(Updated 6/3/14 am) This malware seems to be being delivered as a "Update to Flash Player", which we now think is changing settings in Routers so that ALL DEVICES on the local network are routing to conduit.com servers, we have seen routers where we set server addresses yesterday, and this morning the router DNS changed to 50.63.128.135 (GoDaddy servers in the US) – using just one DNS entry
We have had an epidemic of incidents of "Conduit Search engine" Hi-jacks over the last two days, this appears to be a widespread incident and there are lots of articles on how to remove it on the internet. The most common symptom seems to be an inability to connect to Facebook or Google sites.
(Kind of makes it obvious you have a problem – I suspect this is unintentional previous – conduit search engine hijacks have left users unaware, simply redirecting them and earning money for Conduit!)
What does seem to be different about this malware is that in many of the instances we are finding that users are re-infected after their PC has been cleaned or that the problem extends across several / all devices on the users premises, the fake flash update warning is happening on Macs, iPads , Android tablets and several smartphones (we don't yet know if it is successful at infecting all these devices but it can hijack IE, Google Chrome, Safari, Bing at least so it seems any browser can be "got at")
Now the common denominator we are finding, that (as yet), no-one else seems to be seeing is that it is able to change settings in some network routers, specifically is is changing the DNS servers to point to:
199.223.212.99
199.223.215.157
These are servers located in Virginia USA, and we suspect are directing queries to Conduit Search, so as long as this setting remains in the router , any user is using Conduit to search the internet and will rapidly become infected with Conduit and it's accomplice's malware products (are these evil things products??)
In nearly all the instances we have found so far the router involved has been a TP-Link one, (15:30 6/3/14 – we have just had our first non-TP-Link router which has been affected an Edimax model – we are not yet sure which one) we don't know at this stage if this simply reflects their market share or if they are especially susceptible, or even specifically targeted by this Malware. We have advised TP-Link UK of our concerns around lunchtime today but as yet have disappointingly received no response. TP-Link have now confirmed that they have "other reports", and we have updated them on the situation we are hoping for a technical response from them shortly
We haven't yet found all the answers to this situation and are currently manually changing the DNS in any routers involved, and clearing any machines of malware individually.
This appears to be a variation on the Router Hacks explained here
So far on iPads, iPhones and Android devices we are finding that clearing the Browser History settings seems to enable them to reconnect (we don't yet know if there is any residual malware here however.) We now have reports that on Android at least clearing browser history seems to be all that is needed, we recommend using Malwarebytes to check Android devices, and perhaps Lookout (I have used Lookout for some time and we have experience of Malewarebytes on PC so we know it is reputable – many claimed anti-Virus /Malware / Security apps are in fact quite the opposite so huge caution please!)
As yet we have no info about Mac's (iOS) but assume that as the browsers can be infected any Mac's should be scanned with suitable Anti Virus software (More as soon as we can)
If you feel you may be affected or can provide us with your experience / additional information please contact us immediately via www.cbits.net or leave a message on 0844 504 2986
I will update this post with developments as we get them.
LINKS:
http://www.fixyourbrowser.com/removal-instructions/remove-flash-player-update-popup-scam-virus/
http://itnewsyoucanuse.com/2013/06/28/349/


I too have experienced this issue as well. I have a Linksys E2000 router and had no issues until we were issued a ARRIS TM822 modem from our ISP. I will be trying Blakes solution this weekend and will update if it works for me as well.
Brendon – Generally we would suggest your router should be serving DNS, if your connected devices use fixed IPs they should point to your router for DNS. The router itself is they key issue here and that is where this stuff does the DNS re-direction, so it’s the routers DNS settings you need to ensure are pointed to the servers YOU want them to use
I had it across two laptops and two mobile phones (andriod and Iphone).
I tried every virus scanner, reset my router (TP link), cleared browsing history/caches/cookies, I even rebooted my android device.
In the end the only thing that worked was changing the DNS on all devices to a google or open domain DNS.
Hope that helps.
Have seen the same problem with a TP-Link ADSL router. I fixed the problem by doing a device reset. Then as a pre-caution I changed the admin password and also disabled telnet from the LAN. I suspect the virus uses a telnet session with the default admin password to change the DNS server settings as noted above. This means that any device connecting through the router will get the virus webpage when requesting google or facebook. Only windows machines are vulnerable though as the binary payload file (EXE) is windows PE format.
Final update (I hope!): the problem was solved in this way…
1) Disconnect the router from the Internet and reset to factory.
