![]() |
|
|
#1 |
![]() |
My router is hijacked...
It happened after I was on Facebook. I received a virus last week, not exactly like the publicized one. It appears my router is hijacked as everything tests virus free now. One of my email accounts spammed everybody, and occasionally my page all the sudden goes to yahoo. Anybody know how to fix a hijacked router?
My router page should be 192.168.2.1, and is identified so by cmd.exe, yet I can't access that. |
|
|
|
|
|
#2 |
![]() |
reset it
|
|
|
|
|
|
#3 |
|
Graphical Hacker
Join Date: Feb 2006
Location: San Antonio, Texas
Posts: 7,478 (2.80/day)
Thanks: 798
Thanked 1,174 Times in 834 Posts
|
If someone somehow got control of your router because you did not change the passwords from default you have a big advantage:
YOU HAVE PHYSICAL CONTROL OF THE ROUTER. Best thing you can do is to hard reset all settings in the router, don't connect it to the web, and set a secure password / user.
__________________
CPU-Z validation sig pics temporarily blocked |
|
|
|
|
|
#4 |
![]() Join Date: Jul 2010
Location: Philly
Posts: 1,599 (1.55/day)
Thanks: 1,004
Thanked 765 Times in 539 Posts
|
Sounds more like a virus modified your hosts file then hacked your router . . .
If you're afraid your router was hijacked, which it vary likely isn't, just reset it by holding in the reset button and singing the first half of Tosca . Also disable UPnP so viruses on your network aren't able to open ports for themselves.On the other hand you could post your HJT, and start running antivirus software like it was going out of style.
__________________
|
|
|
|
|
|
#5 |
![]() |
run cmd, check up on what IP their accessing you on. They probably are getting access to your pc too through the network. Even if they hijacked the router they probably got into your network auditing settings that would allow them to access your pc. Even if you reset the router there may still be a chance of them being able to access your pc without you even knowing it. If you can figure it out and they actually have changed your domain's settings then you actually could gain access to their pc as well. It may only take their MAC address to gain access. Ehh. maybe a little more work then that, but its definitely possible.
create you own netbios profile. use cmd and run ipconfig, netstat, net view, and nbtstat. Those will help you find out whos tracking you. also check on event viewer security settings. Itll tell you what IP they do run under. They don't need to have access to your router to access you computer over the network. May also wanta check your auditing settings and make sure they havent switched over to your administrator domain and privileges. You can do that by searching for your pcs group policies and then edit them back to their default values. -They could also be a little shisty and access your pcs workgroup/domain through other computers on your network, using their domains as a way to disguise their own and gain access to your pc. Last edited by oinkypig; Nov 20, 2011 at 02:39 AM. |
|
|
|
|
|
#6 |
|
Semi-Retired Folder
Join Date: Nov 2005
Location: Indiana
Posts: 17,754 (6.48/day)
Thanks: 780
Thanked 5,116 Times in 3,707 Posts
|
I highly doubt it is your router that is hijacked. More than likely you have two things going on.
1.) Your email account was compromised when you got the original virus. Now they can send emails to everyone in your address book from your address, they don't even need access to your email account anymore to do this(though changing your password would be wise anyway), it is extremely easy to spoof an email address. 2.) You still have a piece of malware infecting your computer that is redirecting your browser to yahoo. What have you done to clean the virus, and make sure your PC is virus free?
__________________
Rig1: System Specs. Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5 Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate |
|
|
|
|
|
#7 |
![]() Join Date: Mar 2010
Location: Jakarta, Indonesia
Posts: 3,674 (3.18/day)
Thanks: 190
Thanked 835 Times in 549 Posts
|
yeah i agree try reset it then check your pc, i guess your pc got hijacked or virus or something like that.
since router/switch has no storage capability i guess the err come from your pc
__________________
:: New Cases, Tips And All About Your Cases Visit CaseGear :: ![]() Don't Ever Ask About Love And Honesty That You Don't Ever Have |
|
|
|
|
|
#8 |
![]() |
I ran tdss root kill. Hijack this. I ran Malware Malbytes. I installed MS security essentials. I also ran the Microsoft Tool that boots up in ISO, that is what cleaned the virus.
My email is web only, not sure if that matters. Edit: I also clean my browsers with bleachbit Last edited by jpierce55; Nov 20, 2011 at 03:37 AM. |
|
|
|
|
|
#9 |
![]() |
|
|
|
|
|
|
#10 |
![]() Join Date: Oct 2008
Location: στο άλφα έως ωμέγα
Posts: 3,839 (2.28/day)
Thanks: 2,032
Thanked 1,416 Times in 1,115 Posts
|
Run a few other virus tools, it does not take that long and may be worth the peace of mind.
