Redirects and McAfee Popups that are appearing on the Nexus site.


Started happening to me 3 days ago. Very annoying, have to shut down the page and then find it again, only happens on Nexus.


I suppose if I had read more than the first page of posts, I would have seen you were already aware.

Dark0ne... hope this isn't a necro but the redirects are really really bad currently:

2100hr, SE Usa, Edge Browser


Seems to be associated with plugin adds in LR corner. After about a 45sec delay the redirects are constant. Fallout 4 almost immediate, Skyrim you have a couple minutes before they start. Stopped checking there. Will test Chrome now.


Update edit:
Chrome gives us about 5-7 min before redirects start.
Sample redirects (in Chrome)
Still occurring but strangely it starts in the evening about 1900hr EST and stops sometime in the early morning for me.

I ran a sitecheck which reports:

"Medium Security Risk" due to an old version of PHP being run


Suggested corrections:

Hardening Improvements
Security Headers

Missing security header for ClickJacking Protection. Alternatively, you can use Content-Security-Policy: frame-ancestors 'none'.

Missing security header to prevent Content Type sniffing.

Missing Strict-Transport-Security security header.

Missing Content-Security-Policy directive. We recommend to add the following CSP directives (you can use default-src if all values are the same): script-src, object-src, base-uri, frame-src

Leaked PHP version. Your site is displaying your PHP version in the HTTP headers. Please set expose_php = Off.


(Source: https://sitecheck.sucuri.net/

First time on forum since I didn't know where else to go for this. I just had multiple pop up redirect ads in a row while trying to browse the site just now- including the mcafee one, scan didn't find anything and I have no trouble elsewhere. I understand needing to run ads to pay for the site but these are getting very obnoxious.

Edit: Got two more, mcaffee again and one was called matildawu.online, or atleast thats what is was called in the url.

