Solved

drudgereport.com redirection

Posted on 2014-02-06
6
1,021 Views
Last Modified: 2014-02-11
DrudgeReport.com RedirectedDefault Home Page in IEIE LAN SettingsHi,
  I have a strange situation with this user's Windows 7 PC.
  He as two browsers - IE and Firefox. Recently this computer was attacked by some type of viruses and it planted some stuff in Proxy settings, so I had to clear those in both browsers.
  Now the problem is that even if I set the home page to http://www.drudgereport.com/ on both IE and Firefox, when I open them, it displays an error screen like above screenshots.
  I can visit ESPN.com, YAHOO.com w/o a problem.
  The reason "Proxy server" section looks recessed is because I ran GPEDIT and disabled it so that no one can add anything to proxy server section.

  Can you help?
0
Comment
Question by:sglee
  • 2
  • 2
  • 2
6 Comments
 
LVL 8

Accepted Solution

by:
Chris Wong earned 250 total points
ID: 39841031
0
 

Author Comment

by:sglee
ID: 39841044
SearchConduit malware taken over ChromeChrome Search Engine SettingYes They subscribe to AT&T  DSL Service. I just ran NSLOOKUP and it showed:
C:\Users\Brent>nslookup ibm.com
Server:  dsldevice.att.net
Address:  192.168.1.254

I also just installed Google Chrome and I can browse www.drudgereport.com.
Now I am just confused as to why Google Chrome does something different from IE and Firefox.
Also I noticed that this computer is infected with SearchConduit malware. Even though I set default URL to google.com in Chrome, it displays something else like screenshot.
0
 
LVL 8

Assisted Solution

by:Chris Wong
Chris Wong earned 250 total points
ID: 39841093
Conduit Search – Virus Removal Guide

http://malwaretips.com/blogs/remove-conduit-search-virus/
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 250 total points
ID: 39841226
You can remove Conduit in 'Uninstall programs' but you also need to change the default home page and search engine too.  Just did that on a client's computer this evening.  And usually if you have Conduit, you also have several of it's 'friends'.  My client had 6 different installs from yesterday and she said she didn't install anything on purpose.  I just looked at the install dates in the Add/Remove Programs list to find them.
0
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 250 total points
ID: 39841231
This info is just telling that ATT forces DNS lookups to go thru their service.  I've seen this on other AT&T modems.  I have a Netgear router that does that also.  It screws up the 'nslookup' program but still allows 'normal' DNS queries to go thru.
C:\Users\Brent>nslookup ibm.com
Server:  dsldevice.att.net
Address:  192.168.1.254

Open in new window

0
 

Author Comment

by:sglee
ID: 39841566
Update:
I found an article on google regarding SearchConduit. It suggested that I use CCleaner. So I downloaded it and ran it and and it worked.
IE and Firefox displays drudgereport.com as home page upon start.
This computer has spydoctor anti-virus program installed, but when it scans the hard drive,  it does not catch SearchConduit as virus or malware.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
Shows how to create a shortcut to site-search Experts Exchange using Google in the Chrome browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch the Search Engine Menu: In chrome, via you…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now