We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

help please! pc re-directing online banking to dodgy site

zzzLazyDaisy
zzzLazyDaisy Posts: 12,497 Forumite
Part of the Furniture Combo Breaker
edited 7 June 2010 at 1:22PM in Techie Stuff
Hi, I lent my laptop to my sister and it came back with LOTS of malaware on it.

With help from the techies yesterday I have cleaned it up and it appears to be running clear BUT when I attempt to go to my on-line banking it is taking me to a dodgy website that looks just like my bank's website, but is asking me for lots of personal info. I have spoken to my bank and they have confirmed that it is not their website, and I have also accessed on-line banking with my other pc with no problems.

I have run a full scan on MacAfee, and also on Malawarebytes this morning, both are clear.

Any advice would be welcome

EDIT to add that I am using firefox

Thanks

Daisy
I'm a retired employment solicitor. Hopefully some of my comments might be useful, but they are only my opinion and not intended as legal advice.
«1345

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Hi, I lent my laptop to my sister and it came back with LOTS of malaware on it.

    According to your other thread, it only found one!
    "C:\Windows\Tasks\MSWD-1a2d42fe.job (Trojan.DNSChanger) -> Quarantined and deleted successfully."

    What are you referring to when you say 'lots'?

    Download HostsXpert
    http://www.softpedia.com/progDownload/Hoster-Download-27041.html
    and then follow the below steps.

    * Unzip HostsXpert.zip
    * It will create a folder named HostsXpert in whatever folder you extract it to.
    * Run HostsXpert.exe by double clicking on it.
    * click the Make Writeable? button.
    * click Restore Microsoft's Hosts File and then click OK.
    * Click the X to exit the program


    .......................................................................



    Download HIJACK THIS (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_hijackthis/
    Click MAIN MENU then DO A SYSTEM SCAN AND SAVE A LOGFILE(Takes seconds) then post the log so we can see whats running
    (do NOT do anything else with Hijack but scan and post the FULL log)
    :idea:
  • zzzLazyDaisy
    zzzLazyDaisy Posts: 12,497 Forumite
    Part of the Furniture Combo Breaker
    edited 7 June 2010 at 2:38PM
    Hi, yes by the time I came to MSE I had already scanned with McAfee, Ad-aware, spybot, and iobit 360 security, and they had got rid of most of the stuff, including three trojans, some viruses, and a keylogger.

    Then on the advice of MSE'rs I ran Malawarebytes and it only found one, which was deleted.

    But I am still having problems, there is clearly still something left on my system as when I try to use on-line banking it is re-directing me to this dodgy website which is asking me for personal details.

    I'll follow your instructions now, thanks

    EDIT - I don't know if this is related, but there is a windows update (sp3?) which needs downloading, but when I try, it fails.
    I'm a retired employment solicitor. Hopefully some of my comments might be useful, but they are only my opinion and not intended as legal advice.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Dont attempt ANY updates until the systems clean
    :idea:
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    And please get rid of McAfee, that's probably how you are infected in the first plece. Try Kaspersky. If your bank is Barclays, it's free. If not, try Avira, Avast or Microsoft Essentials.
    Make sure you run the McAfee removal tool after uninstalling.
    No free lunch, and no free laptop ;)
  • zzzLazyDaisy
    zzzLazyDaisy Posts: 12,497 Forumite
    Part of the Furniture Combo Breaker
    Okay, please be gentle, I am obviously doing something wrong...

    I did what you said, but Hijack this said that my system has denied access to the host file. Also when I did the scan it wouldn't let me create a log.

    Can you talk me through it again please?

    Sorry
    I'm a retired employment solicitor. Hopefully some of my comments might be useful, but they are only my opinion and not intended as legal advice.
  • Lokolo
    Lokolo Posts: 20,861 Forumite
    Part of the Furniture 10,000 Posts
    Instead of double clicking the hijack icon to load. Right click and Run As Administrator.
  • zzzLazyDaisy
    zzzLazyDaisy Posts: 12,497 Forumite
    Part of the Furniture Combo Breaker
    edited 7 June 2010 at 3:27PM
    when I right click the icon, there isn't a 'run as administrator' option :(

    Edit just a thought - I am running windows 7, does that make a difference?

    I have just run Highjackthis again, it does the scan, brings up lots of info but then brings up notebook which says

    'cannot find the c:/program files/trend micro/hijackthis/hijackthis.log file do you want to create a new file?'

    (its actually backward slash but I can't find that on my keyboard)
    I'm a retired employment solicitor. Hopefully some of my comments might be useful, but they are only my opinion and not intended as legal advice.
  • tarden
    tarden Posts: 41 Forumite
    Part of the Furniture Combo Breaker
    It should be there directly under 'Open' and say run as...
    which leads you to another window where you enter who you want to run the program as - in this case 'administrator'
  • Lokolo
    Lokolo Posts: 20,861 Forumite
    Part of the Furniture 10,000 Posts
    You want to say yes to that file creation I think!
  • zzzLazyDaisy
    zzzLazyDaisy Posts: 12,497 Forumite
    Part of the Furniture Combo Breaker
    Okay, when I right click it says 'open', 'open file folder (f), trouble shoot compatibility.

    There is nothing that says 'run as'

    Also I clicked yes to the question 'do you want to create a new file' and it just brought up a blank screen....
    I'm a retired employment solicitor. Hopefully some of my comments might be useful, but they are only my opinion and not intended as legal advice.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.