I appear to have a virus that I just can’t get rid of.
Behavior: I work out of home, and use VPN on a Windows 10 machine. I set my Internet Options to ‘Use Automatic Configuration Script’ of http://wpad/wpad.dat. I connect to VPN, and can get access to sites both intranet and internet. However, at some random point in time, internet access stops. I can no longer get to google, etc. When I look at my internet options, ‘Use Automatic Configuration Script’ is unchecked, and the value is empty. I can still get to all sites within my company's intranet, but I cannot get to the public internet. I can always conenct and disconnect to VPN fine. Once connected to VPN, everything will work fine for some period of time, typically 10 seconds to 3-5 minutes. It is random, and I can't find anything to force the issue.
I have run Malwarebytes, and registry issues were found relating to proxy.
I clean from within Malwarebytes. I run another scan with Malwarebytes and no problems found.
If I set my ‘Internet options’ back to ‘Automatic Configuration Script’, Malwarebytes says that I have Malware, specifically Hijack.AutoConfigURL.PrxySvrRST.
If I turn ‘Automatic Configuration Script’ off, no threats are found. I am trying to find out if I have a Virus or not, is MalWarebytes giving a false positive, and if so, what is randomly turning off my ‘Automatic Configuration Script’.
I have also used:
Zemana
Hitman Pro
Spybot Search and Destroy
adsCleaner
I have deleted any thing from programs listing that was questionable. (Drivers update program and PDF split/merge program, both freeware).
I have attached the Farbar files and Malwarebytes log
Any help appreciated.
Addition.txt
FRST.txt
Malwarebytes_log.txt