# A strange virus...

**URL:** https://boards.straightdope.com/t/a-strange-virus/598827
**Category:** Factual Questions
**Created:** [October 6, 2011, 9:55pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827 "2011-10-06T21:55:00Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![Terr](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Terr](https://boards.straightdope.com/u/Terr)
#### Post date: [October 6, 2011, 9:55pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827/1 "2011-10-06T21:55:00Z")

</div>

I have something on my computer (I presume an infection) that every 5 to 10 hours changes the proxy settings in my MSIE (and only MSIE) to 128.0.0.1:59636. Nothing listens on that port, so IE (and anything that relies on WININET) just fails until I go in and change it back.

I did a few google searches and cannot find any reports of a virus that does this. Any of you guys know what’s going on?

---

<div class="post-metadata">

### Author: ![Alley\_Dweller](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/alley_dweller/32/430_2.png) [@Alley\_Dweller](https://boards.straightdope.com/u/Alley_Dweller)
#### Post date: [October 6, 2011, 9:59pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827/2 "2011-10-06T21:59:51Z")

</div>

Have you run Malwarebytes’ Anti-Malware?  
If not, try that first. You can download the [free version here](http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button).

After you’ve run that, let us know what (if anything) it finds.

---

<div class="post-metadata">

### Author: ![Terr](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Terr](https://boards.straightdope.com/u/Terr)
#### Post date: [October 7, 2011, 2:34am UTC](https://boards.straightdope.com/t/a-strange-virus/598827/3 "2011-10-07T02:34:28Z")

</div>

> [@Alley\_Dweller](#):
>
> Have you run Malwarebytes’ Anti-Malware?  
> If not, try that first. You can download the [free version here](http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button).
> 
> After you’ve run that, let us know what (if anything) it finds.

Ran it. Didn’t help me much 🙂

It found: [PUM.bad.proxy - Wikipedia](http://en.wikipedia.org/wiki/PUM.bad.proxy)

I already know that the registry entry got changed and I know how to “fix” it (that is, turn off the proxy setting in IE). The problem is that something sets it again in a few hours, and that wiki entry (or Malwarebytes) doesn’t tell me what does it…

---

<div class="post-metadata">

### Author: ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)
#### Post date: [October 7, 2011, 3:14am UTC](https://boards.straightdope.com/t/a-strange-virus/598827/4 "2011-10-07T03:14:33Z")

</div>

Running Malware Bytes in safe mode helps with most things. The virus usually doesn’t load since safe mode loads minimal drivers.

At work, if I spend more than an hour on it, I reformat and reinstall; I’m wasting my time and my employer’s money.

The idea upthread to boot Linux from a CD and save your files is excellent advice.

---

<div class="post-metadata">

### Author: ![TomS](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@TomS](https://boards.straightdope.com/u/TomS)
#### Post date: [October 7, 2011, 5:19am UTC](https://boards.straightdope.com/t/a-strange-virus/598827/6 "2011-10-07T05:19:05Z")

</div>

Does the proxy change when you are logged in as a non-admin?

Have you tried McAfee’s Stinger program (free)?  
[http://www.mcafee.com/us/downloads/free-tools/how-to-use-stinger.aspx](http://www.mcafee.com/us/downloads/free-tools/how-to-use-stinger.aspx)

How about Windows Defender (free)?  
[http://www.microsoft.com/download/en/details.aspx?id=17](http://www.microsoft.com/download/en/details.aspx?id=17)

Are any files infected or programs acting strange, other than IE?..

---

<div class="post-metadata">

### Author: ![Terr](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Terr](https://boards.straightdope.com/u/Terr)
#### Post date: [October 7, 2011, 5:21am UTC](https://boards.straightdope.com/t/a-strange-virus/598827/7 "2011-10-07T05:21:43Z")

</div>

> [@TomS](#):
>
> Does the proxy change when you are logged in as a non-admin?
> 
> Have you tried McAfee’s Stinger program (free)?  
> [Download and Install our Award Winning Products | McAfee](http://www.mcafee.com/us/downloads/free-tools/how-to-use-stinger.aspx)
> 
> How about Windows Defender (free)?  
> [http://www.microsoft.com/download/en/details.aspx?id=17](http://www.microsoft.com/download/en/details.aspx?id=17)
> 
> Are any files infected or programs acting strange, other than IE?..

Didn’t run those two in particular but I ran a slew of various others. Nothing found. Nothing acts strange except this annoying setting of the proxy in IE. A couple of my google searches uncovered some people suspecting that some MS Office programs are doing this in some circumstances. Am trying to chase that down.

