Can’t access popular sites ‒ redirecting to scam ones instead

NecroSkeith

Honorable
Apr 23, 2013
27
0
10,530
It all started last few days ago,

I tried to type into my address bar a social network that a lot of people use often which is facebook. But the problem was that I could not access that particular site, and instead, it redirected me to a scam site I believe. And the same happens when I try to access google and/or youtube. (http://puu.sh/7aw80 / http://puu.sh/7aw5y)

The site appeared to show me a box saying that there is a problem, it said to update my flash player by installing some file. After staring at the site for a few moments I noticed that my address bar is still the same, it didn’t change to show me this flash player pro address. It was something that really confused me, also notice that there is unistall instead of uninstall at the bottom. A typo that you wouldn’t expect to see.

Anyway, after googling around I seen some users complain about the site being spam or whatnot, something that wouldn’t be wise to install even though the site didn’t register any threats in the web-address scans.

I simply clicked “Remind me later” and there, I automatically downloaded a file. I got even more confused. The file, it was tiny, like a few kbs size and named setup.exe (See image for details: http://puu.sh/7awgK) Unfortunately, even after I tried to look up what this Apache software was, I couldn’t tell what was it.

I tried to use different browsers such as Mozilla Firefox, IE, and CoolNovo etc. Yet I always got the same page asking me to download that file, or show me these pages. (http://puu.sh/7cyKg and http://puu.sh/7axD6)

I do have my clock set, I tried looking up SSL stuff in my browsers and I even tried to reformat by completely wiping out my system drive, but that was all in vain. What I noticed after that is that every device that is from the same network showed the same thing. Although connecting from a different network worked just fine.

I’m desperately looking for anything I could try, if you happen to have any idea on this I would be really grateful to you.

Also, I still haven’t tried to reset my router, it’s a TP-Link one.

If you need any more info, I would be glad to tell you more if I can.
 
Solution
Yup, someone's trying to MITM (man in the middle) you. This could be either by being somewhere between you and the global internet, or by using a fake DNS server to redirect you to the wrong server.

Follow the steps I linked above to change your DNS server.

NecroSkeith

Honorable
Apr 23, 2013
27
0
10,530
I did a full scan using MSE (This is what it detected: http://puu.sh/7b4JG)
Eventually removed them but the problem is still.

Should I try this malwarebytes you speak of?
 

techguy55

Reputable
Mar 3, 2014
63
0
4,660
yes. you have win8keygens on a win7 OS. I use malwarebytes at home and work and I have seen more removals from it than most others.


or, the OS you are using is a cracked version.
 

NecroSkeith

Honorable
Apr 23, 2013
27
0
10,530
I don’t think the OS has anything to do with the problem, I know people who run cracked versions just fine with no problems.

Anyway, I will check that software right away.
 

NecroSkeith

Honorable
Apr 23, 2013
27
0
10,530


Just ran a full scan with KIS 2013 and I still get the page redirection.




Chrome usually uses HTTPS for secure connection most of the time, I tried it and the ISP settings, still no luck.