Pharming Infection

Associate
Joined
7 Jun 2011
Posts
1,649
Evening All

I just wanted to see if anyone has had a similar issue to myself and if anyone had a fix for it.

On Wednesday I logged onto my online bank as usual, everything seemed 100% legitimate, the site security certificates all seemed 100% fine, BUT the password entry box asked for my full password instead of specific characters.

Now it really did concern me, and I closed down my browser, went back to entering the bank address perfectly again...checked the padlock up at the top and certificates were correct and entered my password.

Low and behold somebody the next day logged onto my bank and took every penny from my bank account and savings.

Luckily my bank restored all my funds very quickly and shutdown my online access....a big lesson learnt.

Anyway before they will restore my web access back, they need to know that my PC is 100% clean.

I had MS Security Essentials before; I ran a scan which found 1 "virus" (Java exploit)....I then bought and downloaded Norton Internet Security.....the scan ran and found 36 cookies....but no real viruses.....my bank then asked me to run Trend Micro online Homesafe Scan, which found nothing.

After all that I return back to my internet banking screen only to find the "Pharming Software" is still asking for a full password.

Running Malware Bytes found 2 more bits of Malicious software and removed them, but the Pharming Software remains and I'm not sure what to do...bar flattening my PC....which I REALLY don't want to do.

Have any of you encountered this and managed to fix it?

Thanks for any help.
 
never heard of it . Personally I would use a paid all in one like ESET security suite ( about £25 for the full years licence and see what that throws up. )

Also what browser you using ? Maybe run firefox with ghostery and or noscript and see if problem remains
 
Yeah I have...Firefox doesn't seem to have the issue.

I just paid £25 for Norton Internet Security Suite.

Just been reading about Pharming and its quite alarming....sometimes it can log into your router and redirect all your traffic through the hackers site while they pick up all your personal data and Virus scanners wont pick it up as its no longer a virus.
 
TDSS didn't find anything.

As you can see....it looks 100% genuine and the certificates match....BUT its asking me for my full password and that shouldn't happen.

fakelogin.png
 
Last edited:
Back
Top Bottom