2) Log into the router and slowly tighten configuration, walking through each screen with a critical eye.
– Don’t use static IP,
– Don’t allow remote administration,
– DO filter anonymous requests.
These are specific to resolving this problem, but also be sure you do the other basic wireless security best practices that most techies know, like enabling the router’s firewall, etc.
3) Clear all temporary Internet files from client PC.
4) Reset IE to defaults (Internet Options –> Advanced –> Reset)
5) Reboot, then uninstall IE (Turn Windows Features On Or Off –> uncheck Internet Explorer checkbox –> Click OK –> Reboot)
6) Re-install IE (same steps as above, check Internet Explorer box)
7) I added Microsoft Security Essentials to the client. We already had Avast! Premier Edition, but that let the malware through, so we wanted another layer.
When all that was complete, all was well. I had to re-pin Internet Explorer to the start menu so the client machine could have it there, and I had to re-apply their Windows Theme because it reverted to the Windows 2000 look, but other than that we no longer have the problem.
For now.
I hope that helps other people. This was an ugly bugger to deal with.
Update: this article has me suspecting that at least in my case (and possibly yours) a router worm called The Moon is involved… http://grahamcluley.com/2014/02/moon-router-worm/
This exact issue has hit my home network hard, and here are the details:
1) The Linksys WRT-610N router stopped responding Saturday 5/17 and during a simple power-down we discovered that it had been blown back to factory settings. Restoring from factory to custom using a settings backup file was too little, too late.
2) A Kindle Fire HD was bricked on 5/11, possibly by this issue. It brought up a prompt for an update and then hard crashed before the user could respond, never to power up again.
3) Currently (5/21) a laptop is getting the same treatment you outline above and brain surgery end-to-end does not show any culprit on the machine, making me suspect the router is compromised.
4) I’d kept all machines up to date including the router, but obviously there aren’t new firmware fixes for a WRT-610N. I’m beginning to buy into Bruce Schneier’s recent statement about Heartbleed, where some people’s security fix to problems like this is going to involve the router, a trash can, and a trip to Best Buy…
5) I have Avast Premium and am now working with Avast techs to see if we can clean up the damage. If I learn anything new I will post it here.
Hi everyone. I am using an Edimax model router and have the same issue. Reseting the settings of the router has been the only solution so far however it has just made the issue go away temporarily. Each week since the beginning of March a reset have been required. I do now know if there is a permanent solution for this. Generating sophisticated passwords for the router have not been enough to get rid of this. What I’d like to say to the people having the same problem is that do not waste your hours for running deep virus scans on your devices if you have the same issue on more than one device. Because it means that the the problem is your router and your connection, not the devices. I hope to
I had my wirless-router Edimax infected as well. I re-set to the admin specs but the problem resurfaced again.
Make: Info re TP Link router malware
Model: TP Link wireless modem router TD-W8901G
Fault Discription: Hi,
Just some extra info re the router rest you have described. We are having the same issue with the wireless devices connected to our internet. Same issue for the person in the link copied below.
We also as above have a TP Link device.
http://www.bleepingcomputer.com/forums/t/526812/help-google-redirects-to-a-fake-flash-player-update-on-both-pc-and-mobile/
cheers,
Vernon
I forgot to mention, we are using a Linksys E2000 router. So add that to your list!
I have been running into this specifically at one client and its mind boggling. We had a computer show up with a fake flash update (different picture than what you show). We cleaned the PC but it was still showing up. We ran 10+ different programs on the PC and all said CLEAN! We eventually reformatted the machine offsite and brought it back. As soon as we brought it back and gave the machine a static IP (key point here) the flash update screen came back! Took the static ip/dns off and cleared cache/flush DNS and all was fine. Put static back and boom it was back!
I have never seen anything like this. I rebooted the modem/router and cleared everything one more time and it was gone for over a week, then randomly today, it’s back again! The PC is still clean. I checked the router and the DNS servers are the standard ones for this area. It has to be some sort of hack that is changing the DNS invisibly on the router as the DNS servers there are correct that we use for all clients in the area. I’ve never seen this before and there is very little on the net regarding router dns hijacks! Very irritating.
Also of note when I was receiving the fake flash page it was only popping up on google.com, yahoo.com, msn.com and pinging all 3 of those search engines from command prompt resolved to the same address. Sadly I did not write it down but it started with 55. I believe.
Anyhow…people have to much free time on their hands. I hope whoever created this strain of infection get’s what they deserve.
I forgot to mention, we are using a Linksys E2000 router. So add that to your list!