• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

My router is hijacked...

Joined
Oct 7, 2006
Messages
1,338 (0.21/day)
Processor e8200 3.93mhz@1.264v
Motherboard P5E3 Pro
Cooling Scythe Infinity
Memory 4gb of G.Skill Ripjaw 6-7-7-18@1404 and 1.62v
Video Card(s) HIS 5770 v2 940/1275mhz stock volts
Storage 1TB Hitachi
Display(s) Acer 22" Widescreen LCD
Case Blue Cooler Master Centurion
Audio Device(s) Onboard audio :(, and Klipsch 5.1 Pro Media's
Power Supply 650 Watt BFG
Software Vista 64 Ultimate
It happened after I was on Facebook. I received a virus last week, not exactly like the publicized one. It appears my router is hijacked as everything tests virus free now. One of my email accounts spammed everybody, and occasionally my page all the sudden goes to yahoo. Anybody know how to fix a hijacked router?

My router page should be 192.168.2.1, and is identified so by cmd.exe, yet I can't access that.
 
Joined
Nov 16, 2007
Messages
1,166 (0.19/day)
Location
Hampton Roads
Processor Xeon x5650
Motherboard SABERTOOTH X58
Cooling Fans
Memory 24 GB Kingston HyperX 1600
Video Card(s) GTX 1060 3GB
Storage small ssd
Display(s) Dell 2001F, BenQ short throw
Case Lian Li
Audio Device(s) onboard
Power Supply X750
Software Mint 19.3, Win 10
Benchmark Scores not so fast...

PVTCaboose1337

Graphical Hacker
Joined
Feb 1, 2006
Messages
9,501 (1.43/day)
Location
Texas
System Name Whim
Processor Intel Core i5 2500k @ 4.4ghz
Motherboard Asus P8Z77-V LX
Cooling Cooler Master Hyper 212+
Memory 2 x 4GB G.Skill Ripjaws @ 1600mhz
Video Card(s) Gigabyte GTX 670 2gb
Storage Samsung 840 Pro 256gb, WD 2TB Black
Display(s) Shimian QH270 (1440p), Asus VE228 (1080p)
Case Cooler Master 430 Elite
Audio Device(s) Onboard > PA2V2 Amp > Senn 595's
Power Supply Corsair 750w
Software Windows 8.1 (Tweaked)
If someone somehow got control of your router because you did not change the passwords from default you have a big advantage:

YOU HAVE PHYSICAL CONTROL OF THE ROUTER. Best thing you can do is to hard reset all settings in the router, don't connect it to the web, and set a secure password / user.
 

streetfighter 2

New Member
Joined
Jul 26, 2010
Messages
1,655 (0.33/day)
Location
Philly
Sounds more like a virus modified your hosts file then hacked your router . . .

If you're afraid your router was hijacked, which it vary likely isn't, just reset it by holding in the reset button and singing the first half of Tosca :rolleyes:. Also disable UPnP so viruses on your network aren't able to open ports for themselves.

On the other hand you could post your HJT, and start running antivirus software like it was going out of style. :D
 
Joined
Dec 17, 2005
Messages
446 (0.07/day)
System Name Desktop
Processor 7800 x3d
Motherboard Giga b650i aorus ultra
Cooling pk-3 | conductonaut | AC LF II 280
Memory 64g Gskill X5 ddr 6000 cl30
Video Card(s) 7900 xt
Storage 2Tb Inland Premium
Display(s) Armada 27 1440p 165 + 25 1080p 240hz
Case Tt Black Armor : Phantek Evolv shift xt
Audio Device(s) Ae-7
Power Supply Aresgame 850 sff
Mouse Razer Viper ulti
Keyboard Saitek Eclipse I, II, & III
Benchmark Scores assd 6600|x5675 Cne11.5 -1102|Timespy 24000 | TS Extreme gpu 1 - 87 fps
run cmd, check up on what IP their accessing you on. They probably are getting access to your pc too through the network. Even if they hijacked the router they probably got into your network auditing settings that would allow them to access your pc. Even if you reset the router there may still be a chance of them being able to access your pc without you even knowing it. If you can figure it out and they actually have changed your domain's settings then you actually could gain access to their pc as well. It may only take their MAC address to gain access. Ehh. maybe a little more work then that, but its definitely possible.
create you own netbios profile. use cmd and run ipconfig, netstat, net view, and nbtstat. Those will help you find out whos tracking you. also check on event viewer security settings. Itll tell you what IP they do run under. They don't need to have access to your router to access you computer over the network. May also wanta check your auditing settings and make sure they havent switched over to your administrator domain and privileges. You can do that by searching for your pcs group policies and then edit them back to their default values.
-Theres workaround and access your pcs workgroup/domain through other computers on your network, using their domains as a way to disguise their own and gain access to your pc.
 
Last edited:

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,472 (4.23/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
I highly doubt it is your router that is hijacked. More than likely you have two things going on.

1.) Your email account was compromised when you got the original virus. Now they can send emails to everyone in your address book from your address, they don't even need access to your email account anymore to do this(though changing your password would be wise anyway), it is extremely easy to spoof an email address.

2.) You still have a piece of malware infecting your computer that is redirecting your browser to yahoo.

What have you done to clean the virus, and make sure your PC is virus free?
 
Joined
Mar 26, 2010
Messages
9,784 (1.90/day)
Location
Jakarta, Indonesia
System Name micropage7
Processor Intel Xeon X3470
Motherboard Gigabyte Technology Co. Ltd. P55A-UD3R (Socket 1156)
Cooling Enermax ETS-T40F
Memory Samsung 8.00GB Dual-Channel DDR3
Video Card(s) NVIDIA Quadro FX 1800
Storage V-GEN03AS18EU120GB, Seagate 2 x 1TB and Seagate 4TB
Display(s) Samsung 21 inch LCD Wide Screen
Case Icute Super 18
Audio Device(s) Auzentech X-Fi Forte
Power Supply Silverstone 600 Watt
Mouse Logitech G502
Keyboard Sades Excalibur + Taihao keycaps
Software Win 7 64-bit
Benchmark Scores Classified
yeah i agree try reset it then check your pc, i guess your pc got hijacked or virus or something like that.
since router/switch has no storage capability i guess the err come from your pc
 
Joined
Oct 7, 2006
Messages
1,338 (0.21/day)
Processor e8200 3.93mhz@1.264v
Motherboard P5E3 Pro
Cooling Scythe Infinity
Memory 4gb of G.Skill Ripjaw 6-7-7-18@1404 and 1.62v
Video Card(s) HIS 5770 v2 940/1275mhz stock volts
Storage 1TB Hitachi
Display(s) Acer 22" Widescreen LCD
Case Blue Cooler Master Centurion
Audio Device(s) Onboard audio :(, and Klipsch 5.1 Pro Media's
Power Supply 650 Watt BFG
Software Vista 64 Ultimate
I ran tdss root kill. Hijack this. I ran Malware Malbytes. I installed MS security essentials. I also ran the Microsoft Tool that boots up in ISO, that is what cleaned the virus.

My email is web only, not sure if that matters.

Edit: I also clean my browsers with bleachbit
 
Last edited:
Joined
Oct 7, 2006
Messages
1,338 (0.21/day)
Processor e8200 3.93mhz@1.264v
Motherboard P5E3 Pro
Cooling Scythe Infinity
Memory 4gb of G.Skill Ripjaw 6-7-7-18@1404 and 1.62v
Video Card(s) HIS 5770 v2 940/1275mhz stock volts
Storage 1TB Hitachi
Display(s) Acer 22" Widescreen LCD
Case Blue Cooler Master Centurion
Audio Device(s) Onboard audio :(, and Klipsch 5.1 Pro Media's
Power Supply 650 Watt BFG
Software Vista 64 Ultimate
Sounds more like a virus modified your hosts file then hacked your router . . .

. :D

Perhaps, I don't know what is going on. I don't know why I can't access the router settings page. I did try resetting the router, so it is probably something else.
 

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,670 (2.23/day)
Run a few other virus tools, it does not take that long and may be worth the peace of mind.

Emsisoft Anti-Malware 6.0

Emsisoft Emergency Kit 1.0

Superantispyware

Then you need to re-set a few things, like, others in previous posts mentioned.

And, maybe, these free software tools will help.
You may get a false positive with some A/V or anti-malware packages, as these software packages are made to changes settings, some A/V and anti-malware don't like that.
Feel free to run them through Virus-total, if you have doubts.

Rizonesoft's WinSock Repair - still good and works, has been replaced with Rizonesoft's Complete Internet Repair - this is the best at ease of use for me.
Then there is Tweaking.com's - Windows Repair all-in-one repair tool - which is ok, has a lot, but the gui is so-so for me.

