Windows keeps using a preferred DNS server?

Solution 1:

You may be infected with the DNS Changer virus. Go to this site and it can detect if you are infected (the site is actually run by the FBI as they are the ones managing the Command and Control servers sense the people who wrote the virus got arrested last year).

If you are infected, the FBI is shutting down the servers July 8th so you will have no DNS after that date if you have not removed the infection.

Solution 2:

Tor or some software from the Tor bundles does not do this. Since Tor is working on application level (proxy) there is no need to modify adapter settings.

Maybe you also use (or have used) some VPN software or software for location based management of adapter settings? Some systems come with such software pre-installed. Perhaps the DNS server's PTR or WHOIS data give some hint which software is changing the setting.

Solution 3:

The problem was indeed a virus. This time, it may or may not have installed itself to the boot sector--using an Ubuntu livecd and running fixmbr did not solve the problem. Malware Bytes did not find the virus. Spybot Search & Destroy did not find the virus.

Fortunately, ComboFix successfully removed all traces of the virus. I haven't seen any of the redirects in a month.