Help Removing Manual Proxy Server 127.0.0.1:64550 Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by RSVCS, Jun 13, 2018.

  1. RSVCS

    RSVCS Private E-2

    I had joined the Windows 10 Insiders about early last 2017. All of a sudden after one of the builds I could not access the Internet. I checked the proxy setting due to an error message and saw the manual proxy was turned on and an address was in there. So I deleted the address and turned it off. Everything was fine until I rebooted. It came back. It began to progress to now it just shows up and I do a REGEDIT to clean it out and it comes back. No matter what I do it returns now even during the cleanup of the registry. Needless to say, I am no longer in the Windows 10 Insiders program. I have posted for help there so many times like so many others have and to no avail. They don't even respond to that. How can I get rid of it once and for all?

    I started the clean up advice from your website here and downloaded ADWCleaner. I have attached the file. The Advanced SystemCare 11 is what I have been using the keep my laptop clean. After clean up with AwdCleaner I downloaded the Malwarebytes, RogueKiller, HitmanPro & MGtools. The reason I have not proceeded forward is because I noticed these were from 2017 and 2016. I want to be sure that the most updated fix can be applied before I change anything else on here. After trying so many fixes it gets a bit crowded here with Anti malwares and all.

    Please help me. Thank you.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks
    I don't know what you're referring to... "these were from 2017 and 2016". Although the guide's instructions may not be very recent, they are accurate and the program links are to the current program versions. Please continue with running the requested tools and uploading their logs.

    Additional Scan to perform -
    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them both in your next reply.
     
  3. RSVCS

    RSVCS Private E-2

    I was in "Vista & Windows 7,8,10 Malware Removal/Cleaning Procedure" that was showing dates of 2016 and old software so I wanted to make sure I was in the most updated place for Windows 10 and for 2018 procedures. Thank you very much for responding. I have downloaded Farbar and attached the files requested. I do use SmartApp and Advanced SystemCare 11.
     

    Attached Files:

  4. RSVCS

    RSVCS Private E-2

    However, this manual proxy issue is with or without SmartApp. I had to do a system restore and went to a previous version of Windows 10. That was one of the things I did trying to fix this proxy problem. I did not realize at the time that is was a virus/trojan.
     
  5. RSVCS

    RSVCS Private E-2

    Oops I just noticed I did not fully comprehend your reply. I need to run all of the software fixes including the Farbar.
     
  6. RSVCS

    RSVCS Private E-2

    I have just completed running MALWAREBYTES, ROGUEKILLER, HITMANPRO, MGTOOLS and the files are attached. I did run the Farbar first by mistake. Please let me know if I will need to run that one again. It probably does not matter since these were not altered. I believe I cleaned my system with the ADWcleaner prior, I was following a tech from a different site. But I see that the issue was still there.
     

    Attached Files:

  7. RSVCS

    RSVCS Private E-2

    RogueKiller file
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please re-run RogueKiller and fix these detections:
    ¤¤¤ Registry : 4 ¤¤¤
    [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-1716382979-2854107662-905060344-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-1716382979-2854107662-905060344-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-1716382979-2854107662-905060344-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:64550;https=127.0.0.1:64550 -> Found
    [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-1716382979-2854107662-905060344-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:64550;https=127.0.0.1:64550 -> Found

    Re-boot , run RogueKiller again to generate an updated log..... upload that new log, please.

    This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.

    NOTES:
    * To avoid tying up resources on multiple forums, in the future please choose one forum's malware helper to work with until you are given the 'all clean'.
    * Please be advised that Advanced SystemCare 11 may now be broken after some of its components were removed by the malware scanners.

    Please tell me how your PC is running now.
     

    Attached Files:

  9. RSVCS

    RSVCS Private E-2

    I should have explained that I was on my own after the Windows 10 Insiders would not help so I was using YouTube videos to find solutions. I was trying different things on my own until I remembered MajorGeeks. This is my first time getting any help at all. And believe me I am so very grateful!! It seems that the issue still exists.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Referring to my initial instructions, please re-run Farbar Recovery Scan Tool and upload a fresh FRST.txt log.
     
