As mentioned in my previous post, there has been a report about browser hijacking. However, as days goes by more and more Mac OS X users shares the same experience.
Unfortunately, this site serves unwanted pop-ups (Ads) although no malwares yet found.
So what’s happening here ?
1st of June, MozillaZine Forum user reported this incident and found his DNS search domain was set to “mygateway.net”. From the thread, they suspected that it was coming from the ISP (Rogers Cable).
A month after, another MozillaZine Forum user feels that the issue covers 3 possible source: 1) Zlob DNSChanger 2) DNS hijacking caused by SMC wireless routers 3) Rogers “service” hijacking URL searches
As more and more user experiencing this issue, I wonder if this is indeed related to Zlob’s DNSChanger. Unless someone can provide a DMG or URL for analysis, we can’t conclude this incident as new DNSChanger related activity.