Conduit Ltd - The Conduit Spyware Engine

It has been a while since I last had to fight a virus or malware but today I came across an especially nasty bit of spyware on my girlfriends computer: The Conduit Toolbar. It was drive-by installed through some other software, which AFTER installation provided a pre-checked checkbox with the caption "I have read and agree with the license agreement and privacy policy of xy toolbar and wish to install it." (wording may be a little different depending on which drive by you catch) It is really easy to overlook, even I nearly fell for it.

When she saw the first effects she called me immediately and I took a quick look. It was obvious that there was a big problem when I tried to find some way of removal via google searches. It turns out that not only there is no article with a solution, there are dozends of articles, forum posts and websites claiming the tool was harmless and could just be uninstalled using the normal mechanisms. These were obviously written by Conduit stakeholders.

So I started the tedious process of manually searching for rootkits and hidden files / startup entries / registry entries and so on. It took me almost a day(!) to get rid of the tool. This included blocking the website via the hosts file, through which the software re-downloads and re-installs itself after a partial removal. I also had to delete many registry entries and well hidden files all over the system. And of course I had to remove all browsers and re-install them.

I also analyzed some of the software and it turns out that this is a spyware and backdoor of the worst imaginable kind. Even worse, it will open up your computer to all kinds of additional malicious applications from third parties, which can be installed without you even noticing, once the primary backdoor is open.

