Proxy Settings Re-Appear after Reboot in Registry Post Malware Clean (Windows 8.1 x64)

Hey Guys - 
My main system at home hosts many different things for me.  Because I'm an idiot and had protection disabled, I caught some malware which I cleaned off soon
afterwards.  The malware was listed as Trojan.Generic.KD or something similar.  It had enabled Proxy and set it to 127.0.0.1:58054.  I ran Malwarebytes, Spybot, then ExecuteIt to clean the malware off and currently the scans from all 3 apps
come back clean.  I also had to manually disable proxy via IE settings.
I have one specific app which for whatever reason will use Proxy settings if they are there over anything else and doesn't offer and configuration to disable it.
 Even though proxy is disabled (and cleared) in IE, this app still doesn't work and I still seemingly get redirected to ads in Chrome sometimes.  The log file of the app showed it was trying to connect through 127.0.0.1:58054.  The thing is,
IE Settings still show Proxy disabled!
The Issue
I checked many things are read a few articles to try to fix this including different Windows 8.1 settings, local Group Policy, startup items, checking Run keys
in HKLM and HKCU for "out of place" entries, and more.  Finally, I opened the registry and did s keyword search for ":58054" and found one key with it.  I cleared out all of the data and set the EnableProxy string from "1"
to "0", rebooted, and tried again but the app still failed with the same log message.  I went back into the registry and found out that the strings I changed had all been changed back!  Below is the key / strings I'm talking about which
are located in HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet
Settings.  It's odd because I usually deal with HKLM and HKCU and don't think I've ever worked in ".DEFAULT" on any system ever before.
I know that a full OS re-install is suggested - and I actually do it every 3-4 months religiously - but - I currently don't have the time for the full day it
takes to perform due to how many things it hosts.
Any ideas on how I can get this to stop coming back after each restart until I can perform the re-install?  Below are the system specs.  Thanks!
System Specs
- Intel i7-3770k / 16gb RAM
- x3 partitions  256gb SSD for OS & Apps  /  24tb Disk Pool for Storage  /  500gb Hybrid drive for App installs
- Windows 8.1 Update 1 x64 (Fully Patched)
Thanks again!
Ben K.

Hi,
.default is the profile for the Local System account and is an alias for
HKEY_USERS\S-1-5-18, Consequently, settings in HKEY_USERS\.Default are used by programs and services that run as Local System.
In addition to HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet
Settings, please also check HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet
Settings and HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings, make sure all proxy server disabled, then press F5 to refresh registry, check the application, if the issue disappears, the the registry entry is the culprit. Then please reboot the PC, if the issue appears again, the virus is not cleared in your
system. In this case, please try other virus clean program if possible, meanwhile, check if there're unknown software installed in your system.
Yolanda Zhu
TechNet Community Support

Similar Messages

  • HT200197 Menu will not appear after rebooting.

    After reboot, the menu no longer shows up.
    Only Computers and Settings icons appear.
    Can anyone assist?

    This indicates a Internet connectivity issue.  Although you are the 3rd posting I've seen on this today so it may also be an issue with Apple's servers.

  • X-Fi Audio Settings Not Remembered After Reboot - Solution

    I have an X-Fi Titanium Fatal1ty PCI-E on WIN7 64bit and I decided to try some different drivers, just out of curiosity. My drivers were working fine for the most part (except OpenAL BSOD) prior to this.
    After changing drivers, Windows would no longer remember my audio settings, such as volume level and all the changes I made in the Creative Console Launcher (EQ, disable CMSS-3D, THX settings). After rebooting, the settings would revert to the default setting.
    Solution:
    I went into the Creative Audio Control Panel, to the "Restore Defaults" tab and, with all boxes checked, hit the "Restore Defaults" button. Whatever was causing it to not remember settings was cleared out and it now remembers all of my audio settings after restarting Windows.

    Hy,
    have you already tried to start the soundcard ?at other PCs?
    Do you have this problem with other usb-devices at your PC, too?
    What happens after standby or hibernate?
    Does for example a li've linux or windows in secure mode detect the x-fi after startup?
    Maybe this details can be helpful to find the reason. I could imagine, the died internal sound card is inhibiting windows in detecting any other audio device...
    I've had a died touch pad (the left mouse button didn't work after ~5 minutes) and until disable it, the same problem happened with the other trackpoint mouse, too.

  • How can I stop Mac OS X from resetting proxy settings every time it reboots

    I have an issue I have been working on for a few weeks now.  We have several Mac Pros that connect to a Windows network.  We use an automatic proxy pac file from the proxy service.  I can change the settings in the network control panel, and in the browsers, even as the root ID in hopes it would hold and affect all of the users that may login.  But every time the Mac Pro reboots, the settings are reverted to the previous setting.
    I have tried setting up a fresh new location in the network control panel, but that has not helped.
    I am still learning Mac OS X and I have not figured this one out yet.
    Anyone have any ideas on how to set a proxy setting and have it apply to all the users that will login to our new settings?
    Thanks in advance.

    There are multiple ways to configure the proxy settings on a Mac it sounds like your trying to do it manually. All the places I have been that have used a proxy server have used the "Auto Proxy Discovery" method and this has worked fine. This will work fine for multiple user accounts on multiple Macs.
    For those unaware "Auto Proxy Discovery" uses WPAD (Windows Proxy Auto-Discovery) protocol. This means it either 'learns' the address to download a PAC file from via DHCP option code 252 (preferred), or if it cannot get that address via DHCP it tries using the DNS method.
    All the Mac web-browsers use the proxy settings learned via System Preferences -> Network -> Advanced -> Proxies however some other software particularly command-line tools may need configuring individually. For example curl needs to be told separately.

  • ~/Applications directory appears after reboot

    Hi,
    I have all my applications on the /Applications directory. I user also has an ~/Application directory in the home directory, but it is empty. I do not want that directory and, if I delete it, it apperars again after rebooting the Mac.
    Is there any way to avoid that?
    Also, the name of the /Applications directory is in Spanish (Aplicaciones), but the ~/Applications directory name (in my home folder) is in English

    Anyone?

  • Wacom Intuos4 tablet settings keep resetting after reboot

    I am not sure if anyone else is seeing this but on my fresh install of 10.6, I installed the latest drivers for my Wacom Intuos4 tablet and every time I reboot, the configurations are reset to defaults.
    I've also noticed that when I go into the Wacom preference pane in System Preferences, along with other preference panes (like Growl, for example), I have to restart the System Preference app.
    Is anyone else experiencing similar issues?

    This is a known issue with the current Wacom driver and it will have to be fixed by them in an update. In the meantime, you can make the preferences save by quitting System Preferences after changing any tablet settings and then reopening the Wacom prefpane in System Preferences and closing it again.

  • All user account settings missing/lost after reboot

    MacBook Pro
    10.4.10 Tiger
    I logged into my admin user account, one of the 2 accounts on this system (the Guest account is the second one), and noticed my wallpaper had been reset to the system default. Also, the dock was not as I had set it. I then started Mail. Mail came up as if it had not been run before, wanting to run through the set-up procedure. Other applications behaved the same.
    Please help! How can I restore my user settings?

    If I go to /Users I see three (2) folders: Guest and Shared and an alias with the FileVault symbol with my administrator username. In summary /Users looks like,
    Guest
    Shared
    jmartinezclark

  • Donwload settings always reset after reboot firefox

    as long as I restart my firefox4, the download settings automatic switch to always ask the place I want to save, not save file to a specific folder I specified.

    Hi...
    Try Resetting your Mac's PRAM and NVRAM
    If that didn't help, since your Mac was purchasd last October, it must be running Lion v10.7 and it's still under the one year warranty.
    Try using Lion Recovery to repair the startup disk or reinstall the Mac OS X.
    If nothing above helped, take your Mac to an Apple store or Apple certified repair provider.
    You can make a reservation at a Genius Bar in advance.

  • Cookies missing after reboot

    I'm running windows XP and lately all cookies were deleted every time I reboot my computer. All cookies, and default settings are gone after reboot, I even switched back to IE8 and same issue noted on both IE8 and Firefox 3.6.12

    Again and again!!!I reformatted my usb drive and created a brand new safepoint.
    everyting was ok but two days after, the system has rebooted (no warning and I don't know why) and my Safepoints are missing in the dashboard.
    Obviosly in the WDMyCloud desktop app the SP are visible... Frustating! :-(

  • Lost OEM informatio​n (manufactu​rer, brand, model, logo) after a clean windows installati​on

    Hi,
    It's been about a month since I remplaced my HDD, because the original one which has the recovery partition was currupted...
    So, I had to do a clean windows 8.1 x64 installation, after that I noticed that the OEM information (manufacturer, brand, model, logo) was lost, and I really want to get it back.
    Please help if there's any way to get it back to original.
    Thanks in advance !
    eCut

    @eCut ,
    Hello and thank you for posting on the HP support forums.  To obtain the original recovery media please check out the following link.
    HP PCs - Obtaining HP Recovery Discs or an HP USB Recovery Drive
    Or you may contact HP phone support.
    Please call our technical support at 800-474-6836. If you live outside the US/Canada Region, please click the link below to get the support number for your region.
    http://www8.hp.com/us/en/contact-hp/ww-phone-assis​t.html
    Thank you again for posting and have a great day.
    Please click the "Thumbs Up" on the bottom right of this post to say thank you if you appreciate the support I provide!
    Also be sure to mark my post as “Accept as Solution" if you feel my post solved your issue, it will help others who face the same challenge find the same solution.
    D5GR
    I work on behalf of HP

  • Windows 8 / IE11 forget proxy settings applied by GPO on reboot

    I've just about run out of ideas here on what may be causing this. I've toyed with policies quite often, but never ran into this problem before.
    Windows 8 with IE11. While there are GPO's active on the system, the settings are kept free to alter by the user if need be. We use a proxy, so I'm required to provide the proxy and the exceptions in a policy to the PC's to make sure they work under normal
    conditions. I added a couple of settings in the GPP (Group Policy Preferences) with the correct settings, enabled these settings (green lines) and tested these on a test system. They work fine, I get my proxy settings pushed through.
    Then we get to the rollout on the systems that are affected (not that many, just 10 accounts total, all in nearby rooms). I can run a gpupdate /force to reload the settings, and can confirm the proxy settings are applied properly. So the policy itself seems
    sound also on the workplaces it needs to be active on. Users still have the option to change the proxy settings on their own discretion, but that's exactly what we want to happen.
    Now we run into the problem that when part of these PC's are rebooted, the PC somehow seems to decide the proxy isn't worth its time anymore, and kills all settings for the proxy back to default. Either that, or it just switches the proxy off. Running a
    gpupdate /force reapplies the policy and everything starts working again, but WHY is Windows 8 / IE11 adament about forgetting these settings?
    The really maddening thing is that on a couple of PC's with Windows 8 and IE11 (and the same policies applied) it isn't a problem and the proxy remains filled in, as I would expect from GPO's. These include my test system, which makes me unable to replicate
    the problem and test locally.
    I've tried enhancing the policy with using a forced wait for the network to become available) aswell as a forced logonscript run on boot instead the standard 'after 5 minutes'. Find these under 'Computer Configuration - Policy - Administrative Templates
    - System - Logon' and 'Computer Configuration - Policy - Administrative Templates - System - Group Policy'. Neither setting seems to work tho. I've also tried going with a Computer Configuration Startup script in which I just request to run 'gpupdate' with
    the '/force' as the switches. But this also seems not to do anything.
    In short: Does anyone know why Windows 8 / IE11 falls back to something outside the scope of policies, while it accepts the forced policy update with the correct settings when 'gpupdate /force' is issued manually afterwards? And has anyone any idea what
    I can do to make sure the policy is applied regardless of what Windows 8 / IE11 thinks it should be?

    Just had a go with that... Found out that when I login and refresh the polciy using gpupdate /force, the proxy settings are filled in properly.
    Once I reboot tho, the proxy switches itself off (the entries regarding the proxyname and such remain, as does the 'bypass for local addresses, but it's all grayed out). Once I switch the proxy back on, and check under 'Advanced', I find everything in order,
    except for the exclusion list which is emptied.
    So I forced the gpupdate, verified that the proxy was switched on, and the exclusion list was populated. I then restarted the PC, only to find that above situation (proxy switched off, and exclusionlist empty) had reasserted itself.
    Waited a bit and did a forced policy update again. Then verified the logged files (which was just User.txt).
    After anonymizing the output a bit, I copied the contents to
    http://pastebin.com/YyWswW83 for your review. It looks like it contains 3 batches of GP updates.
    The one at 13:20 is likely the primary one in which I forced the GPUpdate. The one at 13:22 is the one issued on the restart of the computer, while the one at 13:24 is the (once again) forced gpupdate.
    From my understanding it seems as if the no-change of GPO detection works, but also causes it to skip the policy. Tho I admit that's speculation on my part. Any and all light you (or anyone else) may be able to shine on this, will be greatly appreciated.

  • Every time I ask Siri to find something near me, she says that she cannot find my location, and to turn on my location settings and siri settings. These are both on and after rebooting it still doesn't work. How do I fix this?

    Every time I ask Siri to find something near me, she says that she cannot find my location because I need to turn on location services in the settings menu and in siri. These are both on, and after rebooting my phone it still doesn't work correctly. How do I fix this?

    No, the app does not have to completely restart. It gets shifted in its open state into storage. Similar to how a computer uses the hard disk when it has insufficient memory.
    What complicates things is that sometimes memory does not get returned for reuse when you close an app. Thus yo should periodically double click the Home button and "delete" unnecessary apps from the multitasking dock and power off and then back on the iPod.

  • Calendar Settings reset after reboot

    Hi,
    Could anybody please check if you have the same issue on your phone?
    Sony Calendar resets settings after reboot.
    For example, if I set "Week starts on" = "Monday" and reboot the phone, this settings will be back to "Sunday" (which is the default). 
    I am now running Calendar 20.0.A.2.5, but I believe this bug was there before as well (even on my old Xperia V, I believe)
    P.S. I found this topic, but either I didn't understand the solution correctly or it doesn't work for me... I tried to disable the Calendar app, but it didn't help in any way...
    Solved!
    Go to Solution.

    I will forward this internally for further investigation. I will update you as soon as i have more information.
    But as a possible workaround, i suspect you have selected a country/region under Settings -> Language & input -> Language where the week normally is set to start on Sunday like English US? If you are in the Netherlands but want the phone on english you could try setting it to English UK instead to avoid this until i have more information.
     - Official Sony Xperia Support Staff
    If you're new to our forums make sure that you have read our Discussion guidelines.
    If you want to get in touch with the local support team for your country please visit our contact page.

  • Mavericks "forgetting" simple settings after reboot

    After upgrading to Mavericks I was surprised by the the new wave background image on all my spaces - while it is a lovely picture I use the background as a clue to which space I'm in, so I reset them to my own pictures/images as they were prior to the upgrade.
    After rebooting the images returned to the wave on all spaces - huh, that's weird...  So I reset them.
    I also noticed I had an AppleScript app that wasn't working right and I need to debug, so I turned off the "Open at Login" option for the app and went about my business.
    I rebooted again later in the day and once again my desktop images were reset and the AppleScript app was launched at login.
    What am I missing that Mavericks is forgetting these customization settings?

    I was having the same issue with background images. Every time I restarted, back to the waves...
    I've since placed in the image in Library>Desktop Pictures and changed the image through preferences. So far it's been holding (fingers crossed). Previously I had been using the Contextual Menu>Services>Set as Background Image to do it.
    There is also another way. Navigate to System>Library>CoreServices>DefaultDesktop.jpg.
    You'll see it's an alias to the Waves, background. In this case, just create a new alias with the correct privileges and the same name that points to your desired photo. You may have to do this as the root user.
    Lot's of trouble for a simple thing, hopefully it gets fixed.

  • ITunes settings lost after reboot

    I have a problem where after a reboot the settings of iTunes are back to default. For example:
    it loses the account for the Store (I have to re-enter email address and password);
    it loses the wifi sync settings for my devices
    it shows the iTunes tutorials screen, as if I'm starting iTunes for the first time
    settings under preferences are lost
    Other things are not lost:
    the library is still there;
    iTunes remembers the devices (when connecting it is handled as a known device) and knows what playlists/apps/.. to sync with it.
    Since I'm not rebooting my Windows 7 PC a lot, the problem is not occuring a lot, it doesn't keep me from using iTunes, it is just annoying. Now after rebooting I decided it's enough and I would post the issue (since I can't seem to find a comparable issue).
    Also worthwile noticing is that the problem is already there for some time, though I can't exactly pinpoint anymore when it started. Possible when iTunes 9 or 10 were realeased.
    Now I'm using:
    Windows 7 64-bit (completly up to date)
    iTunes 10.5.2.11
    Thanks for any help!

    Router>sh ver
    Cisco IOS Software, 1841 Sofware (C1841-IPBASE-M), Version 12.4(7d), RELEASE SOFTWARE (fc2)
    ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
    Router uptime is 34 minutes
    System return to ROM by power-on
    System image file is "flash:c1841-ipbase-mz.124-7d.bin"
    Cisco 1841 (revision 7.0) with 114688/16374K bytes of memory.
    Processor board ID FCZ1251943K
    2 FastEthernet interfaces
    1 Channelized (E1 or T1)/PRI port
    DRAM configuration is 64 bits wide with parity disabled.
    191K bytes of NVRAM
    31360K bytes of ATA CompactFlash (Read/Write)
    Configuration register is 0x2142
    Router>

Maybe you are looking for

  • Cascading Parameters prompting twice when scheduling report on CMC

    Hi all, I am having some difficulty with the Central Management Console (CMC) when scheduling a report I created. The report contains one sub-report with a stored procedure to generate the data. This stored procedure has 5 parameters including region

  • LaserJet M125a not printing with Windows XP SP3

    Hi everyone. Today I bought new printer. I wanted instal this printer on my old pc with Win xp but during installation appears window with warning " software for this device: "printer" has not passed compatibility testing with windows xp system". Non

  • Nadie me informa de nada

    Hace un mes estuve en la cañada applestore (marbella españa) con mi imac con un problema de pantalla (coincide con un numero de serie con programa de reparacion por fallos genericos en tarjeta de video). Como el articulo hacia mas de un año que lo ha

  • Tasks re-sorting in the MPP file when synching with SharePoint task list

    When synchronizing the MPP file with the ShPt task list, we have seen tasks re-sorting in the MPP file.  Very annoying, especially with schedules with a large number of tasks.  Just wondering if anyone has experienced this issue, and if you could poi

  • AP and EDI/IDOC

    Hi All, Any one worked on AP and EDI(AP payments),if so please forward configuration documents to my email id: [email protected] Thanks, Rau