Default search for whole subnet points to bestmovies.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by swattz101, Aug 10, 2006.

  1. swattz101

    swattz101 Private E-2

    First, I'm not sure it this should be in malware or network, could be either.

    Second of all, thanks to everyone here. I've lurked here many times in the past and been able to use the tips here to fix many a problem on my computer and others both at home and at work. I pride myself on being able to research and fix the problems myself. But this one has me stumped. I would run the programs mentioned here, but I don't know where to start.

    Third, a little background, if it will help. I am one of two IT managers for a small bank. We have two branches. The PDC is at the branch where my office is, the BDC at the other branch. We are using NAT and each branch is on it's own subnet. The problem we are having is only at the second branch and is as follows. Anytime someone at the other branch types in a URL that does not exist, instead of getting a 404 error, they get sent to bestmovies.com. When I first heard of this, I did try most of the tools to find out how it had been hijacked, but turned up nothing. As I have looked into this, I have found it come up on nearly every computer on that subnet. I have even taken my laptop in and tried it, and it comes up with that problem at the other branch, but not in my office.

    We had a trainer come in about two weeks ago from one of our software venders to do some training on new software. It was embarasing to explain to her what was going on when she also got the search page on a URL typo while her laptop was connected to the network and a projector.

    My thoughts are DNS related, but I have little experience in that area. I just remember Verasign or someone doing redirects at one time trying to sell domain names. If anyone has any ideas, I would apriciate it.

    Thanks for your time.
    Steve
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    It does sound like something in the network between the actual PC and the network cloud is causing the problem. Is there another PC or server in the link? What about a switch or router? Paint me a picture of everything in the path beginning with the end PC having the problem and out to the internet.
     
  3. swattz101

    swattz101 Private E-2

    Basically, all the other computers at that branch are connected to a router located at that branch. The BDC is also connected to the router at that branch. That server provideds DHCP/local DNS to provide NAT address to that branch. The branch is on it's own subnet. That branch is connected by frame relay to the Main branch. The main branch then connects to the internet. The problem is only at the remote branch, which leads me to believe that it is probably on the BDC, but where to start.

    I'm trying to think of anything else that might be in between, but can't come up with anything. The other branch is about 15 miles away on the other side of the city. The router is managed by a third party, and I can't get into it so check into anything.

    Thanks again for your help
    Steve
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless the router is really a PC or unless someone reprogrammed the router's response for unknown URLs, then I'm not sure what you problem is either. This may be something better discussed in the Networking Forum.

    If you want to pursue the chance of some kind of malware, you should complete all the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds