• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 408
  • Last Modified:

Conduit and other pesky malware

Almost every week one of our BYOD users manages to get a Malware intrusion by Conduit, Rocket Fuel, FLV or other browser re-directors or pop-up controllers.  Currently there appears to be about six of these things that are prevalent.

I've tried recommending MS Security Essentials, Vipre anti-virus, BitDefender, McAfee, Symantic and other prevention tools yet nothing seems to be able to fully prevent this stuff.

Surfright's Hitman Pro is an excellent "2nd line" removal tool but I'd like to prevent intrusion in the first place.

I'd like to hear how others have dealt with preventing these problems as removing them can be very time consuming.
0
DesertDawg
Asked:
DesertDawg
  • 4
  • 3
  • 2
  • +2
2 Solutions
 
*** Hopeleonie ***IT ManagerCommented:
Have you tried to recommend  MS Security Essentials and Malwarebytes Anti-Malware Pro (one time fee of $24.95)?

I personally use Panda Cloud Antivirus Pro and Malwarebytes Anti-Malware Pro.

But note no security product can give you a 100% garantie. You also need to educate your users...
0
 
Thomas Zucker-ScharffSystems AnalystCommented:
What kind of devices are they bringing?  The answer depends on how far you can go and how far you want to go in restricting usage.  If it is a windows machine (laptop) you can use WINSelect from Faronics to mimic what SteadyState used to do for XP.  But be forewarned that the WINSelect component of Faronics is the nastiest if you want to get it off the device.

I image you shaking your head and saying you can't restrict the users' own machines  (as they are BYOD - but if they bring them into the workplace, they fall under your purview), in this case I recommend the following:

MVPS hosts file installed on all machines (FREE)
MBAM Pro (24.95 for a lifetime license) installed alongside any AV sofware
AV/AM software that has AWL (Application White Listing) capabilities (Comodo Endpoint Security - 60day/600 user trial is an excellent choice) (FREE to try)
WinPatrol Plus to monitor various files (29.95 for a lifetime license)
0
 
DesertDawgAuthor Commented:
I agree about educating the users but many are women who seem to spend a considerable amount of time on shopping sites.....in their own time, I presume.

I might give Panda Cloud a try.
0
 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

 
Thomas Zucker-ScharffSystems AnalystCommented:
SOPHOS says that approximately 80-85% of infections are due to driveby infections, many from perfectly valid websites.  Beware of malvertising.
0
 
*** Hopeleonie ***IT ManagerCommented:
Panda alone is not enough!
You need Panda Cloud Antivirus Pro and Malwarebytes Anti-Malware Pro (both).
0
 
DesertDawgAuthor Commented:
Thanks guys.  Anybody had experience with Bullguard?

The BYOD units are primarily Windows notebooks and various cell 'phones.  The laptops are the biggest problem.
0
 
*** Hopeleonie ***IT ManagerCommented:
Anybody had experience with Bullguard?
Yes I and would not recommend it!
0
 
DesertDawgAuthor Commented:
O.K!
0
 
Dave BaldwinFixer of ProblemsCommented:
The problem with Conduit is that it is not a virus or malware because #1 the user installed it whether they meant to or not, and #2 it does not by itself do anything 'bad' to your computer.  It's just unwanted because it takes over your home pages and search in your browsers.  It may invite other more dangerous programs to your computer but I'm not sure about that.
0
 
DesertDawgAuthor Commented:
I agree with you on it's non-malware functionality but it seems to get everywhere and cause the machine to slow down remarkably.....probably because of the numerous registry entries that it installs.  

It also leads you to other WEB sites that have notorious malware auto-downloads.
0
 
web_trackerCommented:
I agree that conduit is not malware in itself and is often bundled with stuff women like to download like groupon  or other coupon related garbage that gets installed on peoples systems. that is why we no longer give user admin rights to install their own software on the workstations we deploy. People bloat their systems so much with crap wear that the systems are grinding to a halt. Then they are calling us to support their systems because it is running super slow. Then they complain because they can't install updates because they don't have admin rights and they are getting popups to install updates...... sigh....

We finally decided to add the workstations to a managed group on the active directory so that the workstations are automatically updated.
0

Featured Post

Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.

  • 4
  • 3
  • 2
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now