Author Topic: Router infected (DNS hijack) - is it fixed now?  (Read 1820 times)

0 Members and 1 Guest are viewing this topic.

Offline globit

  • Newbie
  • *
  • Posts: 1
Router infected (DNS hijack) - is it fixed now?
« on: June 09, 2020, 08:29:05 PM »
I ran an Avast scan and it said first that my device (laptop) had been DNS hijacked, and then that my router was infected. I tried to follow the instructions to fix my router, but unfortunately Avast doesn't have instructions for the router I have (virgin media) and I couldn't figure out what to do on the virgin media router page. Instead, I did change some DNS by going into control panel -> network and sharing centre -> properties of my wifi connection -> TCP/IPv4 and changing the DNS server address to be obtained automatically - does doing this fix the router's DNS settings, or does this only make sure my laptop is safe without actually fixing the router?

To be safe (since I don't know whether what I did is enough or whether I definitely have to change the settings on the virgin media router page), I got Avast premium so I now have the Secure DNS feature. But I have essentially the same question about Secure DNS - does it just protect my laptop, or does it somehow fix the router?

Also, is there any way to determine how my DNS settings got changed in the first place? Could I have been infected with something through my laptop and it spread to the router, or would the router have had to be targeted directly? Avast found no malware on my laptop, but I just wonder if it was because of my laptop somehow because of an incident I had on youtube a couple months back; oddly this one youtube video seemed to be infected with something (I was thinking maybe an ad was infected?) as Avast kept appearing with "Threat secured" "We've safely aborted connection on www.youtube.com because it was infected with JS:ScriptPE-Inf [Trj]". I don't know what that means but could it have something to do with this DNS hijacking?

As you can see, I'm very confused about this whole thing so any help would be hugely appreciated! :)

Offline r@vast

  • Avast team
  • Massive Poster
  • *
  • Posts: 2761
Re: Router infected (DNS hijack) - is it fixed now?
« Reply #1 on: June 10, 2020, 11:58:29 AM »
Hi,

This might be a false positive.
Virgin provides a type of family protection which can sometimes be classified as DNS hijacking
https://community.virginmedia.com/t5/Networking-and-WiFi/Antivirus-said-my-DNS-is-hijacked/td-p/4047261 (edited)
https://community.virginmedia.com/t5/Security-matters/Avast-says-DNS-queries-on-your-device-have-been-hijacked/td-p/4230668
Are you using "Web Safe"? If so, could you try disabling it temporarily and scan the network thereafter: https://www.virginmedia.com/help/how-to-use-websafe

Concerning the issue of the script. The detection on YouTube.com was unrelated to the DNS issue. Some YouTube videos contain a description that may contain suspicious scripts. This was probably the case here and Avast blocked these scripts so that they could not cause any harm.