Author Topic: Lavasoft Support Forums Malware???  (Read 18355 times)

0 Members and 1 Guest are viewing this topic.

Sly_Toad

  • Guest
Lavasoft Support Forums Malware???
« on: February 19, 2014, 07:49:09 PM »
Hello... I'm having a little problem since monday. I don't know if my pc is infected or not. I presume it's not infected because the only problem I have is with one URL.
I'm using Firefox 27.0.1 and everytime I want to access www.lavasoftsupport.com for the first time, avast block's the connection and the web page is redirected to hxxp://url4short.info/c29e7461
I try to access www.lavasoftsupport.com again and voilá, it's working again. My Firefox deletes user history everytime it's close, so everytime I want to access lavasoftsupport.com for the first time, Avast blocks the connection, redirect's me to that url4short.info crap. And then, if access lavasoft again, it's working again. I've attached and image showing what avast is blocking. It's in Portuguese, because I'm portuguese. :P

I've reinstalled firefox, avast, run malwarebytes and avast, superantispyware, etc etc etc... my pc is clean... And the problem is only specific to www.lavasoftsupport.com and url's that have www.lavasoftsupport.com in them.

Also, I have another problem, this time related to Avast Online Security Add-on on Firefox. Since the v27.0.1 of FF came out, the Settings button (or definitions button... I don't know what's called in the english version) doesn't seem to work. I click on the avast icon on FF, I try to modify the settings, but it doesn't open the chrome\\ webpage anymore.
« Last Edit: February 19, 2014, 10:21:45 PM by Sly_Toad »

Offline Cast

  • Sr. Member
  • ****
  • Posts: 302
Re: Lavasoft Support Forums Malware???
« Reply #1 on: February 19, 2014, 08:22:13 PM »
It could be possible to have something redirecting you to that other link, I tried both links you gave other than the url4short one as I have no idea where it leads and it opened the support forum for lavasoft just fine.

Sly_Toad

  • Guest
Re: Lavasoft Support Forums Malware???
« Reply #2 on: February 19, 2014, 08:52:25 PM »
So, how do I solve this. I've already removed every add-on in FF, and this still happens. I've installed Chrome, it still happens... Has my pc been Hijacked?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Lavasoft Support Forums Malware???
« Reply #3 on: February 19, 2014, 09:36:42 PM »
follow the logs guide at top in viruses and worms forum section.... attach OTL diagnostic log, then a malware expert will take a look


Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5600
  • Spartan Warrior
Re: Lavasoft Support Forums Malware???
« Reply #4 on: February 19, 2014, 10:15:14 PM »
Hello... I'm having a little problem since monday. I don't know if my pc is infected or not. I presume it's not infected because the only problem I have is with one URL.
I'm using Firefox 27.0.1 and everytime I want to access www.lavasoftsupport.com for the first time, avast block's the connection and the web page is redirected to http://url4short.info/c29e7461
I try to access www.lavasoftsupport.com again and voilá, it's working again. My Firefox deletes user history everytime it's close, so everytime I want to access lavasoftsupport.com for the first time, Avast blocks the connection, redirect's me to that url4short.info crap. And then, if access lavasoft again, it's working again. I've attached and image showing what avast is blocking. It's in Portuguese, because I'm portuguese. :P

I've reinstalled firefox, avast, run malwarebytes and avast, superantispyware, etc etc etc... my pc is clean... And the problem is only specific to www.lavasoftsupport.com and url's that have www.lavasoftsupport.com in them.

Also, I have another problem, this time related to Avast Online Security Add-on on Firefox. Since the v27.0.1 of FF came out, the Settings button (or definitions button... I don't know what's called in the english version) doesn't seem to work. I click on the avast icon on FF, I try to modify the settings, but it doesn't open the chrome\\ webpage anymore.
Threat alert ceases because you've got the option set in FF to delete all cookies as well as user history?  Once you've tried the first time, the second attempt always gets you there?

Got the same alert from clicking your redirect link here, so please modify that link as thus:  hxxp://url4short.info/c29e7461  to prevent any issues with other users clicking the live link as it is set now.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Lavasoft Support Forums Malware???
« Reply #5 on: February 19, 2014, 10:23:46 PM »

Sly_Toad

  • Guest
Re: Lavasoft Support Forums Malware???
« Reply #6 on: February 19, 2014, 10:32:30 PM »
No. Threat alert prevents me from accessing the site www.lavasoftsupport.com on the first attempt, because I get redirected to the url4short crap. After this I can access the lavasoftsupport.com site whenever I want if I don't close firefox. I have my firefox to delete all cookies and user history upon exiting. If I restart Firefox and try to access lavasoftsupport.com, I get redirected again on the first attempt.

This doesn't happen with other sites. Also, I've taken the liberty of performing the steps posted here: http://malwaretips.com/blogs/remove-browser-redirect-virus/

but they failed to help me. As I said, my pc is clean according to the results.

Sly_Toad

  • Guest
Re: Lavasoft Support Forums Malware???
« Reply #7 on: February 19, 2014, 11:25:35 PM »
Actually it's affecting every browser in my pc. Chrome, IE, FF, Opera, etc etc etc... all of them are redirected. To be honest, I thought it could be google redirect virus, but it only seems to affect www.lavasoftsupport.com.
I've also installed a lot of freeware cleaners and antivirus, but none of them detect any infection. I also had spybot Immunize a long while ago, so I don't know if it has anything to do with this.

Googling for answers, theres seems to be at least one more felow with the same problem... so, i don't know what to do. Even OTL files are clean. (yes I can tell)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Lavasoft Support Forums Malware???
« Reply #8 on: February 19, 2014, 11:28:07 PM »
Quote
Even OTL files are clean. (yes I can tell)
why not let Essexboy see it?


Sly_Toad

  • Guest
Re: Lavasoft Support Forums Malware???
« Reply #9 on: February 19, 2014, 11:34:52 PM »
Yeah, I'll update them. Right now I'm running ad-aware in compatability mode to see if it detect's anything. I'll run a new OTL after that.

Sly_Toad

  • Guest
Re: Lavasoft Support Forums Malware???
« Reply #10 on: February 20, 2014, 12:04:13 AM »
Ok, i'm having trouble running OTL. It doesn't create and Extras.txt file.

Also, i've noticed something weird. If I write www.lavasoftsupport.com directly or I click it for exemple in one of my posts, I go directly to the site. No problems.
But if I google "lavasoft forums" and click on the first one on the list, I get redirected.

I must ask someone to verify if this also happens to them. Can someone google lavasoft forum and click on the first site on the list to see if it redirects? If so, the problem is not on my computer. This must be done after cleaning history and cookies and restarting Firefox, or Chrome, or IE...

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Lavasoft Support Forums Malware???
« Reply #11 on: February 20, 2014, 12:08:54 AM »
Quote
Ok, i'm having trouble running OTL. It doesn't create and Extras.txt file.
it is only created at first run, that log is not important and usually not needed, as the name say just extra computer tech info




Sly_Toad

  • Guest
Re: Lavasoft Support Forums Malware???
« Reply #12 on: February 20, 2014, 12:13:17 AM »
Ok, running OTL again.

Can you please verify what i asked? Close a clear your browser history and cookies (i know it's a pain), google lavasoft forum, and enter the first on the list. If I write on the url thingy on firefox, I don't get redirected. I only get redirected if i google it.


Offline Cast

  • Sr. Member
  • ****
  • Posts: 302
Re: Lavasoft Support Forums Malware???
« Reply #13 on: February 20, 2014, 06:05:21 AM »
Cleaned my browsing history/cookies, googled lavasoft support forum and clicked the first link and no redirection so must be something on your end.

Sly_Toad

  • Guest
Re: Lavasoft Support Forums Malware???
« Reply #14 on: February 20, 2014, 01:30:22 PM »
Hi and thanks for the answer.

I made an investigation of my own. I reinstalled windows last night and tested again with AVG installed this time around. I was not redirected. I reinstalled windows once again, and installed avast and got redirected. I was starting to think that the problem could be my router or maybe google itself.
 Then, a few hours ago I asked a friend of mine who works at a computer shop for his laptop which had Panda installed and tested again. Nothing happened. Then I installed Avast Portuguese Version and tested again, and voilá, it got redirected.

Keep in mind this was on a DIFFERENT LAPTOP, and connected to a DIFFERENT ISP (usb stick of another ISP). Then he connected to his WIFI, and still got redirected.. Then we tested on another pc connected to a Public Wifi connection, and it was still redirected

As I said all along, I know my pc is not infected. So something is happening here. Also, I'm using Windows 7 Home Premium and he his using Windows XP Sp3 and Windows Vista. All of them are Genuine, as they came pre-installed in the machines.

So what to do now?

Update:
Tested with Avira, Comodo and ZoneAlarm... working fine. Only avast is popping up security warnings and showing me the url4short thing. Also the lavasoftsupport page seems to be opening fine for half a second before redirection. Sometimes it shows the full page, and avast pops-up and it gets redirected.
« Last Edit: February 20, 2014, 01:39:58 PM by Sly_Toad »