Redirecting to Directory Sites

quietman

New member
Local time
12:23 AM
Messages
23
Location
Wales, UK
I have an issue when browsing in Google. When selecting results, I often get redirected to Ask.com or a directory site.

Norton is running, I have cleared all browsing history but stll this problem persits. It seems there is some sort of malware running that redirects my IE pages which is not being picked up by my AV software.

What about re-installing ie8?

Any soltions?
 

My Computer My Computer

Computer Manufacturer/Model Number
Packard Bell
OS
Windows 7 64 Bit
CPU
Core 2 Quad Q8300
Memory
4gb
Hard Drives
640GB +500GB
Do you have multiple search providers?
 

My Computer My Computer

OS
Windows 7
CPU
i5-750
Motherboard
Asus
Memory
4GB DDR3 1600
Graphics Card(s)
GT220

My Computer My Computer

Computer Manufacturer/Model Number
Packard Bell
OS
Windows 7 64 Bit
CPU
Core 2 Quad Q8300
Memory
4gb
Hard Drives
640GB +500GB
I have an issue when browsing in Google. When selecting results, I often get redirected to Ask.com or a directory site.

Norton is running, I have cleared all browsing history but stll this problem persits. It seems there is some sort of malware running that redirects my IE pages which is not being picked up by my AV software.

What about re-installing ie8?

Any soltions?

And what does you list of search providers show? What is the priority order of the search engines?
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
I have an issue when browsing in Google. When selecting results, I often get redirected to Ask.com or a directory site.

Norton is running, I have cleared all browsing history but stll this problem persits. It seems there is some sort of malware running that redirects my IE pages which is not being picked up by my AV software.

What about re-installing ie8?

Any soltions?

And what does you list of search providers show? What is the priority order of the search engines?
Not sure what you mean?
When I search for let's say "synth vst" (i'm into music creation) i will get what I expect. Then I might choose the first result and soon as I click this I will not be directed to the site I wat but a ramdom site which looks like a directory provider or often ask.com being a common one.
 

My Computer My Computer

Computer Manufacturer/Model Number
Packard Bell
OS
Windows 7 64 Bit
CPU
Core 2 Quad Q8300
Memory
4gb
Hard Drives
640GB +500GB
Ah, by directory provider, you mean a bogus site that comes up when a site no longer exists? Like this? oembios.com
 

My Computer My Computer

OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
Ah, by directory provider, you mean a bogus site that comes up when a site no longer exists? Like this? oembios.com

Yes something like that. To be honest I close the site as soon as possible just in case...
 

My Computer My Computer

Computer Manufacturer/Model Number
Packard Bell
OS
Windows 7 64 Bit
CPU
Core 2 Quad Q8300
Memory
4gb
Hard Drives
640GB +500GB
That just means a site doesn't exist at that domain anymore. But it's fishy if this is happening a lot. Does it only come up for certain search terms or everything? And have you changed anything recently in your internet setup?
 

My Computer My Computer

OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
That just means a site doesn't exist at that domain anymore. But it's fishy if this is happening a lot. Does it only come up for certain search terms or everything? And have you changed anything recently in your internet setup?
Not that i'm aware of...

since the last post (trumpet....?) I have run a Norton scan and i found a few nasties. Why it didn't pick these up before I'm not sure? A few cookies were removed and a rar file which it reckoned was suspicious.

Unfortunately, I download lots of zip/rar files with vst synths etc on them then place them (the .dll's) into my DAW (Digital Audio Workstation).

So far I haven't had the re-occurence of redirection so maybe......
 

My Computer My Computer

Computer Manufacturer/Model Number
Packard Bell
OS
Windows 7 64 Bit
CPU
Core 2 Quad Q8300
Memory
4gb
Hard Drives
640GB +500GB
Yeah, it was probably a hijacker. These things work by injecting code into the LSP (Layered Service Provider):

A Layered Service Provider is a DLL that uses Winsock APIs to insert itself into the TCP/IP stack. Once in the stack, a Layered Service Provider can intercept and modify inbound and outbound Internet traffic
 

My Computer My Computer

OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
Yeah, it was probably a hijacker. These things work by injecting code into the LSP (Layered Service Provider):

A Layered Service Provider is a DLL that uses Winsock APIs to insert itself into the TCP/IP stack. Once in the stack, a Layered Service Provider can intercept and modify inbound and outbound Internet traffic

it's still happening... just had a redirect with an Oops! Link appears to be broken screen with the text "controller dsx null" inserted
 

My Computer My Computer

Computer Manufacturer/Model Number
Packard Bell
OS
Windows 7 64 Bit
CPU
Core 2 Quad Q8300
Memory
4gb
Hard Drives
640GB +500GB
Disconnect your internet and scan with Malwarebytes

It may be a persistent one, downloading more code from the internet. It also might be reinstalling itself from a location on your drive. Malwarbytes' should find it/them.
 

My Computer My Computer

OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
Back
Top