Forum Moderators: open

Message Too Old, No Replies

IE goes to different site?

Driving me nuts . . .

         

rocknbil

11:18 pm on Nov 16, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Win XP
IE v. 6.0.2900.2180 SP 2, all updates to date
Set NOT to search from address bar
Grisoft AVG, updated daily
Spybot S & D, scanned weekly
AdAware, scanned weekly
Browsing habits are work only, very few downloads, no "free" sites or bad neighborhoods. That I know of . . .

When I go to my wife's site, it goes to some completely unrelated site. I've never seen anything like it. It comes and goes sporadically, usually rebooting IE brings it back.

Does not happen in any other browser so it's just IE. Effect is the same with or without www and [....]

The site that it goes to has NO keywords in the pages remotely relating to her-site.com and does not even turn up on any of the search engines when I hunt for her-site.com.

Been a long time since I ran hijackthis, off to do that now, anyone got any ideas? :-(

rocknbil

12:37 am on Nov 17, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Ran hijackThis, did find one nameserver that wasn't my ISP, nuked it. Still open to ideas . . .

jdMorgan

12:43 am on Nov 17, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Start->Run Cmd->OK ipconfig /flushdns

Check your Hosts file, too.

Disable any unrecognized "add-ons" in IE to see if that changes anything.

Use the BHO tool in Spybot S&D to check for other unaccounted-for "browser helpers".

Jim

penders

1:19 am on Nov 17, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Clear your browser cache?! (Well hey, nobody has mentioned it already)

I have a site that a friend said he could not access - would somehow be directed to the old site, different name, different server?! I did not witness this myself, and browsing habits could have been questionable, but anyway, sometime later he did a system restore to a point soon after he bought the machine(!) and SHAZAM, the correct site could now be accessed! (Well, that's what I was told!) Sorry, not very helpful really!

rocknbil

2:32 am on Nov 17, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



No, this is all good! But I did flush the cache, deleted cookies, reloaded and the errant site came up a second time. It hasn't since I deleted the HijackThis log entry:

O17 - HKLM\System\CCS\Services\Tcpip\..\{39918C5B-01CB-4B1C-82BB-C86311571561}: NameServer = [IP of my ISP's name server],[IP of some other name server]

Where "some other name server", coincidentally, is one that has been trying to abuse one of my customer's forms. Trying in that no email is being sent, but they have repetitively turned up in my logs. Coincidence, I think, there's no way they could connect us.

The problem is it doesn't do it reliably, once every couple weeks. I only open IE these days to check site compatibility, so it's not like it's browsed anywhere.

Hosts file is blank (all comments) and I did run the flushdns switch, thank you!

encyclo

2:49 am on Nov 17, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



You should also check your network settings: I don't have Windows here so I can't give the exact route, but somewhere in Network Connections there is a properties setting for TCP/IP called "obtain DNS server address automatically". Unless your ISP says otherwise, then this option should be selected.

You most likely have a malware infection of some sort, one which is being used for hijacking the machine's DNS lookups.

You say that you have all IE updates, do you also have the latest versions for your plugins? Get the latest Flash plugin, QuickTime, and in particular get the latest Java runtime environment from Sun - earlier Java installations had big security holes:

[java.sun.com...]

This won't fix your immediate problem, but it will close any potential remaining known holes in your system.

floriniri

6:28 am on Nov 18, 2006 (gmt 0)

10+ Year Member



I agree with penders here. My site was also redirecting to another, totally s...t site, totally unrelated.
I asked my host and they run a check on the domain, it wasn't hacked or anything. So it was a browser problem.
I installed firefox and used it a while, then I restored windows to an earlier date and it got fixed.
But that doesn't help much, right? Btw, I no longer use sys restore, I've disabled it (lost some datas sometime after restoring and it was enough).