求助:DNS疑似遭劫持问题排查及解决建议(Ubuntu 17.10)
Hey there, let's tackle this annoying redirect issue together—nothing's more frustrating than a fresh Ubuntu install acting up with unwanted domain hijacks. Here's a step-by-step troubleshooting plan to get to the bottom of it:
Just changing the WiFi DNS doesn't always mean the system is using it. Let's verify:
- Run
systemd-resolve --statusand look for the "DNS Servers" section under your active network interface. It should show 8.8.8.8 and 8.8.4.4 if your Google DNS settings stuck. - Alternatively, run
nslookup testdomain.comand check the "Server" line at the top. If it's not Google's DNS, your system is ignoring the WiFi config.
Malware or misconfigs often mess with local files first:
- Inspect your hosts file for suspicious entries:
cat /etc/hosts
Look for any lines pointing toadvexplore.comor random IPs that shouldn't be there. If you find something, edit the file withsudo nano /etc/hostsand delete the bad lines. - Flush your system's DNS cache to clear any stale hijacked records:
sudo systemd-resolve --flush-caches
Then restart the DNS service to be safe:sudo systemctl restart systemd-resolved
Sometimes the issue is isolated to your browser, not the entire system:
- Check your browser's default search engine—make sure it's not set to
advexplore.comor a weird unknown provider. - Disable all browser extensions temporarily, then test accessing a non-existent domain again. A malicious extension could be forcing the redirect.
- If that doesn't work, reset your browser to its default settings (most browsers have a "Restore defaults" or "Refresh" option in their settings menu).
Even fresh installs can pick up bad stuff if you downloaded software from untrusted sources:
- Install ClamAV, a free open-source antivirus tool:
sudo apt-get update && sudo apt-get install clamav - Update its virus definitions:
sudo freshclam - Run a full system scan (this might take a while):
sudo clamscan -r / - Also, check for suspicious startup programs:
For GNOME desktop, rungnome-session-propertiesand look for any unrecognized apps set to launch on startup.
For system services, runsudo systemctl list-unit-files --type=serviceand note any services you don't recognize.
Some ISPs force redirects even when you use custom DNS. Let's verify:
- Run
dig randomfakeexamplexyz.com(use any totally made-up domain).
A normal response with Google DNS should showNXDOMAIN(meaning the domain doesn't exist). If you get an IP address pointing toadvexplore.com, your ISP is doing transparent hijacking. - If that's the case, try using DNS over TLS (DoT) or a VPN to bypass the ISP's redirects.
Ubuntu 17.10 uses systemd-resolved, which sometimes overrides DNS settings via a linked resolv.conf file:
- Check what
/etc/resolv.confpoints to:ls -l /etc/resolv.conf - If it's a symlink to
/run/systemd/resolve/stub-resolv.conf, we can replace it with a manual config:- Unlink the existing file:
sudo unlink /etc/resolv.conf - Create a new file:
sudo nano /etc/resolv.conf - Paste these lines:
nameserver 8.8.8.8 nameserver 8.8.4.4 - Save and exit (Ctrl+O, then Ctrl+X in nano)
- Restart NetworkManager to apply changes:
sudo systemctl restart NetworkManager
- Unlink the existing file:
If none of these steps fix the redirect, double-check if you installed any third-party network tools or software right before the issue started—sometimes those can inject DNS hijacks.
内容的提问来源于stack exchange,提问作者Brandon Bertelsen