---

<div class="post-metadata">

### Author: ![Space\_Vegetable](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@Space\_Vegetable](https://boards.straightdope.com/u/Space_Vegetable)
#### Post date: [October 7, 2011, 10:23am UTC](https://boards.straightdope.com/t/a-strange-virus/598827/8 "2011-10-07T10:23:04Z")

</div>

You might try using Microsoft’s [Process Monitor](http://technet.microsoft.com/en-us/sysinternals/bb896645) utility. I think you can tell it to watch all registry accesses and tell you which program is writing to any particular registry entry.

---

<div class="post-metadata">

### Author: ![Jormungandr](https://avatars.discourse-cdn.com/v4/letter/j/a6a055/32.png) [@Jormungandr](https://boards.straightdope.com/u/Jormungandr)
#### Post date: [October 7, 2011, 1:35pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827/9 "2011-10-07T13:35:42Z")

</div>

Other programs you can try, if you haven’t, is [Super AntiSpyware](http://www.superantispyware.com/) and [Norton Power Eraser](http://us.norton.com/support/DIY/).

---

<div class="post-metadata">

### Author: ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)
#### Post date: [October 7, 2011, 1:50pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827/10 "2011-10-07T13:50:38Z")

</div>

> [@Nancy\_Parker](#):
>
> If running malware bytes is not helping in removing the virus, then you should format the pc completely. First take a complete backup of the data, and do the formatting. It would do the complete cleaning of the system. Sometimes doing the scanning also will not remove the virus, if some software gets corrupted.

Ridiculous. Malwarebytes is just one antivirus tool. If that doesn’t work, there’s always [SuperAntiSpyware](http://www.superantispyware.com/), to name just one tool. There’s also the option to update the antivirus and scan (the virus probably blocks updating), or scan using a rootkit tool.

I’ve been dealing with spyware on hundreds of computers for years. There has only been one case that I couldn’t fix things using the tools available – and that was only because the computer was designed so that WindowsPE could not access the hard drive.

---

<div class="post-metadata">

### Author: ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)
#### Post date: [October 7, 2011, 4:00pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827/11 "2011-10-07T16:00:03Z")

</div>

Just to clarify – is your proxy getting set to 12 **8**.0.0.1 or 12 **7**.0.0.1? If it’s 128.0.0.1 (as typed in your OP), that’s an IP address for [mail.ru](http://mail.ru), a Russian email, blog hosting, and social media provider. If your machine is trying to talk to [mail.ru](http://mail.ru), did you recently install any client software for any of their services? I don’t know where you are, so I don’t know if this is something you might have done, but maybe you’re using some kind of blog development package from them or something?

Best of luck.

---

<div class="post-metadata">

### Author: ![Terr](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@Terr](https://boards.straightdope.com/u/Terr)
#### Post date: [October 7, 2011, 4:08pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827/12 "2011-10-07T16:08:38Z")

</div>

> [@Bayard](#):
>
> Just to clarify – is your proxy getting set to 12 **8**.0.0.1 or 12 **7**.0.0.1? If it’s 128.0.0.1 (as typed in your OP), that’s an IP address for [mail.ru](http://mail.ru), a Russian email, blog hosting, and social media provider. If your machine is trying to talk to [mail.ru](http://mail.ru), did you recently install any client software for any of their services? I don’t know where you are, so I don’t know if this is something you might have done, but maybe you’re using some kind of blog development package from them or something?
> 
> Best of luck.

Oops typo. 127.0.0.1 - localhost.

---

<div class="post-metadata">

### Author: ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)
#### Post date: [October 7, 2011, 4:36pm UTC](https://boards.straightdope.com/t/a-strange-virus/598827/13 "2011-10-07T16:36:53Z")

</div>

> [@Terr](#):
>
> Oops typo. 127.0.0.1 - localhost.

Ah. I thought I was on to something.☹

For what it’s worth, I’m on the side of those who say that, in general, it’s best to rebuild a machine when you get malware on it. Anti-malware tools have to know about the malware in order to remove it. According to Symantec, 75% of malware in the wild today infects fewer than 50 machines. Such “micro-targeting” of malware means that anti-malware vendors never see a sample and therefore can’t provide protection against it. So, today, the majority of new malware goes undetected by ALL anti-malware tools.

When your anti-malware system finds some piece of malware, or your machine starts acting in a way that’s indicative of malware, it’s a very good bet that there is more on the machine that you do not detect and may never detect. I think that “cleaning” malware only gives you a false sense of security.
