Browser Hijacker

Discussion in 'Software' started by DukOfURL, Sep 17, 2013.

  1. DukOfURL

    DukOfURL Private E-2

    I recently downloaded a copy of imgburn, the excellent CD/DVD burn freeware. I thought I was careful to uncheck the "make this funny stuff my search engine and home page" boxes, but maybe I didn't. I sure thought I did.

    In any case, the Conduit stuff took over the homepage and search engines of IE, Chrome, and Firefox. It was quite persistent, reappearing each time I removed it or thought I did. I finally went through a process recommended by Microsoft forum using three different malware programs. Hitman Pro even found the executable of imgburn.exe suspicious and wanted it removed. Anyway. I am clean now.

    Has anyone ever heard of a firm so sneaky (I am speaking of this Conduit outfit) that they would install this even if the check box was clear?
     
  2. COMPUABLE

    COMPUABLE First Sergeant

    >> Has anyone ever heard of a firm so sneaky (I am speaking of this Conduit outfit) that they would install this even if the check box was clear? DukOfURL <<

    Yes, I would believe it... ImgBurn which is developed by a company called "Lightning UK!" is quite notorious throughout the Internet for its numerous very nasty, persistent and hard to remove adware programs; which are generally installed onto the (usually unsuspecting) users' computers throughout the ImgBurn installation process with little or no warning at all.

    It therefore does not surprise me to hear that you encountered the "Conduit Search" which is an adware program that persistently changes the users' home page and default search engine to search.conduit.com. As an example how prevalent this problem is: The search terms "Conduit Adware" using the Google search engine garners: About 3,540,000 results.

    Something else that has always bothered me about this ImgBurn adware-sponsored program; is the fact that there seems to be quite a suspicious number of "first time posters" on many of the software download websites out there, who seem to post glowing (and yet almost entirely similar) reviews of this software program - sometimes even word-for-word and on the same dates as well.

    Good Luck! -- COMP​
     
  3. plodr

    plodr Major Geek Super Extraordinaire

  4. DukOfURL

    DukOfURL Private E-2

    I did use MajorGeeks to download it. And I thought I was careful to unclick the "load me up with PUP's" boxes but maybe I wasn't. I was wondering if anyone had come across instances where the "don't install this" was ignored and the stuff installed anyway.
     
  5. DocTomJohn

    DocTomJohn Private E-2

    I am new to this Forum, so please forgive me if I have missed an answer to my query, even though I did use the search facility.

    Re. Imgburn, can anyone confirm unequivocally whether a download from MajorGeeks of Imgburn, when all the boxes to include adware, toolbars etc are ticked or unticked to deny the offensive add-ons, results in the adware being installed (or not)?

    (Note : it seems from web searches that downloads from some sites DO result in adware, even though the options to deny are correctly entered. Hence I ask specifically about downloading from MajorGeeks, which I take to be a trustworthy site.)
     
  6. DukOfURL

    DukOfURL Private E-2

    I don't think it has anything to do with Majorgeeks. I believe it is the same from any download site. And I cannot unequivocally confirm that I had the boxes unchecked. I thought I did, as I always uncheck those offers. But in the interest of science, I am going to reinstall it and make sure this time. Then I will report back if the Conduit stuff is installed in spite of me telling it not to.

    In the meantime, I think you can use BurnAware Free, a very good burner itself.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. I went and downloaded ImgBurn from our website just to settle a few things.

    I am including screenshots of the process I went through and what exactly I had to opt out of.

    First of all there was the chance to allow Real Player to be installed. All we have to do is NOT check the box. (See screenshot)

    Next, we have the option of an express or custom installation.
    If you choose the express and reccommended installation, you will end up with Tune Up Utilities installed.

    Even if you choose CUSTOM, you have to ensure the box is unchecked for Tune Up Utilities (See screenshot)

    Installation was then complete. I restarted my machine and tried out both IE and Firefox. No home page changes, no unwanted software installs, no complaints at all. :)
    If I uninstalled it and went to reinstall, I might well be offered a different set of junk, such as conduit, but it's all the same, just have to pay attention.

    You can safely download ImgBurn from Majorgeeks without having to worry. Just be vigilant during install process, take your time and don't rush through, and it would be hard to let any junk slip by.
     

    Attached Files:

  8. sikvik

    sikvik Corporal Karma

    Hey Kes, did this earlier today as well. :)
    1. The crap offer for snap.do
    2. An offer to install Nitrous PDF viewer.
    I went custom and installed.
    Ran a scan with MBAM and it flagged the PUP OpenCandy. Zapped the ImgBurn installer right off the desk top. :-D
    Nothing terrible though.


    Cheers..
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Sikvik :)

    Malware Bytes detected two OC related objects for me too.
     

    Attached Files:

  10. _nullptr

    _nullptr Major Geeky Geek Geek

    With all OpenCandy bundled installers, if you disconnect from the internet or block the outbound communication with a firewall, you won't be offered any other junk.
    After installation, you'll still have a couple of instances of rundll32.exe running that host ocsetuphlp.dll
    You can either kill these rundll32 instances or do the easy thing and reboot. The OC related files are automatically queued for the Windows Session Manager to delete on boot.
     
  11. DocTomJohn

    DocTomJohn Private E-2

    So it looks like the consensus, though not unanimous, is that the download is contaminated, even from this site! To be avoided ?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds