Author Topic: malware possibly in router?  (Read 370 times)

0 Members and 1 Guest are viewing this topic.

Offline mjduck

  • Newbie
  • *
  • Posts: 2
malware possibly in router?
« on: April 02, 2011, 06:50:11 PM »
My computer, along with Ipad, and netbook has what looks to be a redirect browser problem. It doesn't matter which browser we use, chrome, IE, Firfox.  Sometimes a new tab gets openned without us wanting it to.  Sometimes links through a search engine goes to an unwanted site.  We just got my Daughter a laptop and upon turning it on, the same thing happened to her browser.  Any ideas what causes this?  This is my first post, and not sure what all the protocals are.  Could this be a problem with a router instead of a computer?  Also, I took my main computer into work for our IT guy to see, and it worked flawlessly there. 

Thanks for your help.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: malware possibly in router?
« Reply #1 on: April 02, 2011, 09:59:05 PM »
Hi, mjduck.  Welcome to LandzDown Forum.

We will do our best to assist you.  However, in order to do so, please follow all instructions provided in the sequence given.  Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use.  This may cause conflicts with the tools being used in the cleanup process.   

If you have questions regarding any of the instructions or problems running any tools, please let us know.

1.  Let's start with the router.  Did you change the default password?  See Malware Attacking Your Router.

2.  Let's flush your DNS cache and restore the HOSTS file.  Please copy/paste the lines in bold below to Notepad:

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop.
Double-click flush.bat file to run it. Your computer will reboot.

Note:  For Windows Vista or Windows 7, right-click flush.bat and select "Run as Administrator".

3.  Download DDS.scr by sUBs from one of the following links and save it to your desktop.
Link 1
Link 2
  • Double-Click dds.scr and a command window will appear. This is normal
  • Shortly after two logs will appear, DDS.txt & Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline mjduck

  • Newbie
  • *
  • Posts: 2
Re: malware possibly in router?
« Reply #2 on: April 04, 2011, 01:08:07 AM »
I did step 1-reading the article.  I did step 2 - flush the DNS cache.  I did 3, but it didn't produce any reports.  I went back to article, and then restored my router to factory settings.  Turns out I put a new router in and didn't change the password (from "password").  That's taken care of now, and the browser(s) seems to be working fine.  Thanks for your help, and I'll update if something starts going wacky again.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: malware possibly in router?
« Reply #3 on: April 04, 2011, 01:14:22 AM »
Hi, mjduck.

Since both you and your daughter's new laptop were being redirected, I suggest that you run an updated full-system anti-virus scan on all of the devices.  You may also want to scan with an updated anti-malware program, such as Malwarebytes' Anti-Malware. 

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.