Solved Browser Redirect nightmare

mohavepc

Mohave PC Computers
Guru
VIP
Local time
12:12 AM
Messages
559
Location
Lake Havasu City, Arizona
Hello my friends.

I am having a bit of an issue with a new infection that is kicking by butt. I have an Acer laptop with an i3 and 4gb ram. I have run the following tools. ADW, Malwarebytes, SuperAntiSpyware, Adaware, Eset Scan, MS essentials scan, TDSS Killer, MBAR Rootkit beta, TFC, JRT, CCleaner portable. all clean all run with admin priv. in safe mode with networking where applicable.

When you open "Any" Browser after 30seconds the cursor loses focus and if you click to gain it back you get a new page that redirects twice (address changes) and ends up on a "fake" Norton page saying your infected with a persistent pop up that requires you to CAD and kill IExplore.

For those of you who know me know I am very thorough and I have look through the registry at Run keys, IE Keys, Chrome keys, FF Keys, and Safari keys. Each browser shows clean of all add ons and all have been reset including the remove personal where applicable.

please help I have no hair left to pull out.
its nearing a reinstall but I hate to do that over a stupid browser hitchhiker. :banghead:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Never mind. there was a renamed piece of free "Conduit" software called skycaddie. Once remove the redirects stopped. found it through perusing a hijackthis log. it showed ok but had conduit extensions. It had 3 conduit processes loaded with windows.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
When in doubt, its usually a program thats still on the system. I've been finding some nasty stuff lately.

Also, consider running Autoruns because sometimes there can be lingering problems when malwares startup files are still present.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Dual Boot: Windows 8.1 & Server 2012r2 VMs: Kali Linux, Backbox, Matriux, Windows 8.1
CPU
A10 7700 Kavari SteamRoller
Motherboard
ASUS A88XM-PLUS (FM2+ )
Memory
8GB DDR3 SDRAM PC3-8500
Graphics Card(s)
1024MB ATI AMD Radeon R7 Graphics
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Samsung
Hard Drives
SSD Crucial 120gb
WD VelociRaptor 1tb
PSU
Rosewill Gaming 650w
Case
Rosewill Galaxy 2
Internet Speed
55/12
Antivirus
Malwarebytes, MSE, SAS
Browser
FireFox, Chrome
When in doubt, its usually a program thats still on the system. I've been finding some nasty stuff lately.

Also, consider running Autoruns because sometimes there can be lingering problems when malwares startup files are still present.

Indeed I did run Autoruns, always do as the next to last step along with clearing restore points and creating new ones. The only way I found this one was using Hijackthis log and saw 3 references to Conduit.sys and 2 conduit.dll tied to the sky caddie program. It passed all the scans and tests I could toss at it including AVG and Kasperski rescue cd's which are usually pretty good at catching hidden browser add-on's. There was nothing about the program that even bespoke of conduit accept the links to the sys and dll files (which are aslo manually removed).
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build MPCBS AMII
OS
Windows 7 Professional x64
CPU
AMD Athlon II x4 3.00 GHz
Motherboard
MSI GF615M-p33
Memory
16GB Kingston DDR3
Graphics Card(s)
Nvidia 8600 (dual DVI out for 2 monitors)
Sound Card
Onboard
Monitor(s) Displays
Acer H233H 23", ASUS 23"
Screen Resolution
1366 x 768
Hard Drives
(2) WD Blue 1 TB 3 partitions, (1) Seagate 7200 500GB with 2 partitions for useless and frequently deleted data Looking forward do an ssd for os soon.
PSU
Corsair 1100Watt
Case
Apevia HAF
Cooling
HAF AMD High Profile Heat sink and fan
Keyboard
wireless Logitech
Mouse
wireless Logitech
Internet Speed
16 mbps
Antivirus
eSet, AVG, Clam and Clamwin (depends on machine)
Browser
Firefox
Other Info
(9) Win 7 machines all x64 (POS Updated to Windows 7 pro YEA), (4) Linux machines x64 and x86 including a v3000 compaq lappy brought back to life with Mint 9 used to scan drives, (1) Linux Machine dual boot XP Pro (for testing and destroying), (1) Win 7 pro x64/Win 8.1 Lenovo Laptop Dual Boot.
Back
Top