PC Review


Reply
Thread Tools Rate Thread

What do I do-- JS/Downloader

 
 
MB_
Guest
Posts: n/a
 
      6th Mar 2008
My wife was doing something on the computer and an AVG window popped up
indicating some sort of virus.

She closed the window.

Immediately after that we ran AVG and it found
JS/Downloader
It is located in:

C:\Documents and Settings\My name\Local Settings\Temporary Internet
Files\Content.....

(I don't have the rest of the path; I will as soon as AVG finishes running).

If AVG says it can't heal it, can I delete it by clearing the cache?

If not, can I do this by going to DOS (command prompt)?

If not, any suggestions?

Mel



 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      6th Mar 2008
From: "MB_" <(E-Mail Removed)>

| My wife was doing something on the computer and an AVG window popped up
| indicating some sort of virus.
|
| She closed the window.
|
| Immediately after that we ran AVG and it found
| JS/Downloader
| It is located in:
|
| C:\Documents and Settings\My name\Local Settings\Temporary Internet
| Files\Content.....
|
| (I don't have the rest of the path; I will as soon as AVG finishes running).
|
| If AVG says it can't heal it, can I delete it by clearing the cache?
|
| If not, can I do this by going to DOS (command prompt)?
|
| If not, any suggestions?
|
| Mel
|

Yes, clear the TIF.

Please do provide the fully qualified name and path to the file in question.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
MZB
Guest
Posts: n/a
 
      6th Mar 2008
David:

C:\Documents and Settings\My name\Local Settings\Temporary Internet
> |
> Files\Content.IE5\OP6F01AF\Movie_%20midland%20movie%20theater%7CSpecial%....


Virus found: JS/Downloader.Agent

The file name was a bit longer than shown.

Is there any additional light you can shed on this? I assume this may be a
pop-up type trojan (for advertising)?

I did delete it

Mel


"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:lfZzj.11204$1_.2582@trnddc02...
> From: "MB_" <(E-Mail Removed)>
>
> | My wife was doing something on the computer and an AVG window popped up
> | indicating some sort of virus.
> |
> | She closed the window.
> |
> | Immediately after that we ran AVG and it found
> | JS/Downloader
> | It is located in:
> |
> | C:\Documents and Settings\My name\Local Settings\Temporary Internet
> | Files\Content.....
> |
> | (I don't have the rest of the path; I will as soon as AVG finishes
> running).
> |
> | If AVG says it can't heal it, can I delete it by clearing the cache?
> |
> | If not, can I do this by going to DOS (command prompt)?
> |
> | If not, any suggestions?
> |
> | Mel
> |
>
> Yes, clear the TIF.
>
> Please do provide the fully qualified name and path to the file in
> question.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      6th Mar 2008
From: "MZB" <(E-Mail Removed)>

| David:
|
| C:\Documents and Settings\My name\Local Settings\Temporary Internet
|>>
>> Files\Content.IE5\OP6F01AF\Movie_%20midland%20movie%20theater%7CSpecial%....

|
| Virus found: JS/Downloader.Agent
|
| The file name was a bit longer than shown.
|
| Is there any additional light you can shed on this? I assume this may be a
| pop-up type trojan (for advertising)?
|
| I did delete it
|
| Mel
|

You deleted it and did not post the fully qualified name and path to the file.

All I can conclude is this was a HTML file with a malicious Javascript.

If we still had the file ity could be submitted to Virus Total and we can then use the
report to obtain more information.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
Dennis
Guest
Posts: n/a
 
      6th Mar 2008
On Thu, 06 Mar 2008 23:31:44 GMT, "David H. Lipman"
<DLipman~nospam~@Verizon.Net> wrote:

>All I can conclude is this was a HTML file with a malicious Javascript.


In layman's terms, what kinds of "malicious" things can these scripts
do? Would the browser warn you in any way?

--

Dennis
 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      6th Mar 2008
From: "Dennis" <(E-Mail Removed)>

| On Thu, 06 Mar 2008 23:31:44 GMT, "David H. Lipman"
| <DLipman~nospam~@Verizon.Net> wrote:
|
>> All I can conclude is this was a HTML file with a malicious Javascript.

|
| In layman's terms, what kinds of "malicious" things can these scripts
| do? Would the browser warn you in any way?
|

No, no warning.

A perfect example would be an encrypted JavaScript that when decrypted uses an IFrame
Exploit to download a malware.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
Dennis
Guest
Posts: n/a
 
      7th Mar 2008
On Thu, 06 Mar 2008 23:51:04 GMT, "David H. Lipman"
<DLipman~nospam~@Verizon.Net> wrote:

>From: "Dennis" <(E-Mail Removed)>
>
>| On Thu, 06 Mar 2008 23:31:44 GMT, "David H. Lipman"
>| <DLipman~nospam~@Verizon.Net> wrote:
>|
>>> All I can conclude is this was a HTML file with a malicious Javascript.

>|
>| In layman's terms, what kinds of "malicious" things can these scripts
>| do? Would the browser warn you in any way?
>|
>
>No, no warning.
>
>A perfect example would be an encrypted JavaScript that when decrypted uses an IFrame
>Exploit to download a malware.


Will most anti-virus software prevent the script from being executed? In
the OPs case, it sounds like AVG recognized the script as malware (I
assume it somehow saw the HTML file being written to the browser's
cache). But is the horse already out of the barn at that point?

--

Dennis
 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      7th Mar 2008
From: "Dennis" <(E-Mail Removed)>


|
| Will most anti-virus software prevent the script from being executed? In
| the OPs case, it sounds like AVG recognized the script as malware (I
| assume it somehow saw the HTML file being written to the browser's
| cache). But is the horse already out of the barn at that point?
|

It will depend upon if the exploit is known and if the AV scanner can decrypt the
JavaScript.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Downloader.VB.AXO Dennis Anti-Virus 8 13th Feb 2008 10:17 PM
need best downloader =?Utf-8?B?YWZ0YWI=?= Windows Vista General Discussion 0 22nd May 2007 08:00 PM
downloader Starman Windows XP General 9 10th Dec 2004 07:05 AM
Downloader bronco7 Windows XP General 1 27th Dec 2003 03:37 AM
downloader-BR John Price Anti-Virus 2 27th Jul 2003 12:11 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:43 PM.