Forums
Posted By: Anonymous VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 10:40am
What is this, M security ess, just popped up saying this, i have now removed it, but what is it
Posted By: ex0__ Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 10:56am
It's a signature for a piece of malware that's obfuscating (hiding, basically) another piece of malware.

Reboot to safe mode (restart the machine and spam f8) and do a full scan with malwarebytes and then mse. Make sure you install nad update malwarebytes before you go to safe mode.
Posted By: Anonymous Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 12:07pm
Thank you, all done, it found 6 in total
Posted By: Nelzy84 Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 12:14pm
Scare Ware had two on our network in past two weeks, one on an office lap top and one this morning on a desktop MS Safeworks, just rolled back PC's to last safe restore point job was a goodun,

Laptop needed a bit more work as virus was starting on start up and couldn't be isolated in TM before startup, ended up backing everything up on machine and just re installing windows,

Pain in the backside, find aload of made up virus's and then charge you to use their software to remove their shite grrrr
Posted By: ex0__ Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 12:33pm
Yeah it's called rogue antivirus. And you shouldn't ever think that rolling back to a 'safe restore' fixes problems like that.

In fact you should turn off restores, they are a haven for hiding rootkits.

On the other hand formatting the machine is definitely the best way to be sure that you're safe smile
Posted By: Nelzy84 Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 2:16pm
Good Call Ex, always sensible to run something like registry mechanic to check for malicious exe's and cleverly disguised Sys32 files.

Had one a month or two back that had rougue csrss files in registry had to sweep through them and pick out the non microsoft ones, If all else fails, good old Format, although always best to take a back up of any drivers on the system using driver magician or something similar and the same with the data learnt that the hard way as an appentice bench technician countless hours spent looking for random drivers for obscure chipsets frown

Posted By: TheDr Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 2:56pm
Originally Posted by Nelzy84
... as an appentice bench technician countless hours spent looking for random drivers for obscure chipsets frown


You'd be amazed how many hours are STILL spent by <ahem> "certain people" when they either forget back up drivers or the machine is so corrupt (or drive so dead) that you can't do it.

I have lost count of the number of hours (even in the last few months) that certain people (who work in a certain shop that have their wages paid by a certain me) have spent looking for obscure drivers for the MODEM !!!! Does ANYONE use them anymore ? laugh
Posted By: ex0__ Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 4:26pm
Nearly drove myself nuts trying to find drivers for a PCI serial card a few months ago.

That said if the laptop is anything from the last decade there will be drivers on the manufacturer's website.
Posted By: TheDr Re: VIirus: virTool:JS/Obfuscator.BN - 21st Jun 2011 5:29pm
Originally Posted by ex0__
..... if the laptop is anything from the last decade there will be drivers on the manufacturer's website.


If you spot the tiny link above the menu on the Packard Bell site which says "see old site" (or something similar) and THAT has all the drivers for anything that wasn't sold last week.....grrrr
Posted By: rocks Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 2:32pm
hi my free avg has just found 2 js/obfuscator viruses and there now in the vault, iv never had this before so do i click the button to empty vault or just leave them there?
answer in english please as i dont understand anything of the above haha
Posted By: diggingdeeper Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 2:36pm
It doesn't really matter - they are in a safe place but you might as well delete them, you have no use for them.
Posted By: ex0__ Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 3:10pm
Originally Posted by rocks
hi my free avg


/heavy sigh.
Posted By: rocks Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 3:13pm
Originally Posted by ex0__
Originally Posted by rocks
hi my free avg


/heavy sigh.

leave me alone ex0 lol laugh
Posted By: rocks Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 3:13pm
Originally Posted by diggingdeeper
It doesn't really matter - they are in a safe place but you might as well delete them, you have no use for them.

thanx DD wink
Posted By: Nelzy84 Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 3:22pm
Originally Posted by TheDr
Originally Posted by Nelzy84
... as an appentice bench technician countless hours spent looking for random drivers for obscure chipsets frown


You'd be amazed how many hours are STILL spent by <ahem> "certain people" when they either forget back up drivers or the machine is so corrupt (or drive so dead) that you can't do it.

I have lost count of the number of hours (even in the last few months) that certain people (who work in a certain shop that have their wages paid by a certain me) have spent looking for obscure drivers for the MODEM !!!! Does ANYONE use them anymore ? laugh


Hahaha good stuff doctor and very true, i wander whether i've known you in a previous life, does the surname Chung "chungy" ring any bells smile ?
Posted By: Nelzy84 Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 3:24pm
Originally Posted by ex0__
Nearly drove myself nuts trying to find drivers for a PCI serial card a few months ago.

That said if the laptop is anything from the last decade there will be drivers on the manufacturer's website.


Ball ache isn't it mate, a while back a laptop lan port stopped working so brought a usb - lan dongle came with a driver disk etc.

Had to upgrade vista to 7 prof to get it to talk to the exchange server in process back all drivers up. Since booting into 7 everything works fine bar the driver for the dongle. The driver i'd backed up was for Vista and has compatability issues with 7, even when you think you've covered all bases they can still stich you up lol, hate them !
Posted By: TheDr Re: VIirus: virTool:JS/Obfuscator.BN - 22nd Jun 2011 11:51pm
I've got some Win7 compatible USB - Lan convertors if you need one.
© Wirral-Wikiwirral