You probably know, but the people to contact are your ISP to tell them of their DNS poisoning, and also the "rewards" company to complain about their sneaky affiliate.
You mentioned that it's not confined to just your ISP - It's possible for these DNS attacks to cascade due to the nature of DNS, so the attack may have originated higher up than just your ISP's DNS servers. But they should be able to have a better idea of what's happening.
Comments
I live in a high-rise in downtown Chicago, so my ISP is some local company that services multi-tenant buildings: https://www.am3inc.com/default.cfm
Yes, affiliate params were being passed in the URL to the forward page.
You probably know, but the people to contact are your ISP to tell them of their DNS poisoning, and also the "rewards" company to complain about their sneaky affiliate.
You mentioned that it's not confined to just your ISP - It's possible for these DNS attacks to cascade due to the nature of DNS, so the attack may have originated higher up than just your ISP's DNS servers. But they should be able to have a better idea of what's happening.