How to remove Trojan:JS/Medfos.B malware (Virus Removal Guide)

Trojan:JS/Medfos.B is a malicious JavaScript file that redirects search queries when using websites such as AOL, Ask, Bing, Google and Yahoo to other website from which cyber criminals get some sort of revenue.
Medfos is a member of the Win32/Medfos family and got your computer, after you have visited an infected website which exploited a vulnerability from a Java or Adobe software and Medfos installed a file called chromeupdate.crx in your %LOCALAPPDATA% folder.

As part of its self-defense mechanism,once installed Medfos disguises itself as a legitimate Google Chrome or Firefox extension with the name ChromeUpdateManager 1.0 or Translate This 2.0, as show in the below images:

Trojan:JS/Medfos.B sole purpose is to generate revenue for its authors via pay-per-click advertising links and redirect traffic to affiliate sites, so we recommend that you remove this Trojan as soon as possible from your computer.

Files reported as Trojan:JS/Medfos.B may not necessarily be malicious. Should you be uncertain as to whether a file has been reported correctly, you can submit the affected file to https://www.virustotal.com/en/ to be scanned with multiple antivirus engines.
You should always pay attention when installing software because often, a software installer includes optional installs. Be very careful what you agree to install.
Always opt for the custom installation and deselect anything that is not familiar, especially optional software that you never wanted to download and install in the first place. It goes without saying that you should not install software that you don’t trust.

How to remove Trojan:JS/Medfos.B virus (Virus Removal Guide)

This malware removal guide may appear overwhelming due to the amount of the steps and numerous programs that are being used. We have only written it this way to provide clear, detailed, and easy to understand instructions that anyone can use to remove malware for free.
Please perform all the steps in the correct order. If you have any questions or doubt at any point, STOP and ask for our assistance.

STEP 1: Use Zemana AntiMalware Portable to remove malware

Zemana AntiMalware Portable is a free utility that will scan your computer for the Trojan:JS/Medfos.B browser hijacker and other malicious programs.

  1. You can download Zemana AntiMalware Portable from the below link:
    ZEMANA ANTIMALWARE PORTABLE DOWNLOAD LINK (This link will open a new web page from where you can download “Zemana AntiMalware Portable”)
  2. Double-click on the file named “Zemana.AntiMalware.Portable” to perform a system scan with Zemana AntiMalware Free.
    Zemana AntiMalware portable
    You may be presented with a User Account Control dialog asking you if you want to run this program. If this happens, you should click “Yes” to allow Zemana AntiMalware to run.
    Zemana AntiMalware User Account Control
  3. When Zemana AntiMalware will start, click on the “Scan” button to perform a system scan.
    Zemana AntiMalware Free Scan
  4. Zemana AntiMalware will now scan your computer for malicious programs. This process can take up to 10 minutes.
    Zemana AntiMalware scanning for virus
  5. When Zemana has finished finished scanning it will show a screen that displays any malware that has been detected. To remove all the malicious files, click on the “Next” button.
    Zemana AntiMalware Removing Trojan:JS/Medfos.B Virus
    Zemana AntiMalware will now start to remove all the malicious programs from your computer. When the process is complete, you can close Zemana AntiMalware and continue with the rest of the instructions.

STEP 2: Scan and clean your computer with Malwarebytes Anti-Malware

Malwarebytes Anti-Malware is a powerful on-demand scanner which should remove the Trojan:JS/Medfos.B virus from your machine. It is important to note that Malwarebytes Anti-Malware will run alongside antivirus software without conflicts.

  1. You can download download Malwarebytes Anti-Malware from the below link.
    MALWAREBYTES ANTI-MALWARE DOWNLOAD LINK (This link open a new page from where you can download “Malwarebytes Anti-Malware”)
  2. When Malwarebytes has finished downloading, double-click on the “mb3-setup-consumer” file to install Malwarebytes Anti-Malware on your computer.
    Malwarebytes installer
    You may be presented with an User Account Control pop-up asking if you want to allow Malwarebytes to make changes to your device. If this happens, you should click “Yes” to continue with the installation.
    Malwarebytes User Account Control Prompt
  3. When the Malwarebytes installation begins, you will see the Malwarebytes Setup Wizard which will guide you through the installation process.
    Setup Malwarebytes installer
    To install Malwarebytes Anti-Malware on your machine, keep following the prompts by clicking the “Next” button.
    Completing the Malwarebytes Setup Wizard
  4. Once installed, Malwarebytes will automatically start and update the antivirus database. To start a system scan you can click on the “Scan Now” button.
    Perform a system scan with Malwarebytes
  5. Malwarebytes Anti-Malware will now start scanning your computer for malicious programs.
    This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Malwarebytes scanning for malware
  6. When the scan has completed, you will be presented with a screen showing the malware infections that Malwarebytes Anti-Malware has detected.
    To remove the malicious programs that Malwarebytes has found, click on the “Quarantine Selected” button.
    Malwarebytes Quarantine Selected
  7. Malwarebytes Anti-Malware will now quarantine all the malicious files and registry keys that it has found.
    To complete the malware removal process, Malwarebytes may ask you to restart your computer.
    Malwarebytes removing malware from computer
    When the malware removal process is complete, you can close Malwarebytes Anti-Malware and continue with the rest of the instructions.

STEP 3: Double-check for malicious programs with HitmanPro

HitmanPro can find and remove malware, adware, bots, and other threats that even the best antivirus suite can oftentimes miss. HitmanPro is designed to run alongside your antivirus suite, firewall, and other security tools.

  1. You can download HitmanPro from the below link:
    HITMANPRO DOWNLOAD LINK (This link will open a new web page from where you can download “HitmanPro”)
  2. When HitmanPro has finished downloading, double-click on the “hitmanpro” file to install this program on your computer.
    HitmanPro icon
    You may be presented with an User Account Control pop-up asking if you want to allow HitmanPro to make changes to your device. If this happens, you should click “Yes” to continue with the installation.
    HitmanPro User Account Control Pop-up
  3. When the program starts you will be presented with the start screen as shown below. Now click on the Next button to continue with the scan process.
    HitmanPro setup process
  4. HitmanPro will now begin to scan your computer for malware.
    HitmanPro scanning for Trojan:JS/Medfos.B virus
  5. When it has finished it will display a list of all the malware that the program found as shown in the image below. Click on the “Next” button, to remove malware.
    HitmanPro detected malware
  6. Click on the “Activate free license” button to begin the free 30 days trial, and remove all the malicious files from your computer.
    Activate HitmanPro to remove malware
    When the process is complete, you can close HitmanPro and continue with the rest of the instructions.

Your computer should now be free of the Trojan:JS/Medfos.B virus. If you are still experiencing problems while trying to remove Trojan:JS/Medfos.B virus from your machine, you can ask for help in our Malware Removal Assistance forum.
How to Stay Safe Online

Here are 10 basic security tips to help you avoid malware and protect your device:

  1. Use a good antivirus and keep it up-to-date.

    Shield Guide

    It's essential to use a good quality antivirus and keep it up-to-date to stay ahead of the latest cyber threats. We are huge fans of Malwarebytes Premium and use it on all of our devices, including Windows and Mac computers as well as our mobile devices. Malwarebytes sits beside your traditional antivirus, filling in any gaps in its defenses, and providing extra protection against sneakier security threats.

  2. Keep software and operating systems up-to-date.

    updates-guide

    Keep your operating system and apps up to date. Whenever an update is released for your device, download and install it right away. These updates often include security fixes, vulnerability patches, and other necessary maintenance.

  3. Be careful when installing programs and apps.

    install guide

    Pay close attention to installation screens and license agreements when installing software. Custom or advanced installation options will often disclose any third-party software that is also being installed. Take great care in every stage of the process and make sure you know what it is you're agreeing to before you click "Next."

  4. Install an ad blocker.

    Ad Blocker

    Use a browser-based content blocker, like AdGuard. Content blockers help stop malicious ads, Trojans, phishing, and other undesirable content that an antivirus product alone may not stop.

  5. Be careful what you download.

    Trojan Horse

    A top goal of cybercriminals is to trick you into downloading malware—programs or apps that carry malware or try to steal information. This malware can be disguised as an app: anything from a popular game to something that checks traffic or the weather.

  6. Be alert for people trying to trick you.

    warning sign

    Whether it's your email, phone, messenger, or other applications, always be alert and on guard for someone trying to trick you into clicking on links or replying to messages. Remember that it's easy to spoof phone numbers, so a familiar name or number doesn't make messages more trustworthy.

  7. Back up your data.

    backup sign

    Back up your data frequently and check that your backup data can be restored. You can do this manually on an external HDD/USB stick, or automatically using backup software. This is also the best way to counter ransomware. Never connect the backup drive to a computer if you suspect that the computer is infected with malware.

  8. Choose strong passwords.

    lock sign

    Use strong and unique passwords for each of your accounts. Avoid using personal information or easily guessable words in your passwords. Enable two-factor authentication (2FA) on your accounts whenever possible.

