1. Home
  2. Kaspersky
  3. (long Q, But Please Answer!) This Can’t Be A Virus, Can It?

(long Q, But Please Answer!) This Can’t Be A Virus, Can It?

By admin Posted in: Kaspersky

It all started about a month ago. I went to Google, searched Grooveshark, and went to it. I played a song, paused it, left for about 5 min, and when I came back the tab that it was open in had changed to another site. Can’t remember what it was.
Grooveshark did that a couple times and I thought nothing of it. Then last week I searched the name of a character and went to it’s Wikia page, and abt 30 sec later I got redirected. Can’t remember to where.
And later last week I searched Google and clicked on a link to The Washington Post, switched to another tab, and when I looked at the tab again a few min later it had changed to a site called dleasy . net. I thought nothing.
I later decided to run a full scan of Avast!(found 1 thing), a full scan of MBAM(found nothing), and Combofix(Found a couple things). I also later ran Hitmanpro(Found nothing), Rkill(found nothing), along with Kaspersky’s TDSS(Google redirect virus) killer(Found nothing), and also Symantec’s TDSS killer(Found nothing). Hijackthis found nothing as well.
But then after the scans I searched Grooveshark, played a song, paused it, and a few min later I went to play the song and the tab switched to dleasy . net again.
After all the scans and the last problem I looked at my HOSTS file and Internet Explorer’s proxy and dns settings and found nothing wrong. And I also flushed my DNS with the CMD. I also looked at devmgmt.msc and didn’t find TDSS or anything else that was supposed to be there if I had TDSS. I also even ran CCleaner and delete everything from IE, Flash, Macromedia Flash, and Windows temp files.
Anyways, my Q is:Since I ran all of those scans, do you think I am ok?, as in virus free?. I was reading on here that you can prevent popups and unwanted sites appering by disabling 3rd party cookies. So that was the last thing I’ve done after all the scans and stuff above, and after the last problem I mentioned.
And besides, couldn’t the issue be with the ads on the sites?. Maybe my browser’s opening them or they’re opening themselves without a virus, spyware or malware?. And it also hasn’t even done it everytime I google’d something.
Also, please don’t suggest running another scan if you haven’t read what I’ve already done.
So, Am I ok?. Is my problem caused by something else, ie not a virus/Malware/Spyware?.
Thanks.

  1. Anonymous Says

    Go to IE…click on Page….scroll down to accelerators….then click Manage Accelerators….then click the Search Providers tab….anything on there that looks suspicious other than your search provider like Yahoo or Google….click on it…then delete.

  2. Yoki Guz Says

    same thing happened to my pc, one day it just suddenly stopped doing it i suggest keep going unless you need to reformat your pc

  3. Mike Says

    This has happened to me before, but with some other phishing website. I called my ISP and they came over and did it for me.
    You should try that.

  4. Y Says

    URL redirection is more or less the hallmark of a browser hijacker (a type of redirection virus). It’s extremely likely that these things are embedded inside some of the advertisements on Grooveshark, since that seems to be where your problems started both times. Even though you cleaned up the infection the first time, going back to the site just infected you again. I suggest that you run another scan with Avast and Kaspersky’s tool, since those are the ones that generated hits the first time around, just to make sure. While it’s possible that some of these redirections were one-time events triggered by other, unrelated scripts, I wouldn’t leave it to chance, since it can easily lead to more insidious malware infections.
    I would also recommend that you do something about active content in your browser. Prevent scripts, cookies, and ActiveX from running on sites that you don’t trust. Install a proxy server or other package that can direct you away from or block known bad domains. Reduce your attack surface, and you have less malware to worry about.

  5. PoliteFi Says

    My recommendation is to just not use GrooveShark anymore. it seems to have been the start of your problems. I would instead recommend using Spotify. It doesn’t sound like it is a virus to me.

  6. Jim Says

    - try to avoid sites with icky names.
    - avoid using IE
    - get http://www.siteadvisor.com
    - yes, it’s possible through meta tags or javascript or headers to redirect a page.
    - I have seen sites do stuff after you leave the site. I don’t like them, it’s a horrible practice, I think of it like malware. I will call it malvertising. it MAY install malware on your machine or it may not. (see 1st tip)

Leave a Reply

You must be logged in to post a comment.

More Interesting Things

©2011 Fave Soft, All rights reserved.