  11. RSVCS

    RSVCS Private E-2

    Re ran Farbar files attached.
     

    Attached Files:

  12. RSVCS

    RSVCS Private E-2

    I ran a SCAN on the Farbar not FIX. Was that correct?
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, running a scan only was correct. *My research says that the ProxyServer setting is caused by having SmartApp installed. That can be verified by uninstalling it with Revo Uninstaller 2.0.5 Free, re-booting, and seeing if the ProxyServer setting still appears when FRST or RogueKiller are ran again. If so - I have something in mind to try afterwards.
     
  14. RSVCS

    RSVCS Private E-2

    AFter the removal of SmartApp.
     

    Attached Files:

  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    It looks like using Revo to do the uninstall solved your problem.
     
  16. RSVCS

    RSVCS Private E-2

    lets see how it holds for a few days. I would like to see if this is it. I did a system reset and it seemed to work for a few days but it came back. I won't install any other program. What would you advise for daily cleaning and keeping my laptop safe? Is Windows Defender sufficient?
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I'm not sure what type of "system reset" you did - what did that involve? Windows Defender in your present OS is quite good, however what or how would you be wanting to clean daily? <- A link to a list of recommended software for malware protection will be given when I post the final cleanup steps.
     
  18. RSVCS

    RSVCS Private E-2

    Thank you so very much for your help. I really hope this is it. I am amazed if this SmartApp has caused all of this trouble.
     
  19. RSVCS

    RSVCS Private E-2

    I did a Windows 10 restore to a previous version. It stopped it for a short while then it came back. I thought the manual proxy was coming from a windows 10 build.
     
  20. RSVCS

    RSVCS Private E-2

    This was last year when I was in the Windows 10 Insiders programs.
     
  21. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!
    There was something that was installed which changed the Proxy setting from the operating system's Default; sofar everything points to SmartApp. Let me know whenever you're ready for my final cleanup instructions.
     
  22. RSVCS

    RSVCS Private E-2

    Thank you so much. Yes, you most certainly correct. I was so positive it came from a build in the Windows 10 program because so many others had the same issue too about the same time I did and there was no solution offered. We were all ignored. The problem seems to be fixed. It has not come back. Too bad. I was due to collect payment for my troubles in July from this "SmartApp". However, this is far worth more! I am ready for the final steps. Thank you!
     
  23. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're very welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8/8.1/10 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work through the below link:
    Safe surfing!
     
  24. RSVCS

    RSVCS Private E-2

    Thank you so very much! I greatly appreciate all of your excellent help.
     
  25. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  26. RSVCS

    RSVCS Private E-2

    After all of this fine work I was downloading something my brother was telling me about and along came all of this malware stuff. I did not realize that I had clicked on some suspicious stuff that started multiplying. I ran the Malwarebytes and cleaned up most of it but now I am getting a horrible message from a fake Microsoft that I must call them immediately or they will block my computer etc. This happens every time I open a window on my laptop in Chrome. I was also wondering if you could help with my Android phone. I had that Smart Panel installed on my phone and uninstalled it but it is horribly slow too. I installed the CCleaner and use it regular as well as the Android LG cleaner but it is still slow and won't allow me to access the Internet. But first the laptop issues. My Internet is a different color so I know there is virus on here because my screen is a different color.

    Appended: After running Malwarebytes 7.2.2 My Chrome came back and I noted the infection is on Internet Explorer. Number to all is 888-929-7471. My Chrome has been restored. Advanced System Care 11 has been removed with the cleaning. What do you recommend as a good software to keep?
     
  27. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Let's do some follow-up as a precaution. Please go here: https://www.zemana.com/Download
    Scroll all the way to the bottom of the page and at the bottom of column 2 labeled Features you will find FREE AntiMalware. Click on it and download Zemana to your Desktop and run it. After the appl auto-updates, click on Scan. When it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that log, please.

