I am very careful with my machines, I update them constantly and I do regular scans. Sometimes some software crashes or a machine crashes, that happens every once in a while. But I am very careful of what I install or download, so when something weird starts happening I go into lock down mode. The day before my machine was acting fine when the next day any website I enter gets redirect to “Yandex.ru/blahblahblah” I didn’t know why. Some websites would stay but regular websites get redirected.
Googling it on the infected machine was useless because it kept getting redirected so I used a different machine to Google if this happened to anyone. Turns out there is a hostile bot that hijacks websites and automatically redirects them to Yandex.ru which is a Russian search engine/mail provider.
First Step:
Result:
Next Step:
Result:
Next Step:
Result:
I won’t lie I was a bit freaked out after each step and I was getting pissed, I thought some random Russian was messing with me and I wanted to punch him. So these are the automatic steps that I took and luckily things cleared up. And usually if worse comes to worse, I would format the machine after trying everything, I would have gotten paranoid that somebody really got into it, but it didn’t reach that point.