One final issue...cant remove malicious script "system[1].exe.js"

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Larium, Sep 7, 2004.

  1. Larium

    Larium Private E-2

    I posted this in an older thread but it seems to have been overlooked.

    I finally got rid of About Blank and Coolwebsearch but I have one issue that remains....

    Cant remove the malicious script that my Hijackthis log identifies as:

    04- Startup: system[1].exe.js

    While running Hijackthis I check the box to fix but the program fails to remove it.

    Norton Antivirus also identifies this script as malicious when I boot up but it only gives me the option of "stopping" and nothing else.

    Any suggestions?

    Thanks ahead of time for any replies,
    Larium
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there a process running with this name? Use Task Manager to find out.
    If so, see if you can end it. Then delete the line in HJT and find the file and delete it.
     
  3. Larium

    Larium Private E-2

    This script running in processes? Not that I can see, unless its running under a different name.

    Heres exactly what the Norton Anti Virus script blocker says in regards to this script on startup:

    Object- FileSystemObject
    Activity- GetFile
    File- C:\Documents a...\system[1]exe.js


    And like I mentioned earlier it appears as "04- Startup system[1]exe.js" in my Hijackthislog.


    Im not sure if this has anything to do with it and I dont know why Norton would identify McAffee as malicious but I originally had McAffee anti-virus installed on this computer when I bought it, and for reasons I cant remember I tried to uninstall all of it but could only do some of it (even after calling McAffee and listening to their asenine reply that I "was going to have a difficult time trying to unistall their software").


    Thanks ahead of time for any replies,
    Larium
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have enabled viewing of hidden files and folder: http://forums.majorgeeks.com/showthread.php?t=37650

    Then boot in safe mode and fixing that line in HijackThis and then go to your c:\documents and settings folder and try to locate the file that Norton gave you an incompleter path of (its under one of your user names somewhere):
    C:\Documents a...\system[1]exe.js

    When located, delete it.
     
  5. Larium

    Larium Private E-2

    Got it.

    Thanks again.

    Larium
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ??? Does that mean you fix it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds