● WEBSITE REDIRECTING

Website redirecting to spam or strange pages?

A redirect is not always a mistake, and it is not always visible to the owner. Some malicious redirects only trigger for certain visitors, devices or search results. Dr Web can investigate why the site is redirecting, whether it is a compromise or a fault, and what needs to happen next.

  • Investigation of redirect behaviour
  • Compromise or configuration fault
  • Specialist WordPress recovery
  • No passwords needed to start
DR.WEB / REDIRECT CHECK
REPORTED BYVISITORS
REPRODUCEDNOT YET CONFIRMED
CAUSECOMPROMISE OR FAULT?
SITE ACCESSNOT YET PROVIDED
STATUS● INVESTIGATING
ILLUSTRATIVE DIAGNOSTIC INTERFACE

Why you may not see the redirect yourself

Visitors often report a redirect that the owner cannot reproduce. That does not mean the report is wrong. Malicious code can be written to redirect only certain visitors, such as people arriving from a search result, people on a mobile device or people who are not logged in.

Testing repeatedly can also waste time or put you at risk if the destination is unsafe. It is better to collect what has been reported and get the site investigated than to keep clicking.

● WHAT IT CAN INVOLVE

What a redirecting website can involve

01

Redirects for some visitors only

The site may behave normally for you and redirect people who arrive from Google, use a phone or are visiting for the first time.

02

Code added to the site

Malicious code can be added to theme files, plugin files or content stored in the database. Removing what you can see may not remove the way it returns.

03

Unauthorised access

A redirect can be a symptom of an unknown user, a compromised account or an out-of-date component that gave someone else a way in.

04

Spam pages and search results

A site that redirects visitors may also contain pages that you did not create, and Google may show unexpected text for the domain.

05

Redirects that are settings, not attacks

Redirect loops or unexpected destinations can follow a change to the domain, a security certificate or a redirect plugin. These are faults that need repairing, not malware removal.

06

Redirects that come back

If the redirect disappears and returns, something is probably still in place. The cause needs finding rather than the symptom hiding.

What to do while you wait

01

Record what has been reported

Note the web address people were on, the device they used, how they arrived and where they ended up. Screenshots help.

02

Do not keep testing the redirect

Repeated clicks on an unsafe destination can put you at risk. Do not enter any details on a page that you were redirected to.

03

Keep passwords out of email and forms

Do not send passwords or login details through the public form or ordinary email. A secure method is arranged when access is needed.

04

Avoid deleting files or restoring blindly

Random changes can destroy evidence and can leave the underlying access route open.

Is this a hack or a configuration fault?

It is more likely to be a compromise if:

  • only some visitors, devices or search arrivals are redirected
  • the destination is spam, gambling, adult or scam content
  • pages, files or users appear that nobody created
  • the redirect returns after being removed

If the redirect began straight after a change to the domain, SSL certificate, permalink or redirect plugin, or the browser reports too many redirects, Emergency WordPress Repair may be the better path. If you are unsure, submit the symptoms and Dr Web can help work out which it is.

Why Dr Web

01

Specialists in WordPress recovery

Redirect investigations often involve files, database content, users and plugins together. Dr Web treats them as one investigation.

02

Compromise or fault, decided by evidence

Not every redirect is an attack. The first job is to establish which it is, so the right service is used.

03

Not sure what the site runs on?

If you do not know the platform, Dr Web can check what the website runs on and whether it is WordPress before recommending a next step.

04

Written findings

You receive a record of what was found and changed, not just a statement that the redirect has stopped.


How Dr Web investigates a redirect

01

Tell us what has been reported

Send the website address, who reported the redirect and where they were sent. Do not include passwords.

02

We check fit and safety

Dr Web reviews the request and recommends the safest first step, including whether the site should stay live while it is investigated.

03

Investigation is scoped

The scope, access method and quote are agreed before the technical work begins.

04

Fix, verify and report

The cause is addressed within the agreed scope, the relevant pages are checked and the findings are recorded.

● RELATED RECOVERY FILE

Related Recovery File

This historical case involved injected spam content rather than a visitor redirect. Symptoms and scope vary by website.

RELATED RECOVERY FILE / 003RECOVERED

Recurring Malware After Host Quarantine

Injected code and casino content were removed, WordPress components were updated, PHP was upgraded from 7.4 to 8.2, and a firewall and malware scanner were configured. The recurring infections stopped.

FINDINGS
Quarantining individual files had not addressed outdated application software.
ACTION
Injected code and casino content were removed.
Read the Recovery File
RELATED RECOVERY FILE / 012RECOVERED

Spam Redirect on a Corporate Website

A corporate website began sending visitors to a spam site. A restore from before the compromise was advised, the injected code was removed, and administrator credentials were reset. The client confirmed the redirect had stopped.

FINDINGS
Injected code had been inserted into the site.
ACTION
A restore of a backup from before the compromise was advised, followed by a malware scan, cleanup and software updates.
Read the Recovery File

Need help with something else?

Frequently asked questions

Malicious code can redirect only certain visitors, such as those arriving from search results or using mobile devices. That is one reason a redirect can be hard for the owner to reproduce.

No. Changes to the domain, SSL certificate, permalinks or a redirect plugin can also cause unwanted redirects. The cause has to be established from the evidence.

Reinstalling WordPress alone does not remove code stored in the database, extra files or an unauthorised user. If the access route is still there, the redirect can return.

Fixing the site is an important step, but Google processes changes in its own time. Dr Web can help with the site-side work and explain what remains outside its control.

It can be sensible to, particularly if the host has issued a notice or suspended the account. The provider controls any suspension and must approve its removal.

Not to start. Dr Web reviews the request first. If access is needed, it is arranged through a secure process, never through the public form or ordinary email.

Get the redirect investigated

Tell us what has been reported and what the website does for the business. Dr Web will review the request and explain the safest next step.