QUOTE(JohnLai @ Sep 30 2017, 02:36 PM)
Yes, I can confirm this, replacing the adsl router fixed it.
A simple reset for Innacomm modem will not solve it.....technically, resetting the Innacomm modem/router and reconfiguring it again will fix it....however, it get "re-infected" within 30 minutes to an hour the moment it connected to Internet.
In case you wanna know, remote management and other unnecessary services inside the modem/router are properly disabled. SPI firewall is enabled. No IPv6 is enabled. Password for both TMAdmin and TMUser are changed.
High probability it is either backdoor or some unknown vulnerability.....the fact is.....we have no idea how long our windows pc have been connected to that proxy server.
edit: grammar correction
That's why I changed my ADSL modem router when I first got it as the Innacomm modem/router is very unreliable and full of vulnerabilities. If you go to Shodan, TM routers, specifically the Dir-615, are the worse to be exploited as the DNS servers in that particular router are all totally compromised based on what I can see.A simple reset for Innacomm modem will not solve it.....technically, resetting the Innacomm modem/router and reconfiguring it again will fix it....however, it get "re-infected" within 30 minutes to an hour the moment it connected to Internet.
In case you wanna know, remote management and other unnecessary services inside the modem/router are properly disabled. SPI firewall is enabled. No IPv6 is enabled. Password for both TMAdmin and TMUser are changed.
High probability it is either backdoor or some unknown vulnerability.....the fact is.....we have no idea how long our windows pc have been connected to that proxy server.
edit: grammar correction
This post has been edited by SilentVampire: Sep 30 2017, 02:45 PM
Sep 30 2017, 02:45 PM

Quote
0.2926sec
0.57
7 queries
GZIP Disabled