We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Internet problem- have I got a virus?

Just wondering if anyone can help..

since yesterday whenever i type something into google and click on the link I want, instead of taking me to the right website it will take me to either ebay or some random site.

Im not sure whats happened and its getting pretty annoying now!

Anyone have any ideas?

Thanks
Stay at home mum and blogger who loves to earn money online! :)
«1345

Comments

  • Sounds like some kind of virus.

    Go to malwarebytes[dot]org and download and run the free version. Thats assuming you can get to a site by typing in a URL.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    As well as the above. Download this and save it to your desktop. It should give an indication of what you are infected with.

    http://public.avast.com/~gmerek/aswMBR.exe

    When you've downloaded it...
    • Double click aswMBR.exe to run it (XP), or right click & choose "Run as Administrator" (Vista, Win7)
    • Click yes to the prompt to download Avast! virus definitions.
    • Set the AVscan to Quick Scan, & click the Scan button.
    • When the scan reports "Scan finished successfully", click Save log & save the log to your desktop.
    • Click OK when prompted. aswMBR.txt & MBR.dat will be appear on your desktop.
    • Click EXIT.
    • Copy & paste the contents of aswMBR.txt & post it here.
    Don't click to fix anything yet, just post the log.
  • Thanks for the replies. Im currently downloading what has been suggested although my internet is very slow so might take a while!
    Stay at home mum and blogger who loves to earn money online! :)
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Post the logs - I'll be back to work shortly (till later), but someone else should be able to take a look.
  • Ive finished downloading malwarebytes and ran a scan and it came up with 8 objects found which look like trojans? Do I just click on remove selected?
    Stay at home mum and blogger who loves to earn money online! :)
  • charlishae wrote: »
    Ive finished downloading malwarebytes and ran a scan and it came up with 8 objects found which look like trojans? Do I just click on remove selected?
    Yes , and post the log here too
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy

    CEC Email energyclub@moneysavingexpert.com
  • Thanks,

    Malwarebytes Anti-Malware 1.60.0.1800
    www.malwarebytes.org

    12/01/2012 14:40:41
    mbam-log-2012-01-12 (14-40-41).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 179527
    Time elapsed: 5 minute(s), 47 second(s)
    Memory Processes Detected: 2
    C:\Users\charli\AppData\Roaming\Zekyq\sydaaf.exe (Trojan.FakeAlert) -> 3744 -> Delete on reboot.
    C:\Windows\Temp\qenwgp\setup.exe (Trojan.Downloader.CBCGen) -> 5360 -> Delete on reboot.
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 1
    HKLM\SYSTEM\CurrentControlSet\Services\AMService (Trojan.Downloader.CBCGen) -> Quarantined and deleted successfully.
    Registry Values Detected: 1
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{4288F4CB-00B7-494C-5B82-7C0641FE8C99} (Trojan.FakeAlert) -> Data: C:\Users\charli\AppData\Roaming\Zekyq\sydaaf.exe -> Quarantined and deleted successfully.
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 4
    C:\Users\charli\AppData\Roaming\Zekyq\sydaaf.exe (Trojan.FakeAlert) -> Delete on reboot.
    C:\Windows\Temp\qenwgp\setup.exe (Trojan.Downloader.CBCGen) -> Delete on reboot.
    C:\Users\charli\AppData\Local\Temp\0.7519360182385341golda.exe (Trojan.Downloader.bh) -> Quarantined and deleted successfully.
    C:\Users\charli\AppData\Local\Temp\0.8576161118596953fdrgs.exe (Trojan.Downloader.bh) -> Quarantined and deleted successfully.
    (end)
    Stay at home mum and blogger who loves to earn money online! :)
  • closed
    closed Posts: 10,886 Forumite
    reboot, then do a full malwarebytes scan (not quick)

    and post a hijackthis log
    !!
    > . !!!! ----> .
  • closed wrote: »
    reboot, then do a full malwarebytes scan (not quick)

    and post a hijackthis log

    I rebooted after the quick scan and the problem is still there. Will try that thanks.
    Stay at home mum and blogger who loves to earn money online! :)
  • Anybody have the website url for hijackthis? Cant search for it with this problem
    Stay at home mum and blogger who loves to earn money online! :)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.6K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.7K Work, Benefits & Business
  • 603.2K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.