    Also -
    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan may take some time.
    • Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.

    I'm not clear on what type software you are referring to. (?)
     
  28. RSVCS

    RSVCS Private E-2

    Sorry I meant Anti-malware software. I was using Advanced Systems Care but that does not seem to do the job very well or do I need something for Internet safety? I'm not sure what is good anymore these days to stay safe. It seems no matter what you do there is some virus hiding inside something.
     
  29. RSVCS

    RSVCS Private E-2

    Attached is the file requested. Thank you.
     

    Attached Files:

  30. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Have you run ZHPCleaner yet....waiting for its log.
     
  31. RSVCS

    RSVCS Private E-2

    This should be the file from the Zemana I ran last night.
     

    Attached Files:

  32. RSVCS

    RSVCS Private E-2

    I am so sorry. I just so the rest of the message. It was a very long painful day. My brain has been in a cloud. I was getting the file names crossed. I am completing the second part now.
     
  33. RSVCS

    RSVCS Private E-2

    Attached is the ZHPCleaner report. Thank you.
     

    Attached Files:

  34. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.
    Re-run ZHPCleaner per previous instructions
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
     
  35. RSVCS

    RSVCS Private E-2

    Attached the the ZHPCleaner Repair file. Thank you.
     

    Attached Files:

  36. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    What malware problems are you still having?
    *I am also curious as to how you were again troubled with a proxy-hijacker so soon - aren't you pre-testing file downloads for malware before installing them?
     
  37. RSVCS

    RSVCS Private E-2

    Its not the Proxy-Hijacker its the SavingsCool and Click.adservinganalytics I am seeing that is hijacking Internet Explorer. When I open a window I get a weird message that states to not close my browser window but to call Microsoft to save my windows account. I have to use Task Manager to close the window. I was trying to download a file my brother sent me and it had a trojan in it. I cleaned up most of it but this item is still lingering. I am probably not explaining it well. I used the CCleaner and it found most of the items. It started duplicating some other items that I was able to remove. Also ran MalwareBytes and cleaned up others.
     
  38. RSVCS

    RSVCS Private E-2

    That is why I am not sure how this file slipped past all of these unless I some how bypassed the warnings or somehow clinked on the wrong thing.
     
  39. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Reset Internet Explorer => https://mywindowshub.com/how-to-reset-internet-explorer-in-windows-10/

    Reboot, review the directions in my post# 2, then upload a fresh FRST.txt log.
     
  40. RSVCS

    RSVCS Private E-2

    These are the logs before deleting the personal settings. I went back and deleted the personal settings and will run Farbar Recovery Scan again because I had a full pop up again. So I just rebooted.
     

    Attached Files:

  41. RSVCS

    RSVCS Private E-2

    Thinking since there was no fix there was no difference. The issue still exists. These are the files after the second time running Farbar.
     

    Attached Files:

  42. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Following or not following the order of the instructions I gave results in different FRST.txt logs being generated.

    re: Adware SavingsCool and Click.adservinganalytics
    *Perform "Step 1: Scanning for adware/junkware to remove later of the R&R ME First guide and upload that log.

    Also upload a screen-capture of whatever window you're having to close.
     
  43. RSVCS

    RSVCS Private E-2

    Malwarebytes report from today. Running RogueKiller.
     

    Attached Files:

  44. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please upload the ADWCleaner scan log, which is Step 1....
     
  45. RSVCS

    RSVCS Private E-2

    Rogue Killer report.
     

    Attached Files:

  46. RSVCS

    RSVCS Private E-2

    Oh sorry I thought I did that one first. When I open ADWareCleaner it is MalwareBytes. Is that not correct? That is the file I uploaded first before Roguekiller. Did send the correct report?
     
  47. RSVCS

    RSVCS Private E-2

    HitmanPro log file
     

    Attached Files:

  48. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  49. RSVCS

    RSVCS Private E-2

    Okay running it now. I had 7.2.0.
     
  50. RSVCS

    RSVCS Private E-2

    AdwCleaner 72.2 file
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds