DNS Hijack?

Status
Not open for further replies.

nj_gamer

Contributor
Hi All,

I have this peculiar problem since last week, whenever i visit some sites like google, i get redirected to this page information.com

You can find a similiar screenshot here:

http://www.pawsalava.com/mizoram-popular-website-misual-com-is-inaccessible/

Now i first suspected some malware, and i scaned my system with malwarebytes anti malware and SuperAntiSpyware. I am also protected by kaspersky and Outpost firewall Pro, with the latest versions.

I couldn't find anything. I don't want to brag, but i haven't been infected with any virus/trojan/malware since 8-9 years, and i always conssder security as my main priority. And i am very careful on what i open, and if i find anything suspicious, i always use Sandboxie.

The thing is this problem occurs on my laptop too. And i have both Win XP and Win 7 installed, and i could reproduce the problem on both the systems.

I suspect something is messed up in the DNS, and i've added both OpenDNS and Google Public DNS in the router config page and also on the OS, and the problem keeps occuring.

What baffles me the most is that, the page suddenly appears, and even when i do a google search on the above link, i get 0 results.

I have a BSNL connection, and i have updated my OS, Antivirus, Firewall, AntiMalware to the latest updates. I use Opera as my only browser, but then i tested the sites with firefox and IE8

I did notice bleepingcomputer.com was blocked, even the peerblock updates weren't working

What could be the problem?

Regards,

Nj
 
Well i used some web proxies, and the sites were accessible... some of them were well known sites like youtube, google, and some general sites.
 
Few days back it happened for me while trying to access Google. For couple of hours and I could not access Google from my m/c - it was directing me to some information site. Cleansed temp folders, cache and did all kinds of scan w/o any success. I then accessed Google from another friend's m/c and searched for this issue. Got an old forum thread where it said that there may be a corrupt DNS server and it should get rectified in a short period. I then switched off the m/c and went out for for a few hours. When I came back I was able access the Google as if nothing has happened
 
I guess i fixed it, I checked the ipconfig /all command and noticed that the DNS used was the BSNL one and the OpenDNS/Google DNS was ignored... then i realised that i had changed the DNS server in the router config page and the Ethernet adapter properties... but since i use a PPPoE connection(using a dialer) it somehow bypassed the DNS server settings and used the BSNL DNS server... Now the sites work fine... I guess the BSNL DNS servers are poisoned, and probably by phishers...

Anyhow, i guess i should do some more reading on the PPPoE connection and the windows dialers... Guess everytime we learn something new :)

I hope this post is useful to others... btw i feel Google DNS is better than Open DNS :)

Regards,
nj
 
  • Like
Reactions: 1 person
It was happening to me too,after reading your post i changed both the preferred and alternate DNS to google DNS and issue went away,earlier i used the BSNL dns as preferred
 
Thank you, I was looking for something like this to workaround frequent time out issues with Reliance DNS servers.

BTW, are there any known latency issues with Google DNS?
 
Status
Not open for further replies.