Here's the full notice -> https://arstechnica.com/information-technology/2018/05/fbi-tells-router-users-to-reboot-now-to-kill-malware-infecting-500k-devices/

You can read what happened if you wish but just a r̴e̴b̴o̴o̴t̴ ̴a̴n̴d̴ ̴i̴t̴'̴s̴ ̴g̴a̴m̴e̴ ̴o̴v̴e̴r̴ ̴f̴o̴r̴ ̴t̴h̴i̴s̴ ̴m̴a̴l̴w̴a̴r̴e̴.̴

Update in new reply.

Dani AI

Generated

Following 's links, a short, practical addendum for anyone still sorting this out: the outbreak (VPNFilter) was a modular, potentially destructive infection of SOHO routers and some NAS devices, and law enforcement advised a temporary router reboot during the initial response. (blog.talosintelligence.com)

Concrete checklist (order matters):

  • Before you touch the device, record ISP/login details and, if possible, export the router configuration so you can restore necessary ISP/PPP settings later.
  • Isolate the router from the Internet (disconnect the WAN) before wiping it — investigators warned that parts of the malware can persist and re-download secondary stages if the network path remains open. (cisa.gov)
  • Do a full factory reset (hardware button or vendor UI), then reconfigure over a wired connection only. Use a long, unique admin password; disable remote administration, UPnP, WPS; and use the strongest Wi‑Fi encryption your hardware supports. These are standard hardening steps from federal guidance. (cisa.gov)

After you recover:

  • Check router DNS and DHCP settings for unexpected entries, review logs for unusual activity, and monitor local traffic for odd outbound connections. If a connected NAS (e.g., QNAP) is present, run the vendor’s malware scanner/remover and update NAS firmware/OS per the vendor advisory. If the vendor no longer supports the model, replace the device. (qnap.com)

Why this extra work matters: a single reboot was useful as a short disruption and to aid identification, but true remediation requires wiping persistent components and hardening the device to prevent reinfection. For technical writeups and vendor-specific steps, see the Talos writeup, the FBI/CISA advisories, and your router maker’s security bulletin. (blog.talosintelligence.com)

Turns out nothing is as simple as this. Updated information follows.

https://www.cnet.com/how-to/the-fbi-says-you-should-reboot-your-router-should-you/#

"Update, May 30 at 8:27 a.m.: According to the FBI's PSA regarding VPNFilter, the reboot recommendation is not intended to remove the malware, but rather to "temporarily disrupt [it] and aid the potential identification of infected devices." In other words, the FBI is enlisting you in a search-and-destroy operation. Needless to say, we recommend the aforementioned firmware update and factory reset if you own one of the affected router models."

Here's the current list of possibly affected models:
"Linksys: E1200, E2500, WRVS4400N
Mikrotik: 1016, 1036, 1072
Netgear: DGN2200, R6400, R7000, R8000, WNR1000, WNR2000
QNAP: TS251, S439 Pro, other QNAP NAS devices running QTS software
TP-Link: R600VPN"

This makes this a far more onerous task. About half the home users I know of will be able to update the router firmware. At least the affect models (the ones we know about) is on a short list. Read the article for the list of routers you really need to take care of.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.