How JustAnswer Works:

  • Ask an Expert
    Experts are full of valuable knowledge and are ready to help with any question. Credentials confirmed by a Fortune 500 verification firm.
  • Get a Professional Answer
    Via email, text message, or notification as you wait on our site.
    Ask follow up questions if you need to.
  • 100% Satisfaction Guarantee
    Rate the answer you receive.

Ask lifesaver Your Own Question

lifesaver, Computer Software Engineer
Category: Computer
Satisfied Customers: 5962
Experience:  Engineering degree in Computer science,Microsoft Certified Professional.JA computer expert.
Type Your Computer Question Here...
lifesaver is online now
A new question is answered every 9 seconds

How do I get rid of a virus called JS/Redir that keeps being

Customer Question

How do I get rid of a virus called JS/Redir that keeps being detected in daily anti-virus scans?

I am using Windows XP , AVG Internet Security 9.0 and also have Ad-Aware on system.

Location of virus is always similar, today's example:
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\{11D3928E-8517-49F1-A845-7924C382021A}\chrome\content\overlay.xul

As I say, the daily scheduled scan always detects this but if I run a specific scan on C:\Documents and Settings nothing is found. Ad-Aware finds nothing.

I upgraded from AVG Free Edition to try to deal with this problem which has been around for a few weeks now. AVG Tech Support asked for some diagnostic scans but after a couple of unsuccessful attempts at producing the results they desired, AVG seems to have abandoned me. I need some advice please (and as I am not a techno type please write in plain language, thanks)!
Submitted: 5 years ago.
Category: Computer
Expert:  lifesaver replied 5 years ago.

FOllow these steps to turn system restore on C drive.

  1. Click Start, right-click My Computer, and then click Properties.
  2. In the System Properties dialog box, click the System Restore tab.
  3. Click on C drive to select the Turn off System Restore check box.
  4. Click OK.
After system restore is turned off run AVg scan and remove infections it detects.

Next Download and run this free scanner called Malwarebytes' Anti-Malware from Here

Remove infections it detects

Restart and let me know the results.
lifesaver, Computer Software Engineer
Category: Computer
Satisfied Customers: 5962
Experience: Engineering degree in Computer science,Microsoft Certified Professional.JA computer expert.
lifesaver and 3 other Computer Specialists are ready to help you
Customer: replied 5 years ago.

Hi PC Mechanic,


24 hours after your help, I'm not sure whether virus problem is solved yet or not.


Regards XXXXX XXXXX System Restore on C Drive, I found a box checked stating "system restore turned off on all drives." So System Restore was already turned off on C drive.


I ran AVG which detected JS/Redir virus.


Then downloaded/ran malware scanner which found virus ("C:\Documents and Settings\HP_Owner\Local Settings\Temp\d.exe (Trojan.Dropper) -> Quarantined and deleted successfully"). System restarted, then turned off for night.


Turning on in morning., ran AVG full scan - no virus detected


System ran a scheduled AVG full scan at 5pm - found JS/Redir virus ("C:\Documents and Settings\HP_Owner\Local Settings\Application Data\{C93C3468-7FFC-4ED3-80CE-374722FD8A2A}\chrome\content\overlay.xul";"Virus found JS/Redir";"Moved to Virus Vault")


Ran malware scanner immediately afterwards - no virus detected.




Expert:  lifesaver replied 5 years ago.

Download and run trozan remover.

Don't purchase.use the 30 day trial.Let me know th results/
Customer: replied 5 years ago.

Results :


Installed Trojan Remover this morning and ran it(with AVG program disabled). Result: "No active malicious files were found and no changes were made."


At 5pm AVG program ran scheduled daily full scan : virus found "C:\Documents and Settings\HP_Owner\Local Settings\Application Data\{B675BC47-7B82-4794-BC57-377089FB14ED}\chrome\content\overlay.xul";"Virus found JS/Redir";"Moved to Virus Vault"


Then ran Trojan Remover again : "No active malicious files were found and no changes were made."

Then ran Anti-Malware scanner: "No malicious items detected."

I will pay extra after this reply because I appreciate you are doing this for a fee.



Expert:  lifesaver replied 5 years ago.
Please run these two tools.


2>Combofix.Download link and guide

LEt me know the results.PASte the log combofix creates.

Customer: replied 5 years ago.


Attached is ComboFixLog


I have the ComboFix log ready but the text is too long to paste in this box. I need a way of attaching a file - customer service has not answered my query how to do so.


Earlier I posted a bonus but I can't tell whether this has gone to the right place.


My 5pm AVG full scan (still running) indicates virus is still there.

Expert:  lifesaver replied 5 years ago.

Check the combofix log under other deletions.









c:\windows\system32\Drivers\atapi.sys . . . is infected!!


One of your drivers is infected too..Also when a virus is in recycler it keeps returniong back.


Please recheck that your system restore is turned off.Also let me know your system model..

Customer: replied 5 years ago.

System Restore was turned on when I just checked it (was not when I previously checked). I have now checked the box which turns off System Restore on all drives (TELL ME IF THIS IS NOT RIGHT).


System model general info:


Hewlett-Packard Pavilion AMD athlon(tm)XP3200+ , 2.20 GHz, 448MB of RAM

(hp pavilion a720n)


Microsoft Windows XP Home Edition 2002 Service Pack 3

Expert:  lifesaver replied 5 years ago.

Your system info is correct.


Now check this link on how to determine if system restore is turned on or off.


Now i want you do all the cleaning with system restore turned off and in safe mode.


How to access safe mode?


Simply restart and keep pressing F8 key before windows starts loading.Run all those antivirus tools again.

