Win32.Simda - Some domains blocked, forced compatibility mode?

Dunge

New member
Local time
10:50 AM
Messages
2
Got a virus last Friday, Windows Defender identified as Win32.Simda. MalwareBytes cleaned most of it.

Windows Defender, MalwareBytes (anti-malware & anti-rookit), AdwCleaner, Hitman Pro, ESET Smart Security, Kaspersky Virus Removal Tool, Kaspersky TDSSKiller, RogueKiller, Microsoft Safety Scanner, RKill... nothing find any infection.

Safe mode don't change anything. Network works fine when booting on another HD/OS on the same computer.

The only symptoms I have are:
-Many domains blocked, in browser AND application. Anti-virus won't connect to databases, Windows update won't work, etc. List so far include: microsoft.com, eset.com, bleepingcomputer.com, virustotal.com, steampowered.com, gamespot.com, facebook.com, cnet.com, ign.com, probably tons of others. Facebook and Steam seems to connect, but it block when trying to connect to akamaihd.net for additional content. But other sites like youtube and reddit works just fine.

-If I create a new Windows user, it configure IE network setting to use a proxy (localhost:64955) and it wouldn't connect to any site, presumably because the virus service got cleaned out. Removing the proxy setting, I get the same domain blocked symptoms.

ESET Simda Cleaner Utility tells me I'm using an unsupported version of Windows.
Is there some registry key forcing compatibility mode?

GMER log attached, it found some things (that FRST/FSS/SystemLook wouldn't find).
 

Attachments

My Computer My Computer

At a glance

Win8.1 x64
Computer type
PC/Desktop
OS
Win8.1 x64
This is a follow up in case anyone else get this:

The ESET support guys found the problem after trying many many thing. By deleting the Windows ipsec policy branch under regedit and rebooted, it finally fixed it. They told me it's a known threat that usually only infect Russian PCs (I'm in Canada).
 

My Computer My Computer

At a glance

Win8.1 x64
Computer type
PC/Desktop
OS
Win8.1 x64
Back
Top