Proxy settings keep on changing automatically...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hassanrasheed, Jul 15, 2015.

  1. hassanrasheed

    hassanrasheed Private E-2

    I have attached the log files of the various anti-malware/virus apps according to the guidelines provided in the post titled "Vista & Windows 7 Malware Removal/Cleaning Procedure". Please advise on how to proceed from here. Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not attach the correct log for RogueKiller. Please do so now.

    Re run Malware Bytes and have it remove all it finds.
    Same for Hitman Pro please.

    Then do this....

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. hassanrasheed

    hassanrasheed Private E-2

    Thanks for your reply :)

    Sorry for the incorrect log for Rogue Killer earlier. The correct one is attached now.

    Have run Malwarebytes and Hitman Pro as you advised.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)

    [​IMG] Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fyxcppne (System32\drivers\fchco.sys) -> Found

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Delete this file if you see it. Let me know.
    • C:\WINDOWS\SysNative\drivers\fchco.sys


    Explain how things are running.
     
  5. hassanrasheed

    hassanrasheed Private E-2

    Hello :)

    I have located the said file through Rouge Killer and deleted it.

    The report/log is attached.

    After rebooting, I ran a search for the "fchco.sys" file. It turned up in the following folder:

    C:\System32\drivers\fchco.sys
    instead of
    C:\WINDOWS\SysNative\drivers\fchco.sys

    I deleted that anyway.

    A quick question: I have installed the paid version of Hotpsot Shield which is presently turned off. The proxy settings aren't changing at the moment. Is there a connection between Hotspot Shield and the change in proxy settings?
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes it's likely that when Hotspot Shield is turned on again the proxy may return, if it does, at least you know it's because of that.

    Re enable it, and then rescan with RogueKiller, let's see what happens. Let me know if proxy entries come back.
     
  7. hassanrasheed

    hassanrasheed Private E-2

    Yep, as soon as I turned on Hotspot Shield, the proxy returned. Internet connectivity is fine however. Is this alright or should I just get rid of Hotspot Shield altogether?

    Rogue Killer log is attached.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you need the software we are questioning? It's all very well me saying get rid, but you might actually use it. Did you install it knowingly?
     
  9. hassanrasheed

    hassanrasheed Private E-2

    Yes actually I do need Hotspot Shield (which is a VPN service) to view Youtube, which can't be viewed in my country otherwise and plus I have paid $30 for a year's subscription. So what do you recommend.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It stays. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds