I will go just to 6.37.5 witch is know to be fixed, and you will have no problem with the Bridge changes.
We just change our winbox port to something else besides default. We do this with everything.
So to log in to the new port in winbox ip:new port
And flush firewall connections or reboot router.
Chek first post for updated info …
Can you answer 2 items for the FAQ:
- Is there a simple test to know if a router is infected?
- Upgrading to 6.37.5+ cures an infection or it only prevents infection?
done
And a FAQ entry about webfig from https (www-ssl) may be reasonable.
I’m intrigued - those posts look like you’re running ps on the mikrotik - hos do you get a ‘proper’ shell / bash connection?
Or are they grabs from something like a sysinfo file?
David
we have a RouterOS v6.38.5 router that has been hacked today and deleted to the default settings. Also via the winbox port … We think there is a circular second exploit that works in a similar way to this.
It is not related to this topic. You probably had an easy to guess password.
These are leftover files. They don’t do anything. This is not the program itself, only some remaining things it created. You can delete those if you like, but the device is no longer “infected” as you say
maybe our problem in the following address could be related to this topic.
http://forum.mikrotik.com/t/lost-connection-to-multiple-lhg-units/117662/1
I have seen these from last Friday. I saw anything below 3.38.5 is compromised. Also i have seen 6.39.2 and below in series is affected. I have not seen anything from 6.39.3 and above which is compromised
I upgrade most of the routers to 6.41.3. Not seeing any problem in 6.41.3
@Normis
How “random12” user could show us results of “ps”, “ls” etc … Is he cracking his own router or uses some Mikrotik’s debug/special module?
Simple question: How?
There exists a special NPK package that you can install and gain access to shell. This is not public. This user must have gotten it from MikroTik support. Sometimes this package is installed by MikroTik support when debuging a live installation, but is usually removed. Don’t ask, we will not share it ![]()
Not possible. Maybe you had another router behind that one, then you would see some traffic as if it was coming from this one.
Really? How can you understand it? What’s inside this “/rw/info” file?
What’s about those “/ram/.info” processes that is currently running in memory?

This screen clearly shows me version 6.40.5 (that is not vulnerable as you say us) with “/rw/info” and “/ram/.info” processes in memory.
Are you telling me that it’s all safe now?
I know about the “special” module … not asking “for” … just asking “how” ![]()
(post Removed as others have answered my question)
You are right, this is some other tool. We fixed this one in v6.41 only. This is why upgrading to LATEST version is important. Your scanner has been stopped, but the .info process was not deleted. Upgrade to LATEST should fix also that one.