Browser keeps redirecting in IE8

skuzzzzy

New member
Local time
6:45 PM
Messages
26
Hello im working on a clients computer.

After coming back from china, his IE company homepage keeps redirecting him to, bjdnserror2.wo.com.cn.
IE still shows his homepage as the correct company homepage but it gets auto redirected.

Ive done the following,
cleared cookies, history
deleted IE settings restore stock IE settings
ran malwarebytes
winsock reset and flushed dns
made sure no addons for IE were enabled.

If he opens a fav shortcut for the company page it loads without issue, and there is no issues with chrome.

Anything else I could try?
 

My Computer My Computer

OS
windows 7 64bit
CPU
i7 860
Motherboard
msi p55 gd80
Memory
g.skill eco series 4gb
Graphics Card(s)
4850
Sound Card
onboard
Monitor(s) Displays
asus 26"
Hard Drives
1tb samsung spinpoint
2x 1.5tb wd greens
PSU
corsair hx850
Case
cooler master sniper
Cooling
silver arrow
In addition to malwarebytes, run your anti virus.
Use the online scanner, eset.
Good Luck
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
Ive ran symantic virus scan aswell, forced group policy.

This is happening foir everyone in the group who recently went to china on business.
 

My Computer My Computer

OS
windows 7 64bit
CPU
i7 860
Motherboard
msi p55 gd80
Memory
g.skill eco series 4gb
Graphics Card(s)
4850
Sound Card
onboard
Monitor(s) Displays
asus 26"
Hard Drives
1tb samsung spinpoint
2x 1.5tb wd greens
PSU
corsair hx850
Case
cooler master sniper
Cooling
silver arrow

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
I really dont have much time to site and run a bunch more scans onto his computer because he is very busy,
Ive logged into my account and theres no issue with my internet explorer redirecting, so seems to only be connected to his prifile.

My supervisor says it then has to be in HKEY_CURRENT_USER in the registry, then I went to software/microsoft/internet explorer
and I believe main controls the homepage but all of the office computers show "http://go.microsoft.com/fwlink/?Linkid=69157" which is not what our homepages are.

Im fixing to just reformat his computer, was just checking to see if you knew of anything I could check in the registry
 

My Computer My Computer

OS
windows 7 64bit
CPU
i7 860
Motherboard
msi p55 gd80
Memory
g.skill eco series 4gb
Graphics Card(s)
4850
Sound Card
onboard
Monitor(s) Displays
asus 26"
Hard Drives
1tb samsung spinpoint
2x 1.5tb wd greens
PSU
corsair hx850
Case
cooler master sniper
Cooling
silver arrow
You reset IE: deleted IE settings restore stock IE settings - I think "http://go.microsoft.com/fwlink/?Linkid=69157" is the default home page when you reset IE.

You can just set the home page to whatever the company standard is or you can spend time reformatting and reinstalling.

If you don't want to check for a Trojan - that's your call. You take the full responsibility if there is a virus and it causes more issues on all of those machines. This is happening for everyone in the group who recently went to china on business.

edit: Wait a minute... are your borrowers IE 8?
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
As mentioned in my post, I thought that it was a virus and others agree. Let me add before doing anything try Adwcleaner, as suggested. It has helped many. As mentioned this could be a Trojan with many potential problems, in addition to the home page. Be sure to do a format and clean install, if you desire to reinstall to solve the problem.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
You reset IE: deleted IE settings restore stock IE settings - I think "http://go.microsoft.com/fwlink/?Linkid=69157" is the default home page when you reset IE.

You can just set the home page to whatever the company standard is or you can spend time reformatting and reinstalling.

If you don't want to check for a Trojan - that's your call. You take the full responsibility if there is a virus and it causes more issues on all of those machines. This is happening for everyone in the group who recently went to china on business.

edit: Wait a minute... are your borrowers IE 8?

Yes they are using IE8, the homepage is set to the proper company homepage and does go there before being redirected.
But in the registry it says the homepage is set to microsoft, which it is not.

Its not that I dont want to run another virus application, its time does not allow for me to do so since the user is busy, my boss thinks its a simple fix - something related to the user going to china and china messing with dns? to block sites, but I would had thought flush dns would had taking care of that.

Im in the process of building a machine for that user now, was just hoping to have a few things to look for in the registry for when the others get back from china since they are experiencing the same thing.

And thanks for the suggestions for the anti malware, its just these people dont have the time for me to work on thier machine unless its a simple quick fix.
 

My Computer My Computer

OS
windows 7 64bit
CPU
i7 860
Motherboard
msi p55 gd80
Memory
g.skill eco series 4gb
Graphics Card(s)
4850
Sound Card
onboard
Monitor(s) Displays
asus 26"
Hard Drives
1tb samsung spinpoint
2x 1.5tb wd greens
PSU
corsair hx850
Case
cooler master sniper
Cooling
silver arrow
Understood - you're at the mercy of the user and your supervisor.

A clean install will certainly fix all but hardware ailments, as long as you clean the disk (some malware hides in the root sectors). The thing is you don't know if there is malware or not ... so the clean install is probably your best bet.

Good luck,

Bill
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
This is obviously too late to help the original poster, but in a case like this, something simple to check is the Internet Explorer shortcut. The IE command line accepts a URL that is displayed on open and overrides the homepage stored in the registry. Thus, even a registry search won't find the unwanted URL. Some malware cleaners will detect this and fix it, but most that we have tested do not fix it in all infected user profiles. This might even affect the IE shortcut listed on the System Tools menu. To fix this issue, just edit each IE shortcut's Properties and remove the unwanted URL from the Target command line.
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 7 Pro 64-bit
Back
Top