Adlice forum
General Category => Malware removal help => Topic started by: snakebait on November 18, 2014, 01:09:19 AM
-
windows 8.1 machine.
I cleaned up the pc and everything is fine except the proxy.
It keeps auto filling and no matter what I changed, I cannot fix it. Here is RK scan. I'm not sure is these pum.proxies are correct
-
Yeah, remove them
-
Ok, Most of them deleted, and some came back with errors on them. rebooting and going to scan again.
Also what about the Hook under anti-root kit? it seem that those can be legit at times.
edit: after reboot. All are back.
-
Yeah, antirootkit entry will be whitelisted
-
still no luck clearing the Proxies. As soon as I unchecked it and hit OK and immediately go back in the are auto-filled. RK doesn't seem to remove the entries.
-
Or something put them back.
Can you scan with Malwarebytes?
-
logs and stuff
-
And after a reboot they are back?
-
correct. still here.
-
Are you using a VPN?
Can you install Proces Hacker, then open it
In "Network" tab, could you locate the column "Local Port" that has the value 13081 (you can sort the column) and tell what process is listening on it?
-
I don't believe that it's even up?
And also no VPN.
-
I'm not sure the filter works for port, it may but I'm not sure.
When you simply sort the column without filtering, do you find something?
If not, that means the proxy software isn't running, which would be very strange...
-
yes, when I click on network tab, it shows 75 processes running.
-
Yeah, but do you find the given port?
-
No, it goes from 8000 to 26143
-
Ok, so when i make a new account everything is fine with the proxies. They disappear and stay away. However, the start screen doesnt seem to have all of the info as a new user should, and the store doesn't work at all.
-
Is it company's PC?
-
nope
-
Could you try that? http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
-
I'm sorry Tigzy. I went ahead and did a reinstall. I spent way to much time on this for my client. He will have to re-install his games and start over.
But thank you very much for your help. It would have been nice to see what actually was causing this.
thanks again.
-
No problem, I understand.