Apple Intelligence now features Image Playground, Genmoji, Writing Tools enhancements, seamless support for ChatGPT, and visual intelligence.

Apple Intelligence has also begun language expansion with localized English support for Australia, Canada, Ireland, New Zealand, South Africa, and the U.K. Learn more >

You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Websites being redirected to yandex.ru

I am having a problem as of yesterday. A lot of the websites I have been trying to visit have been redirected to yandex.ru. I am running Chrome on a 15" MacBook Pro with Lion. the sites that are being redirected are very random, but they consistently redirect. For example, MSN.com always loads fine, but trying to click on a link within msn.com from yardbarker.com redirects to yandex.ru.


It doesn't matter whether I access the sites through a search engine or directly on the google omnibox, the sites are always redirected before completely loaded. It is also consistent on other browsers (Safari and Firefox). I have cleared all caches, cookies, extensions, deleted extra search engines, etc, and I have tried using other DNS addresses provided by OpenDNS. None of those things worked.


I thought it might be a problem with my ISP. I am living in Jordan for work, so who knows what kind of potentially shady goings-on are happening, but I asked a friend using the same ISP and DNS addresses to check the sites I was having trouble with, and they loaded fine for him.


I have used ClamXav and MacScan 2, and no problems were reported. I reset my router to factory settings, and I am still having the same trouble. All of the devices we use on the local network are also being redirected. My wife's macbook, my iPhone, and our iPad are all being affected.


I am using a Wimax router through a 3.5G HSPA connection with an airport Extreme attached via ethernet to extend the signal. I tried to connect to the Wimax router directly and still had the same issue. I tried logging in as a guest, using Safari, and was redirected as well. Not sure what to do next.


Any counsel would be thoroughly appreciated.

MacBook Pro, Mac OS X (10.7.2)

Posted on Dec 16, 2011 2:39 AM

Reply
21 replies

Dec 21, 2011 2:15 PM in response to hanmol

Hello Guys,


I suffered over the last two and a half weeks from the same problem.


My Network Setup:

2 X Windows Laptops

1 X IPAD

1 X IPOD

Zain Router Connecting over HSPA GSM network

I tried everything

  • I ran scans using all descent Anti(malware/spyware/Virus) tools in hand.
  • I deleted all internet cache/history/cookies on all browsers.
  • I blocked the domain and sub-domains of (yandex.ru) in all browsers.
  • I tried changing DNS settings on the router, which is impossible on Zain router through HSPA setting.
  • I even upgraded the firmware and hard reset the router just to make sure the router is intact.


But nothing from the above sustained for more than couple of hours.


The Solution

The only thing which worked for me was the following:


Basically:

1) Delete all browsing history and cookies for all browsers.

2) Add a host entry “yandex.ru” pointing to the IP-Address “127.0.0.1” in your operating system’s “hosts” file. (make sure this is the only entry).

Detailed solution:

STEP1) Clear internet cache/history/cookies on all browsers, and temp folders. You can do it manually or you can use a utility, I used CCleaner v3.14, it works for PC and there is also a release for Mac.

You can find CCleaner from below link:

http://www.piriform.com/ccleaner


STEP2) Edit the “hosts” file on your OS and add host “yandex.ru” with value “127.0.0.1”


Windows users:

  • Browse to folder “C:\Windows\System32\drivers\etc\”
  • Open file “hosts” using notepad and add the following line at the end:

    127.0.0.1 yandex.ru


For More details on how to manage hosts file, visit the link http://accs-net.com/hosts/how_to_use_hosts.html

I attached an image capture of my “hosts” file.

User uploaded file



Mac OS X Users:


(you need the root password for below practice)


Add the following entry at the end of your “hosts” file

  • 127.0.0.1 Yandex.ru

For more details please read both below links carefully,

"Please acquire technical assistance if you are NOT sure of what you are doing."

http://decoding.wordpress.com/2009/04/06/how-to-edit-the-hosts-file-in-mac-os-x- leopard/

http://support.apple.com/kb/TA27291


My Opinion

Our Ignorant ISPS’ DNS servers "most probably" where hacked by a Russian geek who really caused us this headache.

Driving our browsers to redirect to the stupid Russian search engine.

The Media

Zain admitted “In a way” that they do have a problem and they are working on a "solution" and occasionally injected an "apology-like" html page within some Zain customer browses telling their customers that they (the customers) are infected with a malware and they need to delete the browsing history.

Zain referenced both below News about the case:

.

English version from Jordan Times: http://insurance-technology.tmcnet.com/news/2011/12/16/6000415.htm

Arabic version from (Khabberni News): http://www.khaberni.com/more.asp?ThisID=66214&ThisCat=1



I Hope this helps


Regards


Hani..

Dec 21, 2011 4:06 PM in response to kandelfire

THE ULTIMATE SOLUTION SO FAR
(for ones how have a Zain HSPA Wireless Routers)

Ok, my first solution would be fine for people who have a Machine running Windows or Mac OS X and have the experience and time to play around with core system settings.


That wouldn’t be so great for IPad, IPhone & IPod users since this needs JailBreaking and manipulating the system files inside IOS.


IF you have an HSPA Router, do the following:

  1. In your browser open http://192.168.1.1 and Logon to your to your router.
    Default username/password are admin/zain, unless previously changed.
  2. Select the “Security” tab from the menu. See Arrow (A) in below Figure.
  3. Select the “Internet Access Policy” tab from the menu. See Arrow (B) in below Figure.
  4. Enter the Policy Name in the text box, I named it “Deny Yandex”. See Point (1) in below Figure.
  5. Make sure “Status” is Enabled. Point (2) in below Figure.
  6. Set “Access Restriction” to Allow. Point (3) in below Figure.
  7. Make Sure “Schedule” is Checked on “Everyday” and “24 Hours” Point (4) in below Figure.
  8. Enter “yandex.ru” in “URL 1” to block it. Point (5) in below Figure.
  9. Scroll all the way down and click “Save Settings” button.
  10. Wait 15 seconds until settings are saved and page refreshes.

User uploaded file



P.S. DO NOT FORGET TO CLEAR HISTORY AND COOKIES ON ALL BROWSERS AND ALL DEVICES ON YOUR HOME NETWORK



Enjoy smooth browsing.


If you have successfully applied above steps in your router, then you wouldn’t need any modification on “hosts” file inside your operating systems since this will block all your network traffic to yandex.ru.



Kandelfire, tell me if this works for you since you have opened the discussion and you do have an HSPA router.


Regards


Hani.

Dec 16, 2011 3:48 AM in response to kandelfire

I have the same problem in Amman JO, traffic on all devices connected to the router are getting redirected to yandex.ru. My wireless broadband ISP which uses Wimax technology have told me that I need to clear history cache etc and clear the %temp% folder however nothing has worked so far. The problem became too annoying I had to get a backup connected that works beautifully now. I am still experiencing difficulties using my main connection as 95% of my traffic gets channelled to russian spider search engine site.


I have used free and paid public DNS services, tried using private DNS servers of a friend of mine on the device trying to access the web itself, the wireless router, and on the Wimax gateway but I keep getting the same results.


Could the problem be with the router itself? I did a 30-30-30 hard reset and it wont go away. My 2 desktops, visitors laptops, many iDevices and my video gaming console all can't seem to be able to get rid of the problem.


If you do figure out any time please update the thread!

Dec 16, 2011 5:33 AM in response to thomas_r.

They are not set to the default passwords on either router, and both are WPA2 protected.


I just found the DNS numbers in the airport extreme, and I changed those. I changed the numbers on my computer's connection yesterday, but I don't think I can change them on my wimax. If I can, I don't know how. It seems like, the ISP locks those settings.


Additionally, my friend is using the same ISP, has the same DNS numbers, and his stuff is still working fine. So, if he is using the same ISP and DNS numbers, and he is not having a problem, does that rule out a local DNS problem? My logic might be faulty, and I am certain there are things I don't know, so... not sure

Dec 16, 2011 5:57 AM in response to thomas_r.

I ruled out the local dns problem, dns on the wireless router (Asus rtn16), all is well. also all the devices are clean.


I believe that the problem is inside the wimax gateway provided by my isp. I am testing 3 troubled devices on a new connection and they're working properly. I also introduced a completely new, untouched device to the troubled network and traffic became troubled immediately as if the device has been infected with the same problem.

Dec 16, 2011 6:31 AM in response to mobei

I can change the DNS names under router settings, and those are the numbers being distributed, but when I go to the status page, the DNS numbers haven't changed, and there is no place in which to change them.


I have a proxy server subscription whose servers are in the States, and all of the affected sites work fine through that portal. Doesn't that prove that it is a Zain problem?

Dec 16, 2011 11:43 AM in response to kandelfire

Temporary solution proposed by zain technical support after a big fight over the phone... (works just fine)


Add yandex.ru to the List of blocked websites under the settings/options menu in the security section, this needs to be done for each browser you use. Whether ur cache is cleared or not, you will be able to avoid the sudden redirection to yandex. Your browser will show a notification that yandex has been blocked (it will block it three attempts of redirection, I took the three yandex.ru/*********** blocked sites and added them in full to the list of blocked sites under the security section in each and every browser on every single device accessing the hspa+ gateway)


My browsing is a **** lot easier now, speed though went a little down, not a problem for me as long as I can get things done)


Tech support promised a permanent solution the coming week.


I still haven't had the chance to try the VPN option. Will give it a shot and update the thread

Dec 16, 2011 12:44 PM in response to mobei

My Grandma knows more than Zain Technical Support.



To fix this annoying DNS redirect just do tho following

- Go to system prefrences -> Network

- Delete the active en3 connection

- disable the ipv6 - make it off

- unplug the zain usp and plug it in again and connect.



this will clear the cache between you and the ISP and renew the DNS settings.



Cheers,

Amer Dababneh

Dec 17, 2011 2:13 AM in response to Magnify.jo

Amér., couldnt really do this on the wimax gateway, or on any iOS powered device. Using new dns servers and blocking the www solved it for me. It could also be that the problem has been corrected somewhere else at zains end. I do agree their tech support has very little capability to solve serious issues.


Are you the same amer dababneh from ages ago on irc?


M. Obeidat

Dec 17, 2011 1:16 PM in response to kandelfire

I'm having the same problem too, noticed it on my iPhone, since yesterday, but I think it is affecting my Internet satellite receiver too as it is failing to connect to server.


What I would like to add here since I'm in Jordan too is that it doesn't seem to be a zain WiMAX problem, I'm connected through Orange Adsl and using their wireless router.


It doesn't seem to be a virus either, not on the devices at least.


Not sure what's causing this redirect.

Dec 20, 2011 11:44 AM in response to kandelfire

Hi

I live in Amman and I havethe same problems on a windows based pc. Actual from today on two PCs.

I am using Orange ADSLconnection plus another ADSL I do not know which one but different from Orangeand Zain 3G wireless. I get the same problems with all 3 connections.

I have tried almost allmalware scanners available but to no avail.


Hans

Websites being redirected to yandex.ru

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.