OS: Windows Vista.
Browser: Chrome.
User’s ISP and email service: Comcast.
Summary: User sees a prompt for a proxy server when she tries to view her Comcast Web mail in her Chrome browser. I suspect foul play by one or more potentially unwanted programs, or PUPs. The culprits I know about so far: Astromenda, “PC Speed Clean,” and “Speed Boost.”
A close friend who lives three states away often asks for my help with computer problems. She’s a very senior citizen, but she’s quite comfortable using her Windows Vista machine. She also uses Facebook, which seems to be the source of some of her computer woes. Recently she complained of difficulty getting into her email. By phone, we explored her installed programs in Control Panel. We found at least four PUPs that had installed themselves on the same recent date. The date and time group of installation coincided with when she’d tried to watch a video she’d found on Facebook.
My friend tried on her own (without success) to uninstall one of the PUPs–something called Astromenda, which had hijacked her browser’s home page. I linked her up with AdwCleaner, which seems to have removed Astromenda. However, she reports that the proxy server prompts persist. It’s unfortunate that my own eyes can’t see what’s going on. The best I can do is ask questions and listen to what my friend tells me. I’ve concluded there’s mischief afoot with this proxy server stuff, and that we can probably trace the mischief back to one of the PUPs. I know there’s nothing wrong with a proxy server, but I don’t think a home PC user would ordinarily use a proxy server to view their email.
I’m looking for some expert advice. Are these proxy server prompts a clue to something malicious? If yes, what’s the threat level and how best to remove the threat?