Main Forum > General Computer Support
(solved)Is Public google dns safe to be selected?
jraju:
Hi, Since the scan by avast shown me dns hijack, i have changed the dns to google dns in the router. But scanning thro a software , the actual dns servers at the time of browsing of a session , point out the existence of an unknown foreign server, which is trying to access the router at some point of times and not always. Moreover, the same website's advt pop up shows whenever i try to view other websites. There the popup would show up.
So, i changed back to my ISP's dhcp server to be on the safer side. But now avast shows dns hijack of domain sites.
I wrote to avast to confirm that dns hijack is false positive and expecting reply from them.
Even full scan at online dns scan site, proved the presence of unknown server.
how to confirm that it is false positive? Nslookup to those domains show the same ip, but peculiarly my service Provider Ip. What to make of it ? pl experts
Boggin:
I don't know what report means either.
I use some of Level Three's DNS servers - 209.244.0.3 and 209.244.0.4 but download the free version of MBAM - click on Scan in the left pane then on Custom/Configure Scan and check the boxes for the drives you want to scan - usually it's just C:
This is a full scan and can take a while to complete.
This will find and remove any PuPs and PuMs.
Follow that up with a scan of AdwCleaner.
Click on Scan and then on Log.
When it has done it's scan it may list some items in the pane below which it considers PuPs - if you want to keep any then uncheck their boxes.
Close the Log and click on Cleaniing where it will produce another report of what it has deleted after the reboot.
https://www.malwarebytes.com/mwb-download/
https://www.malwarebytes.com/adwcleaner/
Run this check on your router to see if it has been hacked and if it has then you will need to factory reset it.
https://www.komando.com/cool-sites/312613/test-your-router-to-see-if-its-been-hacked-heres-how
jraju:
Hi, I have already checked with mbam.Nothing suspicious found in full scan. Fsecure router checker is not working for months. It pops up ovreloading...try after sometime.
Can the ISP allot public ips of some other country to the users of the service provider? I mean, that can the service provider allow a foreign ip as public ip to me, in India?
I have checked the public ip at that time. That was a different one.
Boggin:
I don't know how the ISPs work in India, but for you to be getting a pop up every now and again suggests that you have what is known as a Google redirect.
Which browser are you using ?
If you are using IE then go Start - type iexplore -extoff and press enter.
This will open IE without add-ons.
Click on the home page icon to browse normally and then see if you continue to get those pop ups.
Use this article to set your Hosts file back to default should something have added an entry in there.
https://support.microsoft.com/en-us/help/972034/how-to-reset-the-hosts-file-back-to-the-default
I'll have a look at your IP address and see where it originates and get back to you.
Did you try a scan with AdwCleaner ?
That F-Secure test worked for me.
Boggin:
According to https://www.ultratools.com/tools/ipWhoisLookup it appears to be Chinese.
The page doesn't copy with an IP address in it so enter 117.93.195.165 into the box and hit Go then scroll down for the details.
I'd contact your ISP for clarification.
Navigation
[0] Message Index
[#] Next page
Go to full version