{"id":328,"date":"2014-03-05T19:46:59","date_gmt":"2014-03-05T18:46:59","guid":{"rendered":"http:\/\/www.cbits.co.uk\/ourblog\/?p=328"},"modified":"2015-09-18T11:37:13","modified_gmt":"2015-09-18T10:37:13","slug":"fake-flash-player-update-virus-routers-tp-link","status":"publish","type":"post","link":"https:\/\/cbits.co.uk\/ourblog\/index.php\/news\/fake-flash-player-update-virus-routers-tp-link\/","title":{"rendered":"Fake Flash Player Update Virus &#038; Routers (TP-Link) Update 6\/3\/14"},"content":{"rendered":"<p>\n\t<a href=\"http:\/\/www.cbits.co.uk\/ourblog\/wp-content\/uploads\/2014\/03\/flash-player-update-virus.jpg\"><img loading=\"lazy\" decoding=\"async\" alt=\"flash-player-update-virus\" class=\"wp-image-331 alignleft\" height=\"218\" src=\"http:\/\/www.cbits.co.uk\/ourblog\/wp-content\/uploads\/2014\/03\/flash-player-update-virus.jpg\" width=\"326\" srcset=\"https:\/\/cbits.co.uk\/ourblog\/wp-content\/uploads\/2014\/03\/flash-player-update-virus.jpg 907w, https:\/\/cbits.co.uk\/ourblog\/wp-content\/uploads\/2014\/03\/flash-player-update-virus-300x200.jpg 300w, https:\/\/cbits.co.uk\/ourblog\/wp-content\/uploads\/2014\/03\/flash-player-update-virus-900x602.jpg 900w\" sizes=\"auto, (max-width: 326px) 100vw, 326px\" \/><\/a>\n<\/p>\n<p>\n\t<em><span style=\"color: #800000;\">(Updated 6\/3\/14 am) This malware seems to be being delivered as a &quot;Update to Flash Player&quot;, which we now think is changing settings in Routers so that ALL DEVICES on the local network are routing to conduit.com servers, we have seen routers where we set server addresses yesterday, and this morning the router DNS changed to 50.63.128.135 (GoDaddy servers in the US) &#8211; using just one DNS entry<\/span><\/em>\n<\/p>\n<p>\n\tWe have had an epidemic of incidents of &quot;Conduit Search engine&quot; Hi-jacks over the last two days, this appears to be &nbsp;a widespread incident and there are lots of articles on how to remove it on the internet. The most common symptom seems to be an inability to connect to Facebook or Google sites.\n<\/p>\n<p>\n\t(Kind of makes it obvious you have a problem &#8211; I suspect this is unintentional previous &#8211; conduit search engine hijacks have left users unaware, simply redirecting them and earning money for Conduit!)\n<\/p>\n<p>\n\tWhat does seem to be different about this malware is that in many of the instances we are finding that users are re-infected after their PC has been cleaned or that the problem extends across several \/ all devices on the users premises, the fake flash update warning is happening on Macs, iPads , Android tablets and several smartphones (we don&#39;t yet know if it is successful at infecting all these devices but it can hijack IE, Google Chrome, Safari, Bing at least so it seems any browser can be &quot;got at&quot;)\n<\/p>\n<p>\n\tNow the common denominator we are finding, that (as yet), no-one else seems to be seeing is that it is able to change settings in some network routers, specifically is is changing the DNS servers to point to:<br \/>\n\t<span style=\"line-height: 1.5em;\">199.223.212.99<\/span><br \/>\n\t<span style=\"line-height: 1.5em;\">199.223.215.157<\/span>\n<\/p>\n<p>\n\tThese are servers located in Virginia USA, and we suspect are directing queries to Conduit Search, so as long as this setting remains in the router , any user is using Conduit to search the internet and will rapidly become infected with Conduit and it&#39;s accomplice&#39;s malware products (are these evil things products??)\n<\/p>\n<p>\n\tIn nearly all the instances we have found so far the router involved has been a TP-Link one, <strong><span style=\"color: #800080;\">(15:30 6\/3\/14 &#8211; we have just had our first non-TP-Link &nbsp;router which has been affected an Edimax model &#8211; we are not yet sure which one)&nbsp;<\/span><\/strong>we don&#39;t know at this stage if this simply reflects their market share or if they are especially susceptible, or even specifically targeted by this Malware. We have advised TP-Link UK of our concerns around lunchtime today but as yet have disappointingly received no response. <em><span style=\"color: #800000;\">TP-Link have now confirmed that they have &quot;other reports&quot;, and we have updated them on the situation we are hoping for a technical response from them shortly<\/span><\/em>\n<\/p>\n<p>\n\tWe haven&#39;t yet found all the answers to this situation and are currently manually changing the DNS in any routers involved, and clearing any machines of malware individually.