I caught that thing last year when it forced a search engine into my browser and took control of my home page and the ability to uninstall addons. They used a very convincing window from Adobe for my viewer that didn't trigger my malware detection. None of the cleaners I found on the Internet for it worked or they wanted $19.95 to unlock the cleaner after showing all the payloads and registry paths. So I had to dig it out of my registry long hand while following about 27 file paths to get rid of every place it hid itself. At the last location it had removed every user and group's access to the file and folder. Once I got that taken care of, finally, a deep scan in safe mode detected the rest of the hidden payloads.
That was last years vintage of conduit.