I think I solved it. Thanks all :)


My router: Asus RT-N66U

Every connected computer will occasionally get a message saying something like "Adobe is out of date, download new here".

No virus on my PC itself. The link goes to a site called "download.freesoftwarelive.com" which only says "OK". The direct link will download a file which is recognized as a virus by https://www.virustotal.com/ by a large margin. I have disabled uPnP. No cloud was ever enabled. Firewall enabled. I had a factory reset and set up my internet anew ... nope, still here. Anyone got some advice? I blocked download.freesoftwarelive.com at least, so that no family member downloads this shit.

9 years ago*

Comment has been collapsed.

...What? Routers can get viruses...?

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago*
Permalink

Comment has been collapsed.

is that flu?

9 years ago
Permalink

Comment has been collapsed.

try dr web cureit

9 years ago
Permalink

Comment has been collapsed.

It might be an infected computer in your network? Check all of the connected laptops.

9 years ago
Permalink

Comment has been collapsed.

It COULD be. I will look into it.

9 years ago
Permalink

Comment has been collapsed.

Wait, it can't be that.

Mine is the only PC connected to 5ghz. Others are to 2,4. These two channels are separated with own passwords. Still all get the same pop-up. My PC is not infected with anything.

9 years ago
Permalink

Comment has been collapsed.

That seems odd. Take the router out of the equation and directly hook a computer up to the modem and see what happens then.

9 years ago
Permalink

Comment has been collapsed.

Factory reset and all its gone.

Edit: well u did it, then u dont have virus in your router.

9 years ago
Permalink

Comment has been collapsed.

Nope. Still there.

9 years ago
Permalink

Comment has been collapsed.

How exactly did you do it?

9 years ago
Permalink

Comment has been collapsed.

http://192.168.1.1/ -> reset factory

9 years ago
Permalink

Comment has been collapsed.

9 years ago
Permalink

Comment has been collapsed.

Do not forget to run the installer after downloading.

lel.

9 years ago
Permalink

Comment has been collapsed.

Can you provide more details, what events trigger the popup message? Does it appear on the browser or win app?

9 years ago
Permalink

Comment has been collapsed.

No app anywhere. Same homepage at EVERY computer. But ONLY ONCE. Then it doesn't pop up anymore.

9 years ago
Permalink

Comment has been collapsed.

What is the dns server config on the router?

9 years ago
Permalink

Comment has been collapsed.

Trying to find it right now!

9 years ago
Permalink

Comment has been collapsed.

Have you ever changed router's password? I'm not talking about Wi-fi.

9 years ago
Permalink

Comment has been collapsed.

It has no own password. You log in with the Wi-Fi one. I changed that.

9 years ago
Permalink

Comment has been collapsed.

Have you updated the firmware on your router recently? If not update to the latest as this fixes existing vulnerability. I know they patched several security vulnerabilities recently.

9 years ago
Permalink

Comment has been collapsed.

I did patch it :)

Still there.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

this doesnt seem like a router virus but a pc virus, maybe you installed some software in all the computers withing same network (I prefer to not imagine such thing as router virus even exist for now xD)
I already fixed a pc with a virus called "YAC" which there was no way to uninstall, this virus changed browser homepage and settings so it was impossible to browse the internet, it was not detected by a anti-virus but in most cases it can be fixed with a anti-malware
if a anti-malware cant detect and fix the problem you have to do it manually by finding the process that is causing this and get his location on the disk, restart pc and start windows in safe mode and delete the files
if is indeed a router virus you might wanna get serious help in this :s

ps:. this reminds me that you could always just start your computer and safe mode and check if still happens, please prove me that router virus do not exist :D

9 years ago*
Permalink

Comment has been collapsed.

Hello.

I didn't touch my mothers/fathers/sisters computer. Now all of them get this message, at the same time. Router viruses are real, and it makes only sense. Even my PC - I didn't visit ANYTHING out of the ordinary. Reddit for comments, Steam ... I was gone most of the day and didn't download or do anything. Soooo.

9 years ago
Permalink

Comment has been collapsed.

well, if there is indeed a virus on your router you might wanna know that someone within your network installed it and you might want to start cheking the computers that are connect by cable (if there is any)

9 years ago
Permalink

Comment has been collapsed.

It's more likely you are in a local network and it simply spread. If somebody would really hijack your router, you wouldn't get a simple scamware virus but more likely a hijack one demanding money.
Just run an antivirus, or if you have free ones, get Malwarebytes Anti-Malware. The free edition can wipe anything (it cannot auto-protect system, that is they paid edition), and it's a good program that works well with any installed antivirus.

9 years ago
Permalink

Comment has been collapsed.

You can try custom firmware, DD-Wrt is a good choose, since OpenWRT doenst support your routher model.

9 years ago
Permalink

Comment has been collapsed.

I do not think it is in your router,i think it is well hidden on your pc and whoever connects to it,it sends that crap out or is some how tied to the ip so it shows up for anyone using it.

Be careful of even trusted programs from trusted sites as they may not have a virus but sometimes they have bloat that can install stuff like that to help pay for it being free.If they are trusted they should allow you to not install anything but what you want,If they are not trust then they usually install stuff without you knowing.

Maybe you did that as i did it once to try a free version of a program before i decided to buy it and the free one came with bloatware but i forgot to check not to install it and got infected like you did and it also hijacked Firefox and Chrome.

https://www.malwarebytes.org/lp/lp4/02_r/?gclid=CJPH2oKLusQCFQYIaQodpL4AXw
.

You may think it is not infected but it is,just because you nothing is picked up does not mean nothing is there as it is a cat and mouse game.

Try malwarebytes and see what happens.

You can also download the latest firmware for the router and reinstall it, usually a factory reset just sets it back to how it came from the factory it pretty much just reverts all settings and changes.

Goodluck

9 years ago*
Permalink

Comment has been collapsed.

Every PC that connects gets the virus? I would like to know what master mind virus that is.

9 years ago
Permalink

Comment has been collapsed.

9 years ago
Permalink

Comment has been collapsed.

I can't help with your virus, and for that I am truly sorry. Although I do have a Pixel Puzzle: Japan game key for Steam: 56DDK-XZ9IH-LXBR4 I wish you all the luck with defeating that virus.

9 years ago
Permalink

Comment has been collapsed.

Closed 9 years ago by ThirdSketch.