You are viewing our Forum Archives. To view or take place in current topics click here.
Help! Nasty "Jackson.exe" Virus In Need Of Removal
Posted:

Help! Nasty "Jackson.exe" Virus In Need Of RemovalPosted:

NoSx1000
  • Challenger
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
Hey guys, I need your help getting rid of this virus. IT goes by the name of Jackson.exe. It lives in this directory: C:\ProgramData\Application Hosting. I'll remove it with AVG, then if I restart my PC, it's back. Sometimes it takes a few restarts, or even it will come back some time after my PC has turned on and signed into windows. I really want it gone. (Note: I am tech savvy, so don't be afraid to throw some technical terms at me, I'll understand). This is my gaming PC and I have lots of data on it that I don't want to download again. If I have to get rid of it, I will (format). I have looked it up and all the ways I see just look like ways to assist the virus.
#2. Posted:
ILikeYourHoots
  • Prospect
Status: Offline
Joined: Jun 20, 201113Year Member
Posts: 667
Reputation Power: 26
Status: Offline
Joined: Jun 20, 201113Year Member
Posts: 667
Reputation Power: 26
Go in to your task manager to do this manually, find the infected .exe in your details and or services section of task manager, right click it and open file location then go back to task manager, right click and end process tree and then within seconds of ending the tree, delete the entire infected file, if you leave any trace left, it can come back, so look in your .roaming, your users file, your program files(86) and program files regular, look through the common files on your program files as well(I have had a few that appeared in there, try to find every file that could be connected because this virus could have a secondary exe that reinstalls the virus every time you delete it so try to find what is causing that, after you found it all, find the exes on task manager, end process tree, and delete all the files linked to the virus, and restart pc to see if it deleted it, just make sure before you delete/end process tree check the name on google and see what it comes up with, generally it will tell you whether it is virus/Microsoft/needed on computer, if this doesn't work send me a message on ttg or add my Skype:ilikeyourhoots, I have done this many times before and can most likely help you fix it if this doesn't work, so just let me know
#3. Posted:
NoSx1000
  • Challenger
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
Thanks I will try all of this and reply if I run into any issues.
#4. Posted:
NoSx1000
  • Challenger
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
ILikeYourHoots wrote Go in to your task manager to do this manually, find the infected .exe in your details and or services section of task manager, right click it and open file location then go back to task manager, right click and end process tree and then within seconds of ending the tree, delete the entire infected file, if you leave any trace left, it can come back, so look in your .roaming, your users file, your program files(86) and program files regular, look through the common files on your program files as well(I have had a few that appeared in there, try to find every file that could be connected because this virus could have a secondary exe that reinstalls the virus every time you delete it so try to find what is causing that, after you found it all, find the exes on task manager, end process tree, and delete all the files linked to the virus, and restart pc to see if it deleted it, just make sure before you delete/end process tree check the name on google and see what it comes up with, generally it will tell you whether it is virus/Microsoft/needed on computer, if this doesn't work send me a message on ttg or add my Skype:ilikeyourhoots, I have done this many times before and can most likely help you fix it if this doesn't work, so just let me know


Okay, so I went into my AppData folder (the hidden one) and didn't even have to access roaming. I did and shredded some suspicious stoff with AVG, but in just the AppData folder there was some text document file with a bunch of Chinese characters that I instantly shredded with AVG. You helped, I didn't even think to look in other hidden folders besides ProgramData (That's where the nasty little thing kept appearing).
#5. Posted:
ILikeYourHoots
  • Prospect
Status: Offline
Joined: Jun 20, 201113Year Member
Posts: 667
Reputation Power: 26
Status: Offline
Joined: Jun 20, 201113Year Member
Posts: 667
Reputation Power: 26
NoSx1000 wrote
ILikeYourHoots wrote Go in to your task manager to do this manually, find the infected .exe in your details and or services section of task manager, right click it and open file location then go back to task manager, right click and end process tree and then within seconds of ending the tree, delete the entire infected file, if you leave any trace left, it can come back, so look in your .roaming, your users file, your program files(86) and program files regular, look through the common files on your program files as well(I have had a few that appeared in there, try to find every file that could be connected because this virus could have a secondary exe that reinstalls the virus every time you delete it so try to find what is causing that, after you found it all, find the exes on task manager, end process tree, and delete all the files linked to the virus, and restart pc to see if it deleted it, just make sure before you delete/end process tree check the name on google and see what it comes up with, generally it will tell you whether it is virus/Microsoft/needed on computer, if this doesn't work send me a message on ttg or add my Skype:ilikeyourhoots, I have done this many times before and can most likely help you fix it if this doesn't work, so just let me know


Okay, so I went into my AppData folder (the hidden one) and didn't even have to access roaming. I did and shredded some suspicious stoff with AVG, but in just the AppData folder there was some text document file with a bunch of Chinese characters that I instantly shredded with AVG. You helped, I didn't even think to look in other hidden folders besides ProgramData (That's where the nasty little thing kept appearing).

Yeah I found a virus running my task manager and couldn't pinpoint it, found out it was hiding in my appdata folder, if your cp doesn't seem like its better let me know.
#6. Posted:
AR15
  • 1000 Thanks
Status: Offline
Joined: Oct 24, 201113Year Member
Posts: 12,654
Reputation Power: 718
Status: Offline
Joined: Oct 24, 201113Year Member
Posts: 12,654
Reputation Power: 718
Download Malewarebytes and run a scan. When it finds the malware, let it end its' life and then restart the PC afterwords. When the PC restarts, open Malwarebytes again and scan again. Rinse and repeat the process until no issues are being found.

[ Register or Signin to view external links. ]



Malwarebytes runs a super deep scan on whatever HDD/SSD you run it on and in my case has defeated any viruses or anything I need gone on my PC without a hitch. Good luck.
#7. Posted:
Dan-
  • Summer 2018
Status: Offline
Joined: Sep 10, 201113Year Member
Posts: 1,910
Reputation Power: 1926
Status: Offline
Joined: Sep 10, 201113Year Member
Posts: 1,910
Reputation Power: 1926
I would highly advise reading through this reddit.

Very helpful guide to removing viruses/maleware.

[ Register or Signin to view external links. ]
#8. Posted:
vegeta508
  • Prospect
Status: Offline
Joined: Feb 13, 201014Year Member
Posts: 687
Reputation Power: 32
Status: Offline
Joined: Feb 13, 201014Year Member
Posts: 687
Reputation Power: 32
Thank me later.

[ Register or Signin to view external links. ]
#9. Posted:
NoSx1000
  • Challenger
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
Status: Offline
Joined: Jul 23, 201311Year Member
Posts: 166
Reputation Power: 8
I got rid of it using a program called Reason Core Security, thanks for all the help guys!
Jump to:
You are viewing our Forum Archives. To view or take place in current topics click here.