\n<\/p>\n<p>\n\t<a href=\"http:\/\/arstechnica.com\/security\/2014\/03\/hackers-hijack-300000-plus-wireless-routers-make-malicious-changes\/\" target=\"_blank\"><em><span style=\"color: #800000;\">This appears to be a variation on the Router Hacks explained here<\/span><\/em><\/a>\n<\/p>\n<p>\n\tSo far on iPads, iPhones and Android devices we are finding that clearing the Browser History settings seems to enable them to reconnect (we don&#39;t yet know if there is any residual malware here however.) &nbsp;<span style=\"color: #ff6600;\">We now have reports that on Android at least clearing browser history seems to be all that is needed, &nbsp;we recommend using <\/span><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.malwarebytes.antimalware&amp;hl=en_GB\" style=\"color: #ff6600;\" target=\"_blank\"><span style=\"color: #ff6600;\">Malwarebytes <\/span><\/a><span style=\"color: #ff6600;\">to check Android devices, and perhaps Lookout (I have used Lookout for some time and we have&nbsp;experience&nbsp;of Malewarebytes on PC so we&nbsp;know it is reputable &#8211; many claimed anti-Virus \/Malware \/ Security apps are in fact quite the opposite so huge caution please!)<\/span>\n<\/p>\n<p>\n\tAs yet we have no info about Mac&#39;s (iOS) but assume that as the browsers can be infected any Mac&#39;s should be scanned with suitable Anti Virus software (More as soon as we can)\n<\/p>\n<p>\n\tIf you feel you may be affected<em><span style=\"color: #800000;\"> or can provide us with your experience \/ additional information<\/span><\/em> please contact us immediately via www.cbits.net or leave a message on 0844 504 2986\n<\/p>\n<p>\n\tI will update this post with developments as we get them.\n<\/p>\n<p>\n\tLINKS:\n<\/p>\n<div>\n\t<strong>Remove &quot;Fake Flash Virus&quot;<\/strong><br \/>\n\t<span style=\"line-height: 1.5em;\">http:\/\/www.fixyourbrowser.com\/removal-instructions\/remove-flash-player-update-popup-scam-virus\/<\/span>\n<\/div>\n<div>\n\t<span style=\"line-height: 1.5em;\">&nbsp;<\/span>\n<\/div>\n<div>\n\t<strong>Conduit info &amp; Uninstall<\/strong><br \/>\n\thttp:\/\/itnewsyoucanuse.com\/2013\/06\/28\/349\/\n<\/div>\n<div>\n\t<a href=\"http:\/\/forums.anvisoft.com\/viewtopic-45-5152-0.html\" shape=\"rect\" target=\"_blank\">http:\/\/forums.anvisoft.com\/viewtopic-45-5152-0.html<\/a>\n<\/div>\n<p>\n\t&nbsp;\n<\/p>\n<p>\n\t&nbsp;\n<\/p>\n<p>\n\t&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Updated 6\/3\/14 am) This malware seems to be being delivered as a &quot;Update to Flash Player&quot;, which we now think is changing settings in Routers so that ALL DEVICES on the local network are routing to conduit.com servers, we have seen routers where we set server addresses yesterday, and this morning the router DNS changed [&hellip;] <a class=\"btn more-link\" href=\"https:\/\/cbits.co.uk\/ourblog\/index.php\/news\/fake-flash-player-update-virus-routers-tp-link\/\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":10,"featured_media":331,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[21,13,38,60],"tags":[116,117,115,55,7,33,114],"class_list":["post-328","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-browsers","category-news","category-os","category-virusmalware","tag-conduit","tag-edimax","tag-flash-update","tag-malware","tag-router","tag-security","tag-tp-link"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4tvbq-5i","jetpack_featured_media_url":"https:\/\/cbits.co.uk\/ourblog\/wp-content\/uploads\/2014\/03\/flash-player-update-virus.jpg","_links":{"self":[{"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/posts\/328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/comments?post=328"}],"version-history":[{"count":12,"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/posts\/328\/revisions"}],"predecessor-version":[{"id":753,"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/posts\/328\/revisions\/753"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/media\/331"}],"wp:attachment":[{"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/media?parent=328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/categories?post=328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cbits.co.uk\/ourblog\/index.php\/wp-json\/wp\/v2\/tags?post=328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}