Try them (not all at once). You will, more than likely, need to re-boot after using them.
Hope they help. Goodluck there.:)

EDIT: Another tool to run, is the system file checker that is built into windows. Does what it says.

Open a administrative command prompt, type "sfc /scannow" (without the quotes and put a space between the "c" and "/"), hit enter and let it do an integrity scan on the system files.
 
Last edited:
Joined
Jul 20, 2008
Messages
4,016 (0.70/day)
Location
Ohio
System Name Desktop|| Virtual Host 0
Processor Intel Core i5 2500-K @ 4.3ghz || 2x Xeon L5630 (total 8 cores, 16 threads)
Motherboard ASUS P8Z68-V || Dell PowerEdge R710 (Intel 5520 chipset)
Cooling Corsair Hydro H100 || Stock hotplug fans and passive heatsinks
Memory 4x4gb Corsair Vengeance DDR3 1600 || 12x4gb Hynix DDR3 1066 FB-DIMMs
Video Card(s) MSI GTX 760 Gaming Twin Frozr 4GB OC || Don't know, don't care
Storage Hitachi 7K3000 2TB || 6x300gb 15k rpm SAS internal hotswap, 12x3tb Seagate NAS drives in enclosure
Display(s) ViewSonic VA2349S || remote iDRAC KVM console
Case Antec P280 || Dell PowerEdge R710
Audio Device(s) HRT MusicStreamer II+ and Focusrite Scarlett 18i8 || Don't know, don't care
Power Supply SeaSonic X650 Gold || 2x870w hot-swappable
Mouse Logitech G500 || remote iDRAC KVM console
Keyboard Logitech G510 || remote iDRAC KVM console
Software Win7 Ultimate x64 || VMware vSphere 6.0 with vCenter Server 6.0
Benchmark Scores Over 9000 on the scouter
Sounds more like a virus modified your hosts file then hacked your router . . .
Yeah, check your hosts file for anything suspicious or out of place. Also check msconfig for any startup programs and services that look suspicious and disable them. You might want to do this in safe-mode since some viruses can detect you trying to disable them and just make a different file, etc.

edit: Oh, and if you have another PC that you can toss the drive into, then it would be a good idea to run scans like that so there's no chance of viruses loading and interfering with the scan. You could also try using a boot-disk for the same purpose, like UBCD 4 Windows.
 
Joined
Dec 17, 2005
Messages
446 (0.07/day)
System Name Desktop
Processor 7800 x3d
Motherboard Giga b650i aorus ultra
Cooling pk-3 | conductonaut | AC LF II 280
Memory 64g Gskill X5 ddr 6000 cl30
Video Card(s) 7900 xt
Storage 2Tb Inland Premium
Display(s) Armada 27 1440p 165 + 25 1080p 240hz
Case Tt Black Armor : Phantek Evolv shift xt
Audio Device(s) Ae-7
Power Supply Aresgame 850 sff
Mouse Razer Viper ulti
Keyboard Saitek Eclipse I, II, & III
Benchmark Scores assd 6600|x5675 Cne11.5 -1102|Timespy 24000 | TS Extreme gpu 1 - 87 fps
If you cant access the router through the default gateway and you are wirelessly connected to it, then maybe the router has those connections set to a different IP range other then 192.168.2.x, that makes it so. That way you wouldn't be able to access it unless you had a direct link to the router. I'm fairly certain that can only be done manually though. make sure your IP falls within the default range of the router or just keep resetting it until it does. It has to properly reset eventually.
 
Joined
Mar 24, 2010
Messages
5,047 (0.98/day)
Location
Iberian Peninsula
WOW, AND ALL THIS SH*IT because you visitied Facebook? .... omg!

apart from all the gloriouse tips from above, you can also install (download from official website) the software of the router, it should have a proggie that lets you config and RESET it.

Then we have the phisical buton to RESET it on the router itself.

good luck!
 
Joined
Oct 7, 2006
Messages
1,338 (0.21/day)
Processor e8200 3.93mhz@1.264v
Motherboard P5E3 Pro
Cooling Scythe Infinity
Memory 4gb of G.Skill Ripjaw 6-7-7-18@1404 and 1.62v
Video Card(s) HIS 5770 v2 940/1275mhz stock volts
Storage 1TB Hitachi
Display(s) Acer 22" Widescreen LCD
Case Blue Cooler Master Centurion
Audio Device(s) Onboard audio :(, and Klipsch 5.1 Pro Media's
Power Supply 650 Watt BFG
Software Vista 64 Ultimate
Yeah, and it was not the virus that made news last week. I seen a friend posted a new photo, when I clicked on that wham. The virus was attached to that photo. :(

Resetting the router did not work. I find nothing on startup or system processes showing a virus. I'll keep digging.

I tried 3 root kill softwares and still nothing :( I did the MS boot scan again and it found nothing. After I did all 4 I started typing an email (Firefox) and again it tried to redirect me to Yahoo. I might see if uninstalling and reinstalling the browser works.
 
Last edited:
Joined
Jul 20, 2008
Messages
4,016 (0.70/day)
Location
Ohio
System Name Desktop|| Virtual Host 0
Processor Intel Core i5 2500-K @ 4.3ghz || 2x Xeon L5630 (total 8 cores, 16 threads)
Motherboard ASUS P8Z68-V || Dell PowerEdge R710 (Intel 5520 chipset)
Cooling Corsair Hydro H100 || Stock hotplug fans and passive heatsinks
Memory 4x4gb Corsair Vengeance DDR3 1600 || 12x4gb Hynix DDR3 1066 FB-DIMMs
Video Card(s) MSI GTX 760 Gaming Twin Frozr 4GB OC || Don't know, don't care
Storage Hitachi 7K3000 2TB || 6x300gb 15k rpm SAS internal hotswap, 12x3tb Seagate NAS drives in enclosure
Display(s) ViewSonic VA2349S || remote iDRAC KVM console
Case Antec P280 || Dell PowerEdge R710
Audio Device(s) HRT MusicStreamer II+ and Focusrite Scarlett 18i8 || Don't know, don't care
Power Supply SeaSonic X650 Gold || 2x870w hot-swappable
Mouse Logitech G500 || remote iDRAC KVM console
Keyboard Logitech G510 || remote iDRAC KVM console
Software Win7 Ultimate x64 || VMware vSphere 6.0 with vCenter Server 6.0
Benchmark Scores Over 9000 on the scouter
I might see if uninstalling and reinstalling the browser works.
That actually did work for me once on somebody's PC. Also, you might want to change your e-mail password.
 

johnspack

Here For Good!
Joined
Oct 6, 2007
Messages
5,981 (0.99/day)
Location
Nelson B.C. Canada
System Name System2 Blacknet , System1 Blacknet2
Processor System2 Threadripper 1920x, System1 2699 v3
Motherboard System2 Asrock Fatality x399 Professional Gaming, System1 Asus X99-A
Cooling System2 Noctua NH-U14 TR4-SP3 Dual 140mm fans, System1 AIO
Memory System2 64GBS DDR4 3000, System1 32gbs DDR4 2400
Video Card(s) System2 GTX 980Ti System1 GTX 970
Storage System2 4x SSDs + NVme= 2.250TB 2xStorage Drives=8TB System1 3x SSDs=2TB
Display(s) 2x 24" 1080 displays
Case System2 Some Nzxt case with soundproofing...
Audio Device(s) Asus Xonar U7 MKII
Power Supply System2 EVGA 750 Watt, System1 XFX XTR 750 Watt
Mouse Logitech G900 Chaos Spectrum
Keyboard Ducky
Software Manjaro, Windows 10, Kubuntu 23.10
Benchmark Scores It's linux baby!
I would try running the Kaspersky rescue disk: http://rescuedisk.kaspersky-labs.com/rescuedisk/updatable/
Also, to fully reset your router, use the 30/30/30 rule, hold the reset button for 30secs, while still holding in, unplug power from router and hold another 30secs, then plug the power back in and hold for 30secs more.
 
Joined
Oct 7, 2006
Messages
1,338 (0.21/day)
Processor e8200 3.93mhz@1.264v
Motherboard P5E3 Pro
Cooling Scythe Infinity
Memory 4gb of G.Skill Ripjaw 6-7-7-18@1404 and 1.62v
Video Card(s) HIS 5770 v2 940/1275mhz stock volts
Storage 1TB Hitachi
Display(s) Acer 22" Widescreen LCD
Case Blue Cooler Master Centurion
Audio Device(s) Onboard audio :(, and Klipsch 5.1 Pro Media's
Power Supply 650 Watt BFG
Software Vista 64 Ultimate
I have pounded and pounded. I MAY have succeeded. I had to reset all of my network settings, clean out IE explorer/Firefox again. For a little while I could not access some websites. Hopefully it is good now.
 
Top