Spyware or ELR?

Starting about a week ago I’ll get randomly redirected to an offsite page while looking at recipes. It only happens on recipe pages. This time I just got redirected to a page @ http://www.ibtimes.co.uk/ I’m not suggesting you go there or anything, just posting details. Previously I’ve been redirected to some food website and another one was a fake Microsoft site saying I have a virus.

First I assumed it was spyware, but none of my apps are detecting anything (spybot/malwarebytes). I also use ESET for AV, and that doesn’t find anything either. Before I dig deeper with more spyware tools, I wanted to know if anyone else is having this problem.

2 Likes

I’ve not experienced this, but I’m guessing @daath would be able to say one way or the other if this was some sort of advertising thing or not.

I’m not sure if you’re using any add ons or extensions, but those can sometimes do weird stuff. I had one that I used for downloading all of a professor’s slides from class (he posted them as a bunch of jpeg images on a webpage) and it wound up changing every instance of the word “shopping” on every webpage I visited into really obnoxious ad links.

1 Like

If none of those are detecting anything, then I’d feel pretty safe, and this is a lot of what I do for a living. You could try SuperAntiSpyware, my other go-to anti-malware software, if you’re willing. But if it is spyware that’s not detected by that group, then you may be in trouble. And by “trouble” I’d actually suspect that you’d be in a world of annoyance.

Can you try another browser? And/or the same browser but with all add-ons and extension disabled? Google for “safe mode” for your browser.

As a last bit of paranoia, try heading over to bleepingcomputer.com and run a HiJackThis report and anything else they recommend.

Do you know of a specific recipe that caused the issue? And does it happen every time on that recipe page?

2 Likes

An ad blocker helps me.

1 Like

Thanks for the replies. I do have a few extensions installed that are not necessary so I’ll get rid of those. I haven’t tried another browser or Chrome safe mode, but I’ll try that and Firefox. Doesn’t seem to be specific to any one recipe. It’s happened on at least 3 of mine and other random ones, but it’s not consistent other than recipe pages in general.

Speaking of Adblock, I have it disabled on ELR because it’s always blocked the percentages/amounts of recipe flavorings, but that was long time ago when I did that so maybe it’ll work better now.

I’ll check out the tools @Scottes777 listed. I’ve been out of the loop as far as those tools go since I started using Malwarebytes because it’s usually worked out well for me. Thanks for all your suggestions guys… and girls.

1 Like

Malwarebytes always works for me to find them little pesky re-directors,
You could also run Comodo cleaning essentials, I use that a lot in my line of work as an IT technician, that and malewarebytes together to remove 99% of whatever.

It does sound like a redirect (browser hijacker)
here is the link to it, just choose either 64 bit or 32 bit

https://www.comodo.com/business-security/network-protection/cleaning_essentials.php

2 Likes

That’s an absolutely necessary add-on, IMHO. That and NoScript, and Ghostery.

Be warned that they can make a LOT of sites fail to work, so you often have to whitelist known-good sites, but they can save your butt.

3 Likes

I will never go back to not using one!

1 Like

A few days ago there appeared to have been a rogue ad on one of the networks. I tried to identify the source but couldn’t get it to repeat, so I assume that whoever was responsible for the origin network caught it and eliminated it…

If you stumble across anything suspicious, I’d love to hear it. The ad people I use are usually good at spotting and banning the bad ones…

EDIT: It sounds like you met one - albeit a milder one; mine redirected me through a complex path through to some porn and dating sites…

3 Likes

I hit the fake you have a virus one but that was a day or two ago and my computer is clean of course… its been fine since

1 Like

You can also run Hijack This. It has worked for me in the past to help my numb nuts brother get his mojo back. If you have a browser hijack, get rid of it! I swear some of them can weasel their way deep into your OS if left unhindered.

2 Likes

Just so all the new folks are aware, I am a volunteer, so I’m not saying this cuz it’ll benefit me in any way. Because I know he’s too nice to say anything ( :wink: ), keep in mind that ELR is ad supported and using adblock prevents Daath from receiving any revenue from the site. If you don’t want ads, you might consider a donation instead; $10+ and a request to him and he’ll remove the ads on your account. The donate link is at the very bottom of your “My Page.” :smiley:

15 Likes

Well said JoJo, that’s exactly what I did

6 Likes

True. And as much as we all spend on vape supplies that’s a small price to pay to help support the family.

I do want to say though that ads should not initiate a browser redirect. If they do they’re bad ads IMO.

3 Likes

You beat me I was guna say Donate and you won’t ever see the ads again unless you log out and browse :wink:

4 Likes

The problem I have is on my phone I have a limited data plan. Ads eat me alive on data…on the computer at home it doesnt matter.

2 Likes

If it happens again is there some kind of browser log I should send you, or maybe just the URL? I’m using Chrome but also have the site open in Firefox. If any info would help lemme know and I’ll try to get it.

1 Like

I’ve also been seeing them for the past week or so. Not on my end, running malwarebytes and BD. Very suspicious. Google chrome with no hidden extensions.

1 Like

Fully agree. Wouldn’t run a browser without them in this day and age! For multiple reasons.

1 Like

Yeah, the biggest threat about HiJackers…is not what they do, but where they lead you to going.

They simply conduct the traffic TO the payload sites. It’s where you land that the real threats usually exist! The sooner you fix the hijack, the safer your outcome (typically)!

2 Likes