Emsisoft Anti-Malware 6.0 Emsisoft Emergency Kit 1.0 Superantispyware Then you need to re-set a few things, like, others in previous posts mentioned. And, maybe, these free software tools will help. You may get a false positive with some A/V or anti-malware packages, as these software packages are made to changes settings, some A/V and anti-malware don't like that. Feel free to run them through Virus-total, if you have doubts. Rizonesoft's WinSock Repair - still good and works, has been replaced with Rizonesoft's Complete Internet Repair - this is the best at ease of use for me. Then there is Tweaking.com's - Windows Repair all-in-one repair tool - which is ok, has a lot, but the gui is so-so for me. Try them (not all at once). You will, more than likely, need to re-boot after using them. Hope they help. Goodluck there. ![]() EDIT: Another tool to run, is the system file checker that is built into windows. Does what it says. Open a administrative command prompt, type "sfc /scannow" (without the quotes and put a space between the "c" and "/"), hit enter and let it do an integrity scan on the system files. Last edited by 95Viper; Nov 20, 2011 at 04:23 AM. |
|
|
|
|
|
#11 |
![]() Join Date: Dec 2008
Location: Central Illinois
Posts: 1,286 (0.79/day)
Thanks: 281
Thanked 240 Times in 160 Posts
|
Common malicious software head over to Bleeping Computer I believe they have an extensive guide on how to remove it
DLL addon that is loaded when the webpage loads Might be TDSS rootkit http://www.bleepingcomputer.com/viru...ing-tdsskiller |
|
|
|
|
|
#12 | |
![]() Join Date: Jul 2008
Location: Canton, Ohio
Posts: 3,116 (1.76/day)
Thanks: 2,301
Thanked 865 Times in 612 Posts
|
Quote:
edit: Oh, and if you have another PC that you can toss the drive into, then it would be a good idea to run scans like that so there's no chance of viruses loading and interfering with the scan. You could also try using a boot-disk for the same purpose, like UBCD 4 Windows.
__________________
HEAT “congratulations! you have successfully been inflicted with tpuitis!
symptons include: prolonged computer usage, urge to make tpu your homepage, posting at rapid posts-per-day ratios (also known as post whoring), and the urge to waste lots of money on high end computer hardware that you dont need!” -panchoman
“Modding to me is something best shared with others....
Kind of like a fine wine, but without the drunk driving arrest and hangovers.” -MKmods
“i'm going to punch you in the face now Jesus..” -BumbleBee
|
|
|
|
|
|
|
#13 |
![]() |
If you cant access the router through the default gateway and you are wirelessly connected to it, then maybe the router has those connections set to a different IP range other then 192.168.2.x, that makes it so. That way you wouldn't be able to access it unless you had a direct link to the router. I'm fairly certain that can only be done manually though. make sure your IP falls within the default range of the router or just keep resetting it until it does. It has to properly reset eventually.
|
|
|
|
|
|
#14 |
![]() Join Date: Mar 2010
Location: Moorsoldaten barracks
Posts: 2,183 (1.89/day)
Thanks: 711
Thanked 312 Times in 250 Posts
|
WOW, AND ALL THIS SH*IT because you visitied Facebook? .... omg!
apart from all the gloriouse tips from above, you can also install (download from official website) the software of the router, it should have a proggie that lets you config and RESET it. Then we have the phisical buton to RESET it on the router itself. good luck! |
|
|
|
|
|
#15 |
![]() |
Yeah, and it was not the virus that made news last week. I seen a friend posted a new photo, when I clicked on that wham. The virus was attached to that photo.
![]() Resetting the router did not work. I find nothing on startup or system processes showing a virus. I'll keep digging. I tried 3 root kill softwares and still nothing I did the MS boot scan again and it found nothing. After I did all 4 I started typing an email (Firefox) and again it tried to redirect me to Yahoo. I might see if uninstalling and reinstalling the browser works.
Last edited by jpierce55; Nov 20, 2011 at 04:47 PM. Reason: Still nothing! |
|
|
|
|
|
#16 |
![]() Join Date: Jul 2008
Location: Canton, Ohio
Posts: 3,116 (1.76/day)
Thanks: 2,301
Thanked 865 Times in 612 Posts
|
That actually did work for me once on somebody's PC. Also, you might want to change your e-mail password.
__________________
HEAT “congratulations! you have successfully been inflicted with tpuitis!
symptons include: prolonged computer usage, urge to make tpu your homepage, posting at rapid posts-per-day ratios (also known as post whoring), and the urge to waste lots of money on high end computer hardware that you dont need!” -panchoman
“Modding to me is something best shared with others....
Kind of like a fine wine, but without the drunk driving arrest and hangovers.” -MKmods
“i'm going to punch you in the face now Jesus..” -BumbleBee
|
|
|
|
|
|
#17 |
![]() Join Date: Oct 2007
Location: Nelson B.C. Canada
Posts: 3,728 (1.81/day)
Thanks: 283
Thanked 750 Times in 516 Posts
|
I would try running the Kaspersky rescue disk: http://rescuedisk.kaspersky-labs.com...isk/updatable/
Also, to fully reset your router, use the 30/30/30 rule, hold the reset button for 30secs, while still holding in, unplug power from router and hold another 30secs, then plug the power back in and hold for 30secs more.
__________________
Heatware: http://www.heatware.com/eval.php?id=73875 Clan !! The Fighting 24th !! http://fxxiv.forumotion.ca/ Buy the games you like! Boycott the garbage! Cruncher: P6T Xeon ES W3570 6Gbs Ram 1xgtx285 1xgtx260 |
|
|
|
|
|
#18 |
![]() |
I have pounded and pounded. I MAY have succeeded. I had to reset all of my network settings, clean out IE explorer/Firefox again. For a little while I could not access some websites. Hopefully it is good now.
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| browser hijacked | sttubs | Networking & Security | 9 | Jul 18, 2010 07:50 AM |
| Someone hijacked my hotmail e-mail | HTC | General Software | 6 | Jul 15, 2009 10:50 PM |
| ie8 browser hijacked | InTeL-iNsIdE | Networking & Security | 7 | Jun 11, 2009 08:16 PM |
| Hynix DDR Shipment Hijacked in Taiwan | malware | News | 15 | Dec 30, 2006 10:47 AM |
| ATM's hijacked using Google | zekrahminator | News | 2 | Sep 25, 2006 09:55 PM |