I have a suspected virus which keeps ticking my Proxy Server box in IE. Initially this just stopped my internet access until I un-ticked the box. Then after a while email access was effected and Windows become more sluggish. I did a system restore which improved things but the Proxy Server issue is still there. I am running Windows 8.1
Attached are my OTL & HijackThis logs (pasting them did not work for some reason)
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
please follow all instructions in the order posted
please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
if you don't understand something, please don't hesitate to ask for clarification before proceeding
the fixes are specific to your problem and should only be used for this issue on this machine.
please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
I am looking at your logs now and will reply with instructions shortly.
[external image: thisisujrt.gif] Please download Junkware Removal Toolto your desktop.
shut down your protection software now to avoid potential conflicts.
run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
the tool will open and start scanning your system
please be patient as this can take a while to complete depending on your system's specifications
on completion, a log (JRT.txt) is saved to your desktop and will automatically open
post the contents of JRT.txt into your next message.
Please run OTL again after you’ve completed the above.
It appears that AdwCleaner sorted out some of the bad stuff but I’m not convinced that it has all gone so we’ll run some other checks.
Before that, some advice:
IObit Security 360 is a rogue security program known to cause system problems and that had stolen material from other computer security companies to use in their own program.
I recommend that you uninstall IObit. It is has been proved to be untrustworthy in its programming and is pretty ineffective now that it can no longer be propped up by MBAM
There is a company that has created a free program designed specifically to remove every last trace of the entries of IObit programs left behind if and when you had decided to uninstall one of them but I don’t think it’s compatible with Windows 8 so just uninstalling will have to do for now.
I also see you have RegClean Pro. It's not a good idea to use registry cleaners/boosters.
The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid and erroneous entries does not affect system performance but it can result in "unpredictable results". Unless you have a particular problem that requires a registry edit to correct it, (and you are expert in the registry), I would suggest you leave the registry alone.
I strongly advise you to get rid of RegClean Pro and any other cleaner/optimizer/booster/tuneup/tweak type utilities that you have on this or any other computer.
One of the malware experts, miekiemoes, has an excellent write-up here
Another excellent article by Bill Castner is located here
IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!
Close all running programs.
Download RogueKiller to your desktop.
close all running programs
double-click on RogueKiller.exe
when the pre-scan is finished, click on Scan
click on Report and copy/paste the content in your next post
NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.
Please post the contents of the RKreport.txt in your next reply.
double click DDS icon to run the tool (may take up to 3 minutes to run)
when done, DDS.txt will open.
after a few moments, attach.txt will open in a second window.
save both reports to your desktop.
Post the contents of the DDS.txt and Attach.txt reports in your next reply.
Please POST the results of the 2 scans, NOT attach them – sorry about the capitals but I asked you before to copy/paste them and you went ahead and attached them.
The logs to include are:
RKreport.txt
DDS.txt
Attach.txt
Can you also tell me how your computer is running now.
I tried uninstalling IObit and RegClean Pro but could find no entries in the Uninstall Programs list. I did try a few programs to get rid of the suspected virus before contacting this forum (which I subsequently uninstalled) so maybe the entries are remnants from this.
I have run Rogue Killer as requested and tried to post the resulting text file directly but as before this did not work
I used the following procedure:-
In Notepad I used Edit > Select All then Edit > Copy to get the text
Back in the forum reply box I right clicked and selected Paste but nothing pasted in
I tried selecting/de-selecting word wrap but it made no difference, I also tried the Paste as Plain Test icon, but again no joy
This is the reason I attached the files in my last post rather than pasting them directly
I will await your suggestion before attaching anything
I also tried running the DDS.pif program but it just displayed the message 'DDS is not meant to run in 'Compatibility Mode' The program shall now exit.
Operating System : Windows 8 (6.2.9200 ) 64 bits version
Started in : Normal mode
User : Paul [Admin rights]
Mode : Scan – Date : 12/01/2013 18:15:21
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 8 ¤¤¤
[HJ POL][PUM] HKCU\[…]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKCU\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ POL][PUM] HKLM\[…]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ POL][PUM] HKLM\[…]\Wow6432Node\[…]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKLM\[…]\Wow6432Node\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK][PUM] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND