Hi DaniWeb,

You've been great to me in the past, and now I'm turning back to you to help out with an odd issue I've just encountered.

Recently I moved into a new place shared with several other people. When connecting to the internet from this new location, I noticed that occasional clicks within the browser (I am using chrome, but I don't think that's relevant) would lead me to a new tab opening - always to some half-legit-looking site with lifestyle news articles or videos or whatnot. I notice 'google analytics' often appearing in the address bar before the redirect finishes and I arrive at the target page. Occasionally I land on a page with a captcha to verify where I came from. I first noticed this when I clicked on various links and both the target page, and the ad page opened - but this also seems to happen sometimes when I click anywhere within the page, not just a hyperlink.

I've looked this up *some*, and it seems to me this is not an issue with my laptop. I've had a friend over who had the same thing happen on her Macbook. That - combined with the result of my little research which seems to indicate this could be an issue with a poorly set-up router - makes me fairly confident that my laptop is OK, or at the very least, not the source of the problem. I'm skipping the HJT logs and such because I'm not asking for help cleaning something off my laptop, but rather for help dealing with this router issue.

So, some questions:

1) How worried should I be?
2) What's going on exactly? and how can I stop it?

Hope you guys can help! Again, I know I'm not following protocol this time but the problem is a little unlike most posted in this forum (i.e, specific to a computer). But this was the only virus/spyware/nasty stuff forum here I found, and this most certainly falls under 'nasty stuff.'

Thanks!

Dani AI

Generated

Given ’s note that a second laptop showed the same behaviour and ’s reminder that local logs are essential when a device infection is suspected, the most useful early assumption is that this is a network-level problem (router/ISP/middlebox) rather than a single compromised browser. The immediate aim is to prove whether the redirects follow the Wi‑Fi or follow individual devices, then secure the network gateway.

Common triage steps:

  1. Confirm scope — connect one device to a different network (mobile hotspot or a neighbour’s Wi‑Fi). If redirects stop on the alternate network but continue on the shared Wi‑Fi, the issue is almost certainly at the router/ISP level.
  2. Test multiple clients on the same Wi‑Fi (phone, tablet, guest laptop). Consistent behaviour across devices reinforces a network problem.
  3. Inspect client DNS/proxy settings and capture the resolution path. Useful commands (examples):
ipconfig /all
nslookup <suspicious-domain>
tracert <suspicious-domain>
  1. Check the browser in a clean state (incognito with extensions disabled) to rule out a malicious extension as a secondary cause.

Router/network hardening and remediation:

  • Log into the router admin UI and review WAN/DNS settings, DHCP DNS push, and any unknown admin accounts or scheduled tasks. Disable remote/remote‑web management.
  • Change the router admin password away from factory defaults, update official firmware (download from the vendor site), or perform a factory reset if settings look altered. After reset, immediately set a strong admin password and WPA2/WPA3 passphrase.
  • Consider setting router DNS to trusted resolvers (for example, 8.8.8.8 or 1.1.1.1) or enable DNS over HTTPS/DoT on clients. If the router shows evidence of deep compromise, replacement is the safest option.

If the router is ISP‑supplied or shared with others, escalate to the ISP or building admin. For detailed device‑level followup, collect browser console logs, packet captures, and system logs as suggested before proceeding with forensic cleanup.

Recommended Answers

All 2 Replies

Here's an update. The URL redirects seem to be running from google-analytics.com.

If you really want assistance then the only way we can even begin to offer suggestions is that you follow all the steps on the Read Me sticky and then come back and copy/paste all logs from the steps given. Then we can begin to offer assistance.
http://www.daniweb.com/hardware-and-software/microsoft-windows/viruses-spyware-and-other-nasties/threads/134865

The URL redirects seem to be running from google-analytics.com.
This doesn't appear to be a legitimate site by the way.

Don't be fooled into thinking that the problem is not on your laptop so you are safe, you most definitely are NOT safe. If you have nothing on the laptop now, you soon will unless you start to take some real steps.

There may be a raging fire outside your door but you wouldn't assume you are safe because you are inside, eventually that fire will cause your home to start burning and you won't be safe inside. Right now the laptop "might be" the locked door, but sooner or later the door is going to open, it all ready is "ajar" if you are getting redirects.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.