• April 25, 2024, 05:21:41 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!  (Read 7173 times)

DIR645

  • Level 1 Member
  • *
  • Posts: 3
VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« on: May 13, 2016, 05:49:00 PM »

Hi,
sth really strange did just happen:

I own a DLINK DIR 645, Version A1, FW 1.06.

Set-up:   I have a cable modem (internet) and this is connected to the router's internet-port on its backside.
Everything worked fine until some hours ago:
I tried to log on to the router with my Admin password (tried it about 20 times and it said that the pw would be incorrect). Finally, i left the Admin-pw-field empty and I was able to login.  I am definitely sure that I did not perform a factory reset or sth like that (that is proved by the fact that only the Admin pw seems to be reseted to default and the protocols have been deleted (first entries I see in the logs are the ca. 20 failed logons where I tried to use my personal Admin pw which used to work until like 1 hour ago)

The only thing I changed on the setup today was to unplug the router from the internet (plugged out the ethernet cable that connected my cable modem and the router) in order to connect my PS4 directly to my cable modem for the reason that I had several internet disconnects (or wlan interferences) so that it was quite impossible to play GTA V online on the  PS4.

When I quitted my GTAV online session like 1 hour ago I repluged the ethernetcable from the modem to the internet port of the router and restarted the router and the modem.


Summary:

- Admin PW has been reseted (I did not perform a factory reset)
- Old Router logs / protocols have been deleted  (now they start about 1 hour ago with the failed logins)
- everything else (MAC filter, SSID; wlan pw etc. stayed as they have been before


Is there any logical explanation for having that issue besides a trojan / router has been hacked / virus or sth?


Thank you in advance

Excuse my poor English, Im a native German speaker.
« Last Edit: May 13, 2016, 05:57:45 PM by DIR645 »
Logged

DIR645

  • Level 1 Member
  • *
  • Posts: 3
Re: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« Reply #1 on: May 14, 2016, 02:04:07 AM »

So am I the first one who is experiencing this issue? :/
Is there a way to see who / what changed the Admin pw of the router and deleted the logs?
Logged

RYAT3

  • Level 10 Member
  • *****
  • Posts: 2254
Re: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« Reply #2 on: May 14, 2016, 06:20:57 PM »

So am I the first one who is experiencing this issue? :/
Is there a way to see who / what changed the Admin pw of the router and deleted the logs?

This is really bizarre.  Has it happened again?

It sounds like something of a reset or power cycle happened.

Computers use little coin LithIon batteries (1.5v?) that go bad after years.... but usually the computer is dead after 6 years, so it never really gets replaced. I don't think routers use these.

How long have you had the router? 

Maybe unplug it again for an hour or so and see if it resets everything again?

Logged

RYAT3

  • Level 10 Member
  • *****
  • Posts: 2254
Re: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« Reply #3 on: May 14, 2016, 07:38:45 PM »

Have you read this post?   :o

http://forums.dlink.com/index.php?topic=56366.0

Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« Reply #4 on: May 14, 2016, 08:42:22 PM »

Link>Welcome!

  • What region are you located?
  • Has a Factory Reset been performed?
  • Was a Factory Reset performed before and after any firmware updates then set up from scratch?
  Link> >FW Update Process
  • Was the router working before any firmware updates?

Internet Service Provider and Modem Configurations
  • What ISP Service do you have? Cable or DSL?
  • What ISP Modem Mfr. and model # do you have?

PC Web Browser Configurations
What browser are you using?
Try Opera or FF? If IE 8, 9, 10 or 11, set compatibility mode and test again.

Hi,
sth really strange did just happen:

I own a DLINK DIR 645, Version A1, FW 1.06.

Set-up:   I have a cable modem (internet) and this is connected to the router's internet-port on its backside.
Everything worked fine until some hours ago:
I tried to log on to the router with my Admin password (tried it about 20 times and it said that the pw would be incorrect). Finally, i left the Admin-pw-field empty and I was able to login.  I am definitely sure that I did not perform a factory reset or sth like that (that is proved by the fact that only the Admin pw seems to be reseted to default and the protocols have been deleted (first entries I see in the logs are the ca. 20 failed logons where I tried to use my personal Admin pw which used to work until like 1 hour ago)

The only thing I changed on the setup today was to unplug the router from the internet (plugged out the ethernet cable that connected my cable modem and the router) in order to connect my PS4 directly to my cable modem for the reason that I had several internet disconnects (or wlan interferences) so that it was quite impossible to play GTA V online on the  PS4.

When I quitted my GTAV online session like 1 hour ago I repluged the ethernetcable from the modem to the internet port of the router and restarted the router and the modem.


Summary:

- Admin PW has been reseted (I did not perform a factory reset)
- Old Router logs / protocols have been deleted  (now they start about 1 hour ago with the failed logins)
- everything else (MAC filter, SSID; wlan pw etc. stayed as they have been before


Is there any logical explanation for having that issue besides a trojan / router has been hacked / virus or sth?


Thank you in advance

Excuse my poor English, Im a native German speaker.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

DIR645

  • Level 1 Member
  • *
  • Posts: 3
Re: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« Reply #5 on: May 16, 2016, 12:07:29 PM »

Hi Ryat, thanks for your answer.

I had read the post you mentioned before I started my thread. I started my own thread because the problem discussed in the thread you linked sounds similar but still different to my specific issue.

Yesterday I tried to reproduce the issue and did exactly the same thing that i had done before the issue became present (unplugged the modem from the router and connected the modem directly with my PS4, played online for some hours and then replugged and restarted everything)
This time only the protocols / logs were deleted, but not the Admin password.

Your presumption concerning the "batteries"  sounds plausible to me, I think the router is about 5 years old, could be 4 or 6 as well, though.

 ???
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« Reply #6 on: May 16, 2016, 12:56:57 PM »

Please give feed back and details on the questions presented.

I also have this router and have not experienced this particular issue.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VIRUS/ TROJAN ? DIR 645 RESETS ADMIN PW and PROTOCOLS!
« Reply #7 on: May 20, 2016, 07:34:33 AM »

Any status on this?
 ???
Hi Ryat, thanks for your answer.

I had read the post you mentioned before I started my thread. I started my own thread because the problem discussed in the thread you linked sounds similar but still different to my specific issue.

Yesterday I tried to reproduce the issue and did exactly the same thing that i had done before the issue became present (unplugged the modem from the router and connected the modem directly with my PS4, played online for some hours and then replugged and restarted everything)
This time only the protocols / logs were deleted, but not the Admin password.

Your presumption concerning the "batteries"  sounds plausible to me, I think the router is about 5 years old, could be 4 or 6 as well, though.

 ???
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.