Author Topic: Banker removed - Iinternet access lost - *except via SafeZone browser*  (Read 6198 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I guess I should first reset 'Internet protocol version 4 (TCP/UPv4)' / 'Properties' to 'Obtain DNS server automatically'?

'biro' eh? That places you quite precisely (I am in Brazil).

REDACTED

  • Guest
Good guess or not, I did so and reset the router. Internet access with automatic DNS server duly restored and thank you sir.

I will give you a 24-hour follow-up status, just in case all the unseemly jubilation proves premature.

Thank you again. Essex rocks!
« Last Edit: June 13, 2016, 04:35:30 PM by pingo »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
The second computer having the same problem after I reset the DNS was the clue.  Let me know when you are happy

REDACTED

  • Guest
I never did get back because things settled only partly and temporarily. We're now back to a similar situation, but now Avast has reported an attack by HTML:Router CSRF-C. In telligent Scan reports no Virus, but does identify Network Problems (without specifying what they are). Boot-time Scan finds nothing. Whether or not this is a continuation of the previous problem, a new infection or a successfully averted attack, I have not been able to discover. In any case, all attempts to accesses banking sites from my wife's computer get redirected to phishing sites.
Really sorry if this sounds a lot like back to square one...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
What you need to do is reset the router and then change the router password so that it is not on default

If you let me know what make your router is I will get you the user name and password

REDACTED

  • Guest
Thank you, Essex, but I've done that. I am moderately computer literate, so set up the router myself originally. I now own the admin and network passwords (and they're 'strong').
Is that a satisfactory answer to your suggestion?
Should I go back to the beginning and run the anti-malware applications?
Should I start a new thread?

REDACTED

  • Guest
Update.
I finally lost all Internet access again and - long story short - an independent techie found my modem had been reconfigured (no-one here even knew how to access the modem). Instead of the provider's login and password, my wife's e-mail address and some asterisks. He restored the appropriate entries and access was restored.
Next morning, lost access again. This time I accessed the modem and, scanning through the entries (the changes made previously stood), was intrigued (as DNS server had been one of the problems identified by Windows network diagnostics) by "Manual DNS Server" and the two IPs entered. The technician was too, and suggested replacing them with Google (8.8.8.8 and 8.8.4.4), which restored access. All hunky-dory to date - including apparently clean bank access.
I then googled with the two IP addresses, which turn out to be hosted in the Russian Republic.
That is, my modem had been reconfigured somehow to two Russian DNS Server IPs.
Go figure.
« Last Edit: July 29, 2016, 05:55:02 PM by pingo »

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
hey pingo have you tried to reset your routher witch essexboy suggested? if not please do so. second im quessing esexboy is on holyday with all right :) but if he comes online later today agian i suggest you run a fresh scan with frst+addation and attach them here so he have something new to look at.
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM