JS Downloader

Status
Not open for further replies.

helderberg

Posts: 6   +0
I have detected via AVG that I have a virus called JS Dowmnloader - can someone please help me to get rid of it.

Thank you
 
Hello, helderberg, and welcome to Techspot :wave:

Please take a moment to read the following threads to make your experience here as enjoyable as possible :)

Message for all newcomers

SNGX1275's Guide to making a good post/thread

The Techspot FAQ

If you could take a minute to fill in some of your profile information that would be helpful to all members of the forum :)
Knowing someone's location in the world can be extremely helpful, even if you just put a country.

Also remember to post any problems or questions that you have in the appropriate forums

With regards to your problem, please read this thread If your system is infected, read this before deciding whether to Clean or Format.

If you decide to clean your system, follow these instructions Virus/Spyware/Malware, preliminary removal instructions and post fresh HJT, Combofix, and AVG Antispyware logs as attachments to a new reply in this thread as well as the result of the Panda Antirootkit scan.


This thread is for the use of helderberg only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
1. Open the C:\Program Files\TrendMicro\HijackThis folder from MY Computer.
2. Rename the Hijackthis.exe file to Crusty.exe by right clicking the HijackThis.exe file and choose rename.
3. Type Crusty.exe and press the enter key.
4. Right click the Crusty.exe file and choose send to desktop(create shortcut).


This thread is for the use of helderberg only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
I get this far: C:\Program Files\TrendMicro\Hijack but then do not know where to get the Hijackthis.exe file to change to Crusty.exe

I know how to rename but the exe confuses me
 
When you get to the folder, there will be a file either called Hijackthis or Hijackthis_v2.

Right click this file and click rename, and type in the word Crusty, and press enter.


This thread is for the use of helderberg only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Hi,

I have posted you a further reply now that my laptop is able to communicate again - can you please respond to that
 
HI,

Sorry, I do not know whether my previous message got through to you, but I just want to mention that after my attempts to fix js downloader my laptop kond of block. Now I can work it again but it is very slow and AVG is still detecting the virus. I know I am not very bright with computers but I tried to do all the instructions you gave me without success. What should I do now.

Thanks
 
Follow the instructions again, if you read through all the instructions carefully, you should be ok.

Once you have finished the instructions and have a log for AVG Antispyware, Combofix and HijackThis and a result from the Panda AntiRootkit scan, and attach the logs to a new reply in this thread.

That last link shows you how to attach a log to a post in a thread, ignore the bit about getting a HJT log as you will already have one. Just follow the instructions for attaching the file.


This thread is for the use of helderberg only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
I am totally stuck - cannot open Ad- Aware, gives me this respond: 'Ad blocked here by SPF' - don't know what it means. Some of the other programmes I am suppose to download in 'safe mode' is just not possible. Can I call you to ask for help?
 
If you can't run Ad-Aware then don't worry about it, go onto the next step.

You can't download anything in Safe Mode because networking is disabled. Download the programs first (in normal mode) and then reboot the PC and run them in Safe Mode.
 
Status
Not open for further replies.
Back