0

Request: Kindly do not mark this question as a duplicate without reading the whole description. I know this sounds like any other malware-infection question, but I request you to please read the whole description first. After that, if you still think this is a duplicate, mark it so and provide a link to a similar, answered question where the answer has been accepted as the solution with adequate confirmation.

I have been struggling with a (possible) malware infection (possibly) to my system (an employer-provided laptop with licensed software only). As you can see in the image below (iFrame element and jScript name), I am getting these frequent pop-ups which keep bothering me every time I open a website. As always, the minute I try to close them (a close button appears when I hover my mouse over it), it opens up a new tab and takes me to suspicious websites. The one url that always appears before being redirected to a random malicious page is double-u double-u double-u dot tradeadexchange dot com.

Image for iFrame Element and jScript

Before I resorted to taking SU's help and reading Joel Coehoorn's answer here, I had scanned my employer-provided laptop with SpyHunter (free license) and Kaspersky Rootkit Removal Tool. I can't blindly follow Joel's suggested solutions without an unambiguous confirmation of the infection because I would have to submit it to my employer's lazy, good-for-nothing maintenance team who will assuredly take 2 weeks to do it while cutting corners and not being as thorough as Joel Coehoorn suggested. And during which I, a developer working in the IT dept, would be forced to use a substitute ancient with performance slower than Win98 on 64kb ROM.

Kaspersky Rootkit Removal tool found nothing whatsoever. On my personal laptop, I use a licensed copy of Kaspersky Internet Security, and it blocks these ads and shows me a Malicious URL blocked message every time I open a website. SpyHunter gave me the location of 3 cookie files that it identified as malware/spyware, which I promptly deleted. And, not so surprisingly, they keep popping up every now and then.

But I think the SpyHunter results are false-positives. Why? Because - and this is a curve-ball for me - I am getting these same pop-ups on other devices that use my home WiFi connection too, but which have never, ever, ever had a data-transfer with my laptop. Also, a friend of mine gets his internet connection from the same ISP, and he too is getting similar pop-ups. Now again, this does not rule out malware, his system too could have been compromised. Another important point, I don't get these ads when I connect to my office's WiFi connection. The office connection obviously has a host of professional firewalls and security measures implemented, but, and again, I don't think those measures are the reasons why I don't get the pop-ups on the office WiFi.

So, I would be very, very, very thankful if the community could help me out on this. I just need a concrete confirmation as to whether my system indeed is compromised or if it's my home router or the ISP itself. Also, is it possible that an infected system, when connected to an entirely new network, transmit sufficient details so as to compromise all systems on that network too, without the other systems doing anything whatsoever? Deep down I know this is possible, but not sure. Do clarify, please.

Meet K.
  • 101

0 Answers0