fake flash – Our Recommendations

If you read around the items here you will get a reasonable handle on the problem, we wrote about it here:
http://www.cbits.co.uk/ourblog/news/fake-flash-player-update-virus-routers-tp-link/
In essence Malware based on Conduit Search infects a machine, this is then able to alter the search settings in certain routers, on TP-Link (TD-W8901, being common- It’s a huge seller so lots around) but also Linksys, and Edimax models. Replacing the routers is a short-sighted (and expensive/wasteful) answer – we know of one customer who bought a newer version of the TP Link model ! – they didn’t ask for advice, and didn’t solve the problem.

Conduit looks little different from Google search
Conduit looks little different from Google  

We have spoken to Edimax, who it seem’s really aren’t interested (its affected older products… – so far!) so guess how much we’ll recommend them in future? TP-Link after a couple of kick’s at least got back and knew about the problem, they promised a firmware upgrade, but as yet have not come back to us with it – Wake up TP-Link great products and prices alone won’t do
With the TP-Link, it comes allowing remote admin by default, if you don’t need this turn it off (but IT IS VERY USEFUL so consider carefully!).
Disconnect everything from the network, and using a clean (Malwarebytes is good, but do a final check with hitmanPro – needs to be on-line though) PC. then change the DNS servers being used to either those of your ISP or perhaps Google’s (8.8.8.8 & 8.8.4.4,), I suggest you update the firmware on your router to the latest available from the manufacturer involved – careful here it might be worth going to you local PC store flashing a router incorrectly can kill it!)

Run scans to clean all PC’s and Mac’s – final check on PC’s with Hitman Pro – don’t register (unless you want to buy it!) – by the way install Hitman Alert on any PCs its Free and a great protection. (Get these via our support pages)

All Android, phones, Tablets, iPads and iPhones need their browser settings reset back to default – then you should be good to go (until the next “Conduit Malware” (we are about to post about these guys to our blog) variant, no doubt clobbers your Belkin, Netgear, D-Link et al.)

FBI’s take on DNS Changer malware:
http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf
Theme: Overlay by Kaira Powered by cbits.net
The Chambers, Market Place, Chapel-en-le-Frith, High Peak, SK23 0EN