Infected router - Google search redirects even on a clean system

AID: 5327
  • Status: Published

22016 points

  • Byrpggamergirl
  • TypeGeneral
  • Posted on2011-05-02 at 04:35:00
Awards
  • Community Pick
  • Experts Exchange Approved
  • Editor's Choice
If your system is showing symptoms of browser hijacks or 'google search redirects' check out my other article first and run the tool TDSSKiller to get rid of the infection.

Once done, and if the PC seems to be clean but the redirect has not stopped, or in cases where you have just reformatted your system yet also showing the symptoms - then this article is for you, read on.


Router infections:

This infection has been doing its rounds for a while now; there were many PCs infected last year and currently it is still going as seen here. While it only needs to infect one PC in the network and affect all systems which share the same router; it's not surprising that a newly reformatted PC could also show the same symptom.


How does it get into the system:

Much like the Smitfraud family of infection, the Zlob/DNS changer trojans often trick the user by masquerading as a video codec to download. When they are in, these trojans check for wired and wireless hardware router. Once known that a router is being used, it guesses the router’s password by consulting a built-in list of routers with default username and password. Once it has access to the router it then changes the DNS settings, hence called DNS Changer trojans.

However, if the user had changed the default username and password for the router, these trojans will not be able to change DNS settings. That is why it is very important to create your own password and username when using one. Unlike wareout infection(mentioned in another article), this one does not show any entries in the HijackThis log.


The Fix:

Scan the system with your favorite scanner, e.g., MalwareBytes will handle this infection nicely.
Once every PC had been cleaned, you then reset the router to its default configuration. To do this, just insert a tip of a paper clip, or the tip of a cake skewer into a small hole labeled “reset” which is on the back of the router. Press and hold for about ten to 15 seconds. The router’s light should go Off and On again.
Note that if there are other zlob-infected PCs sharing the same router, they need to be cleaned before resetting the router, otherwise the Trojan will simply go back and change DNS settings again.

If needed, you can find most router’s default password on this link, http://www.phenoelit-us.org/dpl/dpl.html.

Also check out this video tutorials on how to configure your router’s security settings, http://www.onguardonline.gov/topics/wireless-security.aspx

There is a new variant of TDL4 rootkit recently that is undetectable by TDSSKiller so if the issue lingers on it could be that the Master Boot Record has been modified and you would need to run “Fixmbr” command from the Recovery Console to fix it.
If you have scanned with TDSSKiller, you had reset the router but the redirects have not stopped then post a question at Virus & Spyware zone and we will be there to give you some assistance.

Hope you find this article helpful.
Asked On
2011-05-02 at 04:35:00ID5327
Tags

google search redirects

,

infected router

Topic

Windows XP Operating System

Views
3898

Comments

Expert Comment

by: younghv on 2011-05-02 at 04:53:10ID: 26159

rpggamergirl,
Thank you for putting together this Article.
We have seen so much of this problem over the past few weeks and I think this will help a lot of our Members.

"Yes" vote above.

younghv

Expert Comment

by: MASQUERAID on 2011-05-02 at 04:59:02ID: 26160

And from me - amazing how many people forget to take the simple precaution of adding a password to their router.   Perhaps now they know a virus can do this they may take more care about their security.

Thanks for this.

Author Comment

by: rpggamergirl on 2011-05-02 at 05:21:45ID: 26163

younghv, masqueraid,
Thanks for voting 'Yes' :)

Expert Comment

by: SSharma on 2011-05-02 at 11:08:24ID: 26170

@younghv,

Good article indeed.

Sudeep

Expert Comment

by: SSharma on 2011-05-02 at 11:09:23ID: 26171

Sorry I mean "rpggamergirl" to thanks, but I got the link from one of post from Younghv.

So thanks to both of you.

Author Comment

by: rpggamergirl on 2011-05-04 at 06:32:21ID: 26194

Thanks SSharma.... and thanks to you too younghv for pointing them here.

Expert Comment

by: Steve-Seese on 2011-05-12 at 08:17:33ID: 27234

I have been researching and struggling with this problem for over a month now and this has been the only thing that has helped. I downloaded the Zip, unzipped and ran the exe, then voila! Fixed the issue. Fantastic I tell ya, fantastic!

Expert Comment

by: Jonvee on 2011-06-24 at 12:31:03ID: 29097

This document nicely complements your "Google Hijack" article.   Thanks again.

Voted "Yes" above.

Author Comment

by: rpggamergirl on 2011-06-24 at 20:04:14ID: 29109

Steve-Seese,
Glad to know that this article has been helpful to you, thanks for the yes vote.

Jonvee,
Thanks for voting Yes.
Please use any of my article links in your posts when you see fit, thanks.

Expert Comment

by: Guillermin-go on 2011-07-04 at 11:29:21ID: 29442

Interesting article.

I´m not famous, but voted yes ^^

Author Comment

by: rpggamergirl on 2011-07-04 at 17:57:38ID: 29449

"I´m not famous,"

Neither am I, :)
Thanks for commenting and for voting Yes, I appreciate it :)

Expert Comment

by: Jsmply on 2011-07-07 at 13:07:49ID: 29558

As always, RPG's advice and article was very helpful and informative.  Thanks RPG!

Expert Comment

by: mbizup on 2011-07-30 at 12:00:37ID: 30181

Voted yes

Author Comment

by: rpggamergirl on 2011-08-02 at 04:56:11ID: 30222

Jsmply, Mbizup,

Thank you for voting Yes!

Expert Comment

by: Jsmply on 2011-08-02 at 15:25:40ID: 30237

Your welcome RPG, but actually we should be thanking you.  =)

Author Comment

by: rpggamergirl on 2011-08-02 at 22:52:40ID: 30246

@ Jsmply,

Your feedbacks on questions and continued support to my articles are what motivate me, and I am very grateful. :)

Expert Comment

by: Jsmply on 2011-08-03 at 10:32:40ID: 30275

Glad to hear it, we have said many times that access to RPG alone is worth the price of EE!

Add your Comment

Please Sign up or Log in to comment on this article.

Join Experts Exchange Today

Gain Access to all our Tech Resources

Get personalized answers

Ask unlimited questions

Access Proven Solutions

Search 3.2 million solutions

Read In-Depth How-To Guides

1000+ articles, demos, & tips

Watch Step by Step Tutorials

Learn direct from top tech pros

And Much More!

Your complete tech resource

See Plans and Pricing

30-day free trial. Register in 60 seconds.

Loading Advertisement...

Top Windows XP Experts

  1. nobus

    109,514

    Master

    0 points yesterday

    Profile
    Rank: Savant
  2. MASQUERAID

    86,680

    Master

    498 points yesterday

    Profile
    Rank: Genius
  3. flubbster

    83,880

    Master

    2,000 points yesterday

    Profile
    Rank: Genius
  4. thinkpads_user

    44,689

    1,500 points yesterday

    Profile
    Rank: Genius
  5. BillDL

    43,868

    0 points yesterday

    Profile
    Rank: Genius
  6. Run5k

    41,750

    0 points yesterday

    Profile
    Rank: Genius
  7. Darr247

    38,180

    0 points yesterday

    Profile
    Rank: Genius
  8. SSharma

    36,782

    0 points yesterday

    Profile
    Rank: Genius
  9. ve3ofa

    34,109

    0 points yesterday

    Profile
    Rank: Genius
  10. cwstad2

    32,527

    0 points yesterday

    Profile
    Rank: Guru
  11. motnahp00

    29,474

    3,000 points yesterday

    Profile
    Rank: Sage
  12. DTHConsulting

    28,336

    0 points yesterday

    Profile
    Rank: Guru
  13. Anuroopsundd

    26,827

    2,000 points yesterday

    Profile
    Rank: Sage
  14. hanccocka

    26,512

    0 points yesterday

    Profile
    Rank: Genius
  15. arnold

    26,147

    0 points yesterday

    Profile
    Rank: Genius
  16. KCTS

    25,512

    0 points yesterday

    Profile
    Rank: Genius
  17. l33tf0b

    22,780

    0 points yesterday

    Profile
    Rank: Wizard
  18. rindi

    22,108

    0 points yesterday

    Profile
    Rank: Savant
  19. dstewartjr

    21,650

    0 points yesterday

    Profile
    Rank: Genius
  20. Callandor

    21,288

    0 points yesterday

    Profile
    Rank: Genius
  21. DaveBaldwin

    21,060

    0 points yesterday

    Profile
    Rank: Genius
  22. leew

    20,982

    0 points yesterday

    Profile
    Rank: Savant
  23. garycase

    20,824

    0 points yesterday

    Profile
    Rank: Genius
  24. rpggamergirl

    20,432

    10 points yesterday

    Profile
    Rank: Genius
  25. jcimarron

    19,748

    0 points yesterday

    Profile
    Rank: Genius

Hall Of Fame