Solved

drudgereport.com redirection

Posted on 2014-02-06
6
1,033 Views
Last Modified: 2014-02-11
DrudgeReport.com RedirectedDefault Home Page in IEIE LAN SettingsHi,
  I have a strange situation with this user's Windows 7 PC.
  He as two browsers - IE and Firefox. Recently this computer was attacked by some type of viruses and it planted some stuff in Proxy settings, so I had to clear those in both browsers.
  Now the problem is that even if I set the home page to http://www.drudgereport.com/ on both IE and Firefox, when I open them, it displays an error screen like above screenshots.
  I can visit ESPN.com, YAHOO.com w/o a problem.
  The reason "Proxy server" section looks recessed is because I ran GPEDIT and disabled it so that no one can add anything to proxy server section.

  Can you help?
0
Comment
Question by:sglee
  • 2
  • 2
  • 2
6 Comments
 
LVL 8

Accepted Solution

by:
Chris Wong earned 250 total points
ID: 39841031
0
 

Author Comment

by:sglee
ID: 39841044
SearchConduit malware taken over ChromeChrome Search Engine SettingYes They subscribe to AT&T  DSL Service. I just ran NSLOOKUP and it showed:
C:\Users\Brent>nslookup ibm.com
Server:  dsldevice.att.net
Address:  192.168.1.254

I also just installed Google Chrome and I can browse www.drudgereport.com.
Now I am just confused as to why Google Chrome does something different from IE and Firefox.
Also I noticed that this computer is infected with SearchConduit malware. Even though I set default URL to google.com in Chrome, it displays something else like screenshot.
0
 
LVL 8

Assisted Solution

by:Chris Wong
Chris Wong earned 250 total points
ID: 39841093
Conduit Search – Virus Removal Guide

http://malwaretips.com/blogs/remove-conduit-search-virus/
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 250 total points
ID: 39841226
You can remove Conduit in 'Uninstall programs' but you also need to change the default home page and search engine too.  Just did that on a client's computer this evening.  And usually if you have Conduit, you also have several of it's 'friends'.  My client had 6 different installs from yesterday and she said she didn't install anything on purpose.  I just looked at the install dates in the Add/Remove Programs list to find them.
0
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 250 total points
ID: 39841231
This info is just telling that ATT forces DNS lookups to go thru their service.  I've seen this on other AT&T modems.  I have a Netgear router that does that also.  It screws up the 'nslookup' program but still allows 'normal' DNS queries to go thru.
C:\Users\Brent>nslookup ibm.com
Server:  dsldevice.att.net
Address:  192.168.1.254

Open in new window

0
 

Author Comment

by:sglee
ID: 39841566
Update:
I found an article on google regarding SearchConduit. It suggested that I use CCleaner. So I downloaded it and ran it and and it worked.
IE and Firefox displays drudgereport.com as home page upon start.
This computer has spydoctor anti-virus program installed, but when it scans the hard drive,  it does not catch SearchConduit as virus or malware.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Invalid Profile Message On Windows 7 8 33
How to block internet connection for windows7 11 58
Total AV worth it? 4 89
Understanding UserAgent String 2 15
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
Google currently has a new report that is in beta and coming soon to Webmaster Tool accounts. This Micro Tutorial will highlight new features for Google Webmaster Tools.

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question