Member Avatar for Member #393757

Hi all

I've just spent the last week tearing my hair out with a terrible rogue dialler, browser hijack and virus. And, against my will, sending out thousands of emails along the lines of No More Teeny Man in Locker Room! and Discount Ci%lis.

Finally I solved it all in one morning, by getting Spybot into the computer via a pen drive. It immediately detected several registry entries redirecting sites such as this one to 127.0.0.1 (as well as finding the diallers and a Firewall Bypass script.

I wonder why AVG, Lavasoft and Comodo didn't detect these, even when booting in safe mode?

Cliff

Dani AI

Generated

Brief explanation and practical checks

What tripped the scanners in 2008 (and still can today) is that a lot of “redirect” tricks are not a single malicious file with a clear signature — they are small, legitimate-looking changes to the system that give malware persistence or change networking locally. Signature-based engines often miss those until a pattern is added, and modern detections increasingly rely on behavior/telemetry rather than just file signatures. That’s why saw something Spybot flagged even when AVG/Lavasoft/Comodo did not: the infection used local configuration/persistence rather than a single obviously-malicious binary. (See modern AV behavior monitoring practices.) Behavior monitoring in Defender. (learn.microsoft.com)

Where to look (common hiding places)
Check several places that malware uses for redirects or persistence: the hosts file, Internet/WinHTTP proxy entries stored in the registry, browser add‑ons and SearchScopes, Startup/Run and RunOnce keys, AppInit_DLLs and Winsock/LSP entries. These are standard autostart or networking configuration locations — tools that list every autostart spot (including BHOs, AppInit, LSPs and Run keys) are especially useful. [Autoruns documents those locations]; proxy settings live under the Internet Settings registry key; the hosts file is in %WinDir%\System32\drivers\etc. (learn.microsoft.com)

Immediate, safe steps to inspect and clean

  1. Boot from a clean medium or use another account to avoid active hooks.
  2. Inspect the hosts file and reset if needed.
  3. Run a trusted autostart inspector to review Run keys, BHOs, AppInit entries and LSPs.
  4. Query Winsock providers and, if broken or malicious, reset the catalog.
  5. Look for ProxyEnable/ProxyServer under HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings and remove unwanted values. Do these checks before deleting things; back up the registry and hosts file first. Useful references: [Autoruns] and the Windows netsh winsock commands. (learn.microsoft.com)

Notes and caveats
Safe Mode won’t always stop persistence (Run/RunOnce entries are ignored by default in Safe Mode unless specifically set to run there), so not seeing the malware in Safe Mode doesn’t prove it’s gone. If manual cleanup is uncomfortable, offline scanning or a clean OS image is the safest recovery. ’s point about “no single tool finds everything” is correct; combine careful inspection (hosts, proxy, Run keys, LSPs) with appropriate removal or a clean restore. (learn.microsoft.com)

Recommended Answers

All 3 Replies

There is no one program which will detect everything. Sorry that you had this happen, however, depends on what the exact problem was, when and how it came onto the computer AND if your particular programs were the very latest versions and had all ready had updates which would have detected whatever it was. If it was something brand new then many times some perfectly good programs won't detect it until the techs at that particular place come up with the update to the program so that the new threat can be detected and stopped and removed. Can't say absolutely why yours didn't detect and remove because we don't know what it was. There are a several very nasty items out there now and some programs just don't catch them yet. There are also some nasties which just aren't detected by your standard anti-virus program, they need a special program to do so.
When you say Lavasoft, I have to assume you mean some version of AdAware...the most recent versions, at least I don't feel are as thorough as previous versions.
Spybot is and has been a very good program to keep on the computer. Don't use the TeaTimer portion however as at times it can interfere with removals. Another very good program in use now is Malwarebytes'-Anti-Malware. It too is highly recommended and WILL remove many of the latest nasty items out there.
There really is not one program which will catch everything, there probably is no way to create one, it would be too large for most computers to run and too cumbersome too. This is why several programs are always recommended...ONE anti-virus, ONE firewall, and several anti-spy/malware programs. Keep your temp files small, keep your Java updated, use good security settings in your browsers all will help. Another great program is SpywareBlaster. It will

Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
Block spyware/tracking cookies in Internet Explorer and Mozilla Firefox.
Restrict the actions of potentially unwanted sites in Internet Explorer.

It is FREE and best of all it DOES NOT run in the background consuming valuable resources. Add this to your protection and be sure to also use it's Restricted Sites section. You will be very pleased with it, I am sure.
Judy

Member Avatar for Member #393757

That's really helpful Judy, thank you. I've made the tweaks to Spybot you suggest, reduced the size of the temp folder and I'll have a look at the other programs you suggested. I just never want to have a week like last week. The only good thing to come out of it was learning a bit about the registry and so on...but I'd rather have found an easier way!

Many thanks again
Cliff

The other programs are really must haves today, at least I believe.
Good Surfing! Don't hesitate to come back if you ever need help, somebody is always here ready to jump in.
Judy

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.