We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

how do I remove this malware?

ObfuscatorJM and Zbot.gen!Y

MSE keeps detecting them and quarantining them but each time I restart it detects them again.
«1345

Comments

  • 23n1th
    23n1th Posts: 1,523 Forumite
    I would advise doing the usual MBAM scan after updating of course and posting the log, thereafter running HJT and posting its log here as well.
  • spaceboy
    spaceboy Posts: 1,933 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    23n1th wrote: »
    I would advise doing the usual MBAM scan after updating of course and posting the log, thereafter running HJT and posting its log here as well.

    Is MBAM free?
  • aerostar
    aerostar Posts: 1,738 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    yes it is, do a google
  • 23n1th
    23n1th Posts: 1,523 Forumite
    Yep download from here: http://www.malwarebytes.org/mbam.php

    Looks like you're infected from your post in the other thread. Run MBAM and post its log which will pop up at the end here and re-run HJT and post its log as well.
  • fiddiwebb
    fiddiwebb Posts: 1,806 Forumite
    spaceboy wrote: »
    Is MBAM free?

    The free version is.

    Download the latest version of Malwarebytes from filehippo.com.

    Once downloaded, open mbam and update it first before running a scan.
  • Donnie
    Donnie Posts: 9,862 Forumite
    It going to be a bit more complicated than that. You have a password stealing Trojan. Even when you remove it, the changes that it makes are not reversed.

    So you can try to remove it and then manually reset any changes, or just back up your data and run a Factory Restore or a Clean Install.

    Use a Sandbox in the future if you going to expose yourself to risks, as they can also have Sandboxed browsers too.
  • Donnie
    Donnie Posts: 9,862 Forumite
    If you want to go ahead with some scans....

    Download, install, update and run a Quick Scan with Malwarebytes' AntiMalware. When complete, choose 'Remove Selected' if there is anything to remove and Reboot your computer.

    After restart, open the program again and go to 'Logs'. Double click on the log produced for today and post the contents here.

    Then download, install and run Hitman Pro 3.5.

    Next, download, install and run the HijackThis Version 2.0.4 installerand executable and use the Quick Start guide to enable you to produce a log for posting here too.

    I'm not sure how effective these will be.

    You may need a rootkit remover.
  • Donnie
    Donnie Posts: 9,862 Forumite
    More details here

    Have you run a Full Scan with MSE?
  • 23n1th
    23n1th Posts: 1,523 Forumite
    If its as bad as Donnie thinks it is and you want to save the install rather than a clean install then I'd recommend going to a forum like: http://www.geekstogo.com/forum/ they've very good trained experts at this sort of thing.
  • Donnie
    Donnie Posts: 9,862 Forumite
    We can remove it here, but I'm going to bed now. The OP can decide which path he wants to traverse. There are lots of tools out there with which to play. But a format and clean install gives peace of mind.

    A hijack this log may assist in diagnosing possible security holes to watch for in the future.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.7K Mortgages, Homes & Bills
  • 177.4K Life & Family
  • 258.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.