  9. Be careful where you click.

    cursor sign

    Be cautious when clicking on links or downloading attachments from unknown sources. These could potentially contain malware or phishing scams.

  10. Don't use pirated software.

    Shady Guide

    Avoid using Peer-to-Peer (P2P) file-sharing programs, keygens, cracks, and other pirated software that can often compromise your data, privacy, or both.

To avoid potential dangers on the internet, it's important to follow these 10 basic safety rules. By doing so, you can protect yourself from many of the unpleasant surprises that can arise when using the web.

38 thoughts on “How to remove Trojan:JS/Medfos.B malware (Virus Removal Guide)”

  1. Yep, finally! Thanks. MSE first identified and quarantined it, but couldn’t remove it. I tried the Malicious Software Tool, nuttin’. Malwarebytes, surprisingly, nuttin’. And MS Emergency Response Tool, nuttin’. None of those even saw it. Safe Mode boot, still none saw it. Skipped to Rogue Killer since most folks seemed to say that was the one…it identified two malicious entries which it highlighted red, the others were brown and clearly ok from what I could tell. Deleted the two reds, and we seem to be ok now.

  2. Wow………. Thank you soooooooooooo much! What a great person to take the time to give such detailed instructions; complete with links for the program downloads! This was the ONLY site/instructions that worked on this virus!!!!! You are a life saver!!! THANK YOU THANK YOU!

  3. At first I was skeptical that this page was an add for malware removal tools,lol. But scanning through the comments it seemed to be legit and not just marketing comments, so I gave it a try. Worked like a charm. Combofix, Roguekiller and Malwarebytes each found a few items, the other 3 scans had no results. Took about 3 hours, but these links and directions made it simple and a frustration free experience. Never removed a virus with so easy an experience. Thank you!!!! Erika

  4. Thanks for the help, I ran all the programs and our Windows 7 computer is now clean. This was a hard one to handle, great web site and support.

  5. This did the trick. All the different stages worked fine. some took as long as 25 min, but the results are worth it. Thanks for giving me my computer back!

  6. I could use a little more help. I ran the TDSSKiller–it didn’t find anything, so I moved on to the next step. The ComboFix seems to be “stuck” trying to create a new System Restore point. (left it overnight in case it was a slow process. . .found it in the same spot this morning. .. ). What do I do now?

  7. Thank you for this! I was so worried I was going to have to spend a bunch of money and be without my work laptop. I followed your steps exactly and I dont know which step got rid of the problem, but my laptop is working as good as new now. Thank you SO much!

  8. Tried lots of things until I found this processs. A little long but worked great.
    Thank you so much for the simple and complete instructions. Since Kaspersky TDSSKiller didn’t find anything I used RKill instead, it did stop some processes. This trojan was really persistant so thanks again.

  9. Well thank you very much for the simple and effective solution. I am not sure where the fix was actually done, but I am grateful all the same. Take note others about to do this – it takes hours so be patient, but the reward is that it works.

    Thank you very much Stelian for helping my with my Messi

  10. Hello BT,
    Can you please copy/paste the RogueKiller (should be on your desktop) and Combofix (should be in C:\Combofix.txt) logs so that I can take a look at what’s going on…

  11. Hello Garnie,
    Adwcleaner is a legit and malware free software..Your antivirus is having a false positive detection, which you can ignore.

  12. My antivirus blocks the ADWCleaner website, saying it is infected with Mal/Generic-L.
    Is there an alternative?
    I believe JS/Medfos on my friend’s computer came from the Avios website.

  13. My virus program found the troj_medfos.smi under appdata\roaming\rsvcrp.dll, squplo.dll, rcobc.dll but not able to remove the threat. Both malwarebytes and hitman pro scan came back zero. Rougekiller came back with a list of the registry that has those 3 dll files, I did not delete afraid I might be deleting something that I am not supposed to. All files are under system 32\rundll32.exe, also some window\regboot clean 64.exe

  14. Thanks Stelian. This was a lifesaver for me. After three whole days of trying to get this fixed, things were getting a bit depressing but your steps took care of it beautifully!

  15. Hello Lou,
    There are different versions on the Medfos trojan, and some of them will detect and block TDSSKiller from running… In your case it worked without needing to be renamed so that’s great!:D
    Stay safe!

  16. Hello Stelian,

    I can’t thank you enough for your help. With one exception, I followed your instructions to the letter and got rid of medfos, although it appeared that ComboFix and Roguekiller did most of the work. The exception: I did not rename the TTDSKiller executable. It did not make sense to me to call it iexplore.