Remove Conduit Search Malware (as of 04/08/14) ---------------------------------------------- Conduit Search is advertisingware piggybacked onto malicious updates for Adobe Flash and Java. Homepages of browsers are hijacked and toolbars installed. All searches will then go through Conduit. Proxies may be created for Internet connectivity. Do the following general procedures: |==================================================================================| | A. Install and update Malwarebytes.org and run a full scan to remove | | instance of the malware that can be found that way. | | B. Reset browser homepages and search engines; remove Conduit add-ons. | | Internet Explorer, Chrome, Firefox, Safari, etc. | | C. Clear and delete toolbars in the browsers. | | D. Clear Windows temp files. Do Disk Cleanup if the application exists. | | | E. Adjust the System Configuration (startup) with msconfig to stop the | | loading of Conduit upon start up. | | F. Clear Conduit entries and paths from the Windows registry. Search | | for Conduit and then modify or delete the keys or subkeys. (at least 12) | | G. Check the control panel's Programs and Features for evidence of Conduit. | | H. With Windows Explorer search for Conduit in the Programs folders and | | then delete the Conduit folders if found. | | I. Reset Internet Connections for No Proxy in all browsers and use the LAN. | |==================================================================================| 1. Stop these Conduit Search Processes: ----------------------------------- ieLogic.exe, ConduitInstaller.exe, cltmng.exe, ConduitHelper.exe, TBMessagingHost.exe 2. Remove these Conduit Search Files: --------------------------------- BackgroundContainer.dll cltmng.exe ConduitInstaller.exe ConduitEngine.dll ConduitHelper.exe ieLogic.exe %LOCALAPPDATA%\Conduit %PROGRAMFILES%\Conduit %PROGRAMFILES(x86)%\Conduit prxtbrad0.dll prxtbWin2.dll TBMessagingHost.exe TBHostSupport.dll TBHostSupport_0.dll TBVerifier.dll %UserProfile%\AppData\LocalLow\Conduit %USERPROFILE%\Local Settings\Application Data\Conduit 3. Remove these Conduit Search Windows Registry Entries: ---------------------------------------------------- Software\AppDataLow\Software\ConduitSearchScopes Software\AppDataLow\Software\Conduit Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} 4. Run Malwarebytes' Anti-Malware using the full scan. The Premier Edition might work better.