Customer: replied 5 years ago.

Please clarify -when you say all those antivirus tools again, do you mean all four you have so far specified or just the last two ? So far have used anti-malware, trojan remover,smitfraudfix and combofix. And all in safe mode?

Expert:  lifesaver replied 5 years ago.
Yes all the four in safe mode..
Customer: replied 5 years ago.

I ran the four tools again in the same order under the conditions which you specified.


Here is the combofix report: ComboFixLog2

Expert:  lifesaver replied 5 years ago.



Does the virus still return back?

Customer: replied 5 years ago.

The last two scheduled AVG full scans have been clean, so it looks very hopeful. I guess if those scans continue to be clean then the virus has been removed. May I de-install any of the software used?


The cleaning process seems to have had one adverse result in that DVDs and CDs are no longer autmatically detected and I no longer have a pop up box offering a choice of programs to play the disks. The dvd and CD drives do work and appear on the Device Manager menu but I have to go directly to the media files and open them in order to play a disk. If I can't work out how to put this right I will probably be back to this website to post a second question.


In the meantime I thank you very much for your time and advice and wish you a Happy Thanksgiving (if you are in the USA that is!)



Expert:  lifesaver replied 5 years ago.

Yes you can remove all other softwaes used.


Just keep AVG.


If youa re using AVG paid version ignore my next message.Else if youa re using AVG 9 free edition get a new antivirus porotection like bitdefender or Kapersky


Now regarding the Cd drives.Are they detected under My computer?

Customer: replied 5 years ago.
Yes, they are both detected when I go to the device managers tab and there are no error codes when I check the device status. I can play disks but only if I open the files directly, computer does not automatically detect them anymore.
Expert:  lifesaver replied 5 years ago.
  • In Device Manager, expland DVD/CD-ROM drives, right-click the CD and DVD devices, and then click Uninstall.
  • When you are prompted to confirm that you want to remove the device, click OK.
  • Restart the computer.
  • After the computer restarts, the drivers will be automatically installed.


    See if it helps.

    JustAnswer in the News:

    Ask-a-doc Web sites: If you've got a quick question, you can try to get an answer from sites that say they have various specialists on hand to give quick answers... seen a spike since October in legal questions from readers about layoffs, unemployment and severance.
    Web sites like
    ...leave nothing to chance.
    Traffic on JustAnswer rose 14 percent...and had nearly 400,000 page views in 30 days...inquiries related to stress, high blood pressure, drinking and heart pain jumped 33 percent.
    Tory Johnson, GMA Workplace Contributor, discusses work-from-home jobs, such as JustAnswer in which verified Experts answer people’s questions.
    I will tell you that...the things you have to go through to be an Expert are quite rigorous.

    What Customers are Saying:

    • My Expert answered my question promptly and he resolved the issue totally. This is a great service. I am so glad I found it I will definitely use the service again if needed. One Happy Customer New York
    < Last | Next >
    • My Expert answered my question promptly and he resolved the issue totally. This is a great service. I am so glad I found it I will definitely use the service again if needed. One Happy Customer New York
    • I am very happy with my very fast response. Eric is very knowledgeable in the subject area. Thank you! RP Austin, TX
    • Hi John, Thank you for your expertise and, more important, for your kindness because they make me, almost, look forward to my next computer problem. After the next problem comes, I'll be delighted to correspond again with you. I'm told that I excel at programing. But system administration has never been one of my talents. So it's great to have an expert to rely on when the computer decides to stump me. God bless, Bill Bill M. Schenectady, New York
    • The Expert answered my Mac question and was patient. He answered in a thorough and timely manner, keeping the response on a level that could understand. Thank you! Frank Canada
    • Wonderful service, prompt, efficient, and accurate. Couldn't have asked for more. I cannot thank you enough for your help. Mary C. Freshfield, Liverpool, UK
    • This expert is wonderful. They truly know what they are talking about, and they actually care about you. They really helped put my nerves at ease. Thank you so much!!!! Alex Los Angeles, CA
    • Thank you for all your help. It is nice to know that this service is here for people like myself, who need answers fast and are not sure who to consult. GP Hesperia, CA

    Meet The Experts:

    • Andy

      Computer Consultant

      Satisfied Customers:

      11yr exp, Comp Engg, Internet expert, Web developer, SEO
    < Last | Next >
    • Andy's Avatar


      Computer Consultant

      Satisfied Customers:

      11yr exp, Comp Engg, Internet expert, Web developer, SEO
    • James's Avatar


      Sr. Computer Support Expert

      Satisfied Customers:

      20 years of experience building, fixing and servicing PCs and operating systems.
    • Engineer John C.'s Avatar

      Engineer John C.

      Computer Science Engineer

      Satisfied Customers:

      Computer Science Engineer with 10 years of experience in Computer Support, and Microsoft, A+ and Cisco certified
    • RPI Solutions's Avatar

      RPI Solutions

      Support Specialist

      Satisfied Customers:

      5+ Years in IT, BS in Computer Science
    • Ryan H.'s Avatar

      Ryan H.

      Computer Support Specialist

      Satisfied Customers:

      A+ Certified Technician - 10 Years experience working with all types of computer systems.
    • Jane Lefler's Avatar

      Jane Lefler

      Sr Prog Analyst / Technician

      Satisfied Customers:

      Computer Programmer / Technician/ Consultant 16+ years
    • B. Rath's Avatar

      B. Rath

      IT Professional

      Satisfied Customers:

      Certified support for tech-related issues, including computers, email and software.
    Chat Now With A Tech Support Specialist
    4288 Satisfied Customers
    Engineering degree in Computer science,Microsoft Certified Professional.JA computer expert.