• February 22, 2025, 10:16:18 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: DNS malware and resetting this puppy.  (Read 7818 times)

HedgeHocker

  • Level 1 Member
  • *
  • Posts: 20
DNS malware and resetting this puppy.
« on: February 11, 2009, 07:43:24 PM »

Hi,

I'm getting some flakey DNS server issues and suspect I have a malware alteration to my DIR-855 ...especially after Windows One the Safety Scanner found more evidence.  I wish I could remember where and what Safety Scanner found (online scanner) but it said it was a worm/trojan that altered router settings.  I deleted that file suspecting the find was just a false possitive.  I've since reformatted and installed Windows 7 Beta (7000) but from what I've read the changed that worm/trojan does to your router can remain until you reset it.... I have never reset this router and I don't know how really.

i have tried unplugging it and using a paperclip I depressed the reset in the back for about 10 seconds but after plussing things back up my old settings are still there.

Obviously I need to learn more about my router but can anyone comment to this kind of malware attack and more importantly tell me how to reset this g.d. thing so I don't worry while I try and Google it? Please.

TY
Logged
"The attatchment upload directory is not writeable."

HedgeHocker

  • Level 1 Member
  • *
  • Posts: 20
Re: DNS malware and resetting this puppy.
« Reply #1 on: February 16, 2009, 10:54:23 AM »

I did find the Reset - okay.

I still get errors connecting wirelessly. It stays once I get it connected though.  Maybe I have a hard to detect malware changing my settings somewhere.  I am running Windows 7 but it did the same thing for Windows Vista.
Logged
"The attatchment upload directory is not writeable."

vulkanbros

  • Level 2 Member
  • **
  • Posts: 52
Re: DNS malware and resetting this puppy.
« Reply #2 on: February 16, 2009, 01:37:37 PM »

I have never heard about malware/trojan/worm should be able to alter hardware settings in a router ??

It sounds more like a virus/trojan/malware in your OS.

Have you tried the scanner from www.malwarebytes.org or www.superantispyware.com

/Vulkan
« Last Edit: February 16, 2009, 11:45:24 PM by vulkanbros »
Logged
Product: DIR-655 - HW Version: A2 - FW Version: 1.33NAb01

Product: DAP-1522 - HW Version: A1 FW: 1.20

Product: DWA-643 - HW Version: A1 - FW Version: 2.0

Product: DWA-160 - HW Version: A1 - FW Version: 1.20 E

Product: DCS-1130 - HW Version:A1 - FW Version: 1.01

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: DNS malware and resetting this puppy.
« Reply #3 on: February 17, 2009, 09:21:41 AM »

Hi,

I'm getting some flakey DNS server issues and suspect I have a malware alteration to my DIR-855 ...especially after Windows One the Safety Scanner found more evidence.  I wish I could remember where and what Safety Scanner found (online scanner) but it said it was a worm/trojan that altered router settings.  I deleted that file suspecting the find was just a false possitive.  I've since reformatted and installed Windows 7 Beta (7000) but from what I've read the changed that worm/trojan does to your router can remain until you reset it.... I have never reset this router and I don't know how really.

i have tried unplugging it and using a paperclip I depressed the reset in the back for about 10 seconds but after plussing things back up my old settings are still there.

Obviously I need to learn more about my router but can anyone comment to this kind of malware attack and more importantly tell me how to reset this g.d. thing so I don't worry while I try and Google it? Please.

TY

Routes can only be manipulated when your OS is infected. The router has nothing to do with it, it only has  a passive role. Clean your PC from viri and malware and reset the TCPIP and Winsock settings to default (google for the tool to do so) and everything should be OK.
Logged
DIR-655 H/W: A2 FW: 1.33

HedgeHocker

  • Level 1 Member
  • *
  • Posts: 20
Re: DNS malware and resetting this puppy.
« Reply #4 on: February 18, 2009, 01:29:01 PM »

Okay. Thanks guys.  It was hard to imagine a router malware.
Logged
"The attatchment upload directory is not writeable."

smlunatick

  • Level 5 Member
  • *****
  • Posts: 625
Re: DNS malware and resetting this puppy.
« Reply #5 on: March 16, 2009, 01:42:10 PM »

Sometime last year, it was in the news that DNS services can have a major problem to cause bad results.  Several DNS providers were scrambling to fix this at the DNS server end.  Some seem that have not done this.  You might be able to fix your problem by trying OpenDNS, a free alternative to your ISP's DNS servers.
Logged

Azuse

  • Level 1 Member
  • *
  • Posts: 18
Re: DNS malware and resetting this puppy.
« Reply #6 on: March 26, 2009, 03:37:31 PM »

For the record, the psyb0t Worm exclusively infects routers, although it's limited to linux based ones currently it's only a matter of time before someone adapts it  :'( That said, swap to open dns (the fact that some isp still haven't fixed the vulnerability in their servers so long since detection should say alot about them as a company) and clean out the os and you should be good.
Logged