Virus Proxy http=127.0.0.1:6061

basi -  
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   -
Hello,

I already mentioned this last week on this subject that I thought was resolved, but unfortunately, I see that there are still a few small things to fix.

I have a virus that modifies my proxy settings every time I restart my computer, and I thought I had gotten rid of it, but it's back! (I promise I haven't downloaded anything suspicious in the meantime)

The difference from last time is that I can change the proxy settings and access the internet, but I have to do it every time I restart the computer because the virus reconfigures them.

Here are my 3 FRST files:

FRST.txt
https://pjjoint.malekal.com/files.php?id=FRST_20190428_x12r7q15o11d7

Addition.txt
https://pjjoint.malekal.com/files.php?id=20190428_k8s5n13w14j6

Shortcut.txt
https://pjjoint.malekal.com/files.php?id=20190428_t10s97u1115

Thank you in advance for any help you can provide!

5 answers

  1. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
     
    Here is the correction to be made with FRST. You can refer to this explanatory note with screenshots.
    Restart FRST and then press CTRL + Y on your keyboard.
    The Notepad will open, copy/paste this.

    Start
    CloseProcesses:
    CreateRestorePoint:
    2019-04-07 16:07 - 2019-04-28 21:03 - 000002930 _____ C:\WINDOWS\System32\Tasks\Re-attempt Adobe® Flash Player Install
    2019-04-07 16:07 - 2019-04-28 21:03 - 000002536 _____ C:\WINDOWS\System32\Tasks\Inno Setup® Software Update Scheduler
    2019-04-07 16:07 - 2019-04-07 16:25 - 000000000 ____D C:\Program Files\KMSpico
    2019-04-07 16:07 - 2019-04-07 16:07 - 000003584 _____ C:\WINDOWS\SECOH-QAD.dll
    Program Files (x86)\Common Files\Inno Setup
    C:\ProgramData\Adobe Flash Player
    EmptyTemp:
    RemoveProxy:
    Reboot:
    End


    Save the content from the file menu and then save.

    Close Notepad, return to FRST, and click the "Fix" button.
    A reboot may be necessary and automatic.
    A text file will appear, copy/paste the contents here in a new message.

    Restart the computer.

    2°)
    Finish with a cleanup using Malwarebytes - Malwarebytes Anti-Malware Free Version Tutorial

    --
    Please press a key to continue the disinfection...
    2
    1. basi
       
      Hello,

      Here is the fixlog: https://pjjoint.malekal.com/files.php?id=20190429_h14f8y7x8u13

      Thank you!
      0
    2. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711 > basi
       
      Is it better?
      0
    3. basi
       
      The proxy is unfortunately still active...
      https://pjjoint.malekal.com/files.php?id=20190429_o8i7n8f14u10
      0
    4. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711 > basi
       
      Malwarebytes finds nothing?
      0
    5. basi > Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention  
       
      No... I just ran it again right now but it doesn't detect anything unusual.
      It's quite annoying. This virus is very stubborn!
      0
  2. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
     
    I think it's him:
    C:\Program Files (x86)\Common Files\Inno Setup\Updater\InnoUPD.exe

    Can you upload this file to MediaFire and provide the link here to check?

    Here is the correction to be made with FRST. You can use this explanatory note with screenshots as a guide.
    Restart FRST and then press CTRL + Y on your keyboard.
    Notepad will open, copy/paste this.

    Start
    CloseProcesses:
    CreateRestorePoint:
    Task: {6E0DF1A4-D106-4C4E-98C1-DAB27B60D8F9} - \Inno Setup® Software Update Scheduler -> No file <==== WARNING
    2016-05-08 18:17 - 2016-05-08 18:17 - 000000000 _____ () C:\Users\Sébastien\AppData\Local\{E2F71E9A-5D9A-49BD-BF16-D123E0C10EA7}
    Task: {CC21E712-2FAB-433F-B22E-8C499EA4CD6F} - \Re-attempt Adobe® Flash Player Install -> No file <==== WARNING
    C:\Program Files (x86)\Common Files\Inno Setup
    EmptyTemp:
    RemoveProxy:
    Reboot:
    End


    Save the content using the file menu then save.

    Close Notepad, go back to FRST and click the "Fix" button
    A restart may be necessary and automatic.
    A text file will appear, copy/paste the content here in a new message.

    Restart the computer.

    --
    Please press any key to continue the disinfection...
    1
  3. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
     
    Hello,

    Here is the correction to be made with FRST. You can refer to this explanatory note with screenshots.
    Restart FRST and then press the CTRL + Y keys on your keyboard.
    The notepad will open, copy/paste this.

    Start
    CloseProcesses:
    CreateRestorePoint:
    EmptyTemp:
    RemoveProxy:
    Reboot:
    End


    Save the content via the file menu and then save.

    Close the notepad, return to FRST and click on the "Fix" button.
    A restart may be necessary and automatic.
    A text file will appear, copy/paste the content here in a new message.

    Restart the computer.

    --
    Please press a key to continue the disinfection...
    0
  4. basi
     
    Hello,

    I have followed these steps but the proxy is still enabled in the same way...

    Thank you for your response and your help.
    0
    1. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
       
      Please provide the text to be translated.
      0
      1. basi > Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention  
         
        I am attaching it here:
        https://pjjoint.malekal.com/files.php?id=20190428_m14r6i9v9u14
        0
  5. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 711
     
    Ok, redo a FRST scan and let the analysis go all the way, because in your first message, the FRST.txt file is cut off.
    Then provide the links again.

    --
    Please press any key to continue the disinfection...
    0
    1. basi
       
      Indeed! Here are the untruncated files
      https://pjjoint.malekal.com/files.php?id=FRST_20190428_w6r6m10p8j12
      https://pjjoint.malekal.com/files.php?id=20190428_j14e13b11j13e14
      https://pjjoint.malekal.com/files.php?id=20190428_j14e9q5y8l11

      Thank you very much!!!
      0