/12/2013 13:17:27]
    AdwCleaner[S6].txt - [1774 octets] - [28/12/2013 07:38:47]
    AdwCleaner[S7].txt - [3840 octets] - [28/12/2013 13:55:28]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S7].txt - [3900 octets] ##########
     
  12. dvk01

    dvk01 Derek Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    47,880
    That should have cured it
    I don't know why Adwcleaner didn't tell you it was out of date. On my computer I get a warning telling me it is out of date when a new version/update comes out and it won't allow me to do anything except press yes & go to the site or cancel & close adwcleaner
     
  13. johnnyo34

    johnnyo34 Thread Starter

    Joined:
    Jan 18, 2008
    Messages:
    139
    Thanks, yes that cured it. I don't know either, but I never got a message, & it just kept working,, :confused:
    Thanks again, a belated Merry Christmas, & all the best for 2014..(y)
    John
     
  14. dvk01

    dvk01 Derek Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    47,880
    Glad we could fix it
    Happy Xmas and a prosperous and healthy new year to you
    go here http://myonlinesecurity.co.uk/how-to-protect-yourself-and-tighten-security/ for info on how to tighten your security settings and how to help prevent future attacks.

    and scan here http://secunia.com/vulnerability_scanning/personal for out of date & vulnerable common applications on your computer and update whatever it suggests.

    Then pay an urgent visit to windows update & make sure you are fully updated, that will help to plug the security holes that let these pests on in the first place. If windows update doesn't work, please come back & tell us
     
  15. Mark1956

    Mark1956 Malware Specialist

    Joined:
    May 7, 2011
    Messages:
    14,142
    Thanks for the input Derek. It never occurred to me that Adwcleaner could be out of date, as you have pointed out, it usually creates a pop up when an update is available. I'd never dealt with any other thread where its removal of Conduit left any remaining issues.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1116156