MobileTechie
01-15-2011, 09:01 PM
I have a laptop in which had a fake AV infection. This was dealt with but Hitman kept finding an infected file and a proxy set on a 127.0.0.0:8074
I've checked it out with the usual array of AV tools like MBAM, SAS and Hitman and TDSSKiller. I reset the MBR both using MBRCheck and then again offline. Manual investigations with tools like Kernel Detective and Malware Defender and Autoruns have found no startup entries but a few inconclusive kernel hooks. Sigverif was finding an unsigned driver but not anymore. Offline scans found a rootkit and a trojan which were removed.
The system seems to be running absolutely fine and there are no redirections going on. No virus scan finds anything. Various MBR checkers come up clean. However, Hitman still claims IE is connecting to the internet via the 127.0.0.0:8074 proxy after each reboot. There is no sign of this proxy in Internet Options or in the related registry keys.
I'm trying to work out whether the infection is still present or whether this is a Hitman Pro bug.
I've checked it out with the usual array of AV tools like MBAM, SAS and Hitman and TDSSKiller. I reset the MBR both using MBRCheck and then again offline. Manual investigations with tools like Kernel Detective and Malware Defender and Autoruns have found no startup entries but a few inconclusive kernel hooks. Sigverif was finding an unsigned driver but not anymore. Offline scans found a rootkit and a trojan which were removed.
The system seems to be running absolutely fine and there are no redirections going on. No virus scan finds anything. Various MBR checkers come up clean. However, Hitman still claims IE is connecting to the internet via the 127.0.0.0:8074 proxy after each reboot. There is no sign of this proxy in Internet Options or in the related registry keys.
I'm trying to work out whether the infection is still present or whether this is a Hitman Pro bug.