Hijacked proxy settings, lots of ADs

Discussion in 'Malware Help (A Specialist Will Reply)' started by BubbaJay89, May 4, 2014.

  1. BubbaJay89

    BubbaJay89 Private E-2

    Hello there MajorGeeks Helper,

    for the first time of my life, I'm experiencing a malware problem, I'm not able to get handled myself.

    Scince may 1, I get a lot of ads shown in all my browsers. Most of them are embedded ads, but sometimes links, that should've been clean are redirecting to an ad.

    After my first investigations I noticed, that my browsers now tend to use a proxy, but I can't find out which one. Proxy settings are set to 127.0.0.1:8118. I guess this 'hijacker' is using an installation of Privoxy, which I never installed in the first place. (It's running in background, able to see it in task manager. If killed, browser isn't able to connect to internet until i change proxy settings. It's not working for long, proxy settings will be reverted to the above after about 5 - 30 seconds.)

    Please help, it's really annoying.

    P.S.: Why aren't Grisoft AVG Free and IObit Malware Fighter able to handle such threads?


    Best regards an a big tank you
    BubbaJay
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fix these items in RogueKiller:

    Code:
    ¤¤¤ Registry-Einträge : 10 ¤¤¤
    [RUN][SUSP PATH] HKCU\[...]\Run : InetStat ("C:\Users\Jens\AppData\Roaming\InetStat\inetstat.exe" /c=5 [7]) -> GEFUNDEN
    [RUN][SUSP PATH] HKUS\S-1-5-21-293272317-256204014-334039894-1001\[...]\Run : InetStat ("C:\Users\Jens\AppData\Roaming\InetStat\inetstat.exe" /c=5 [7]) -> GEFUNDEN
    [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:8118;hxxps=127.0.0.1:8118 [Country: (Private Address) (XX), City: (Private Address)]) -> GEFUNDEN
    [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyEnable (1) -> GEFUNDEN
    Then reboot and see if the issue remains.
     
  3. BubbaJay89

    BubbaJay89 Private E-2

    Hi TimW,

    thanks for your help. Didn't solve anything, ADs still occure and the proxy setting are still refreshing the same way alike.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this happening in all browsers? Which ones?
     
  5. BubbaJay89

    BubbaJay89 Private E-2

    Chrome, Firefox, IE, Opera...didn't test Safari yet
     
  6. BubbaJay89

    BubbaJay89 Private E-2

    Found sth interesting...

    Proxy is Privoxy hooked at 127.0.0.1:8118

    It's installed in C:\Program Files(x86)\MSR\

    user.action
    user.filter

    Those two files contain code strangely looking like .htaccess entries. The Ads are hooked up in here (addelivery1.....). Tried swapping both files with empty ones, but after reboot they are back to "normal".

    After deleting the whole Privoxy install my browser isn't able to open connections, obviously because the proxy is gone. Changing proxy settings still reverts back though. After reboot the installation is back, too.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and attach the new log.
     
  8. BubbaJay89

    BubbaJay89 Private E-2

    Rogue Killer log
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and fix these items:
    Code:
    ¤¤¤ Registry-Einträge : 12 ¤¤¤
    [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:8118;hxxps=127.0.0.1:8118 [Country: (Private Address) (XX), City: (Private Address)]) -> GEFUNDEN
    [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyEnable (1) -> GEFUNDEN
    Reboot and tell me how things are running.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does this exist in your Add/remove list:
    System Update kb70007

    If so, you need to delete it.
     
    Last edited: May 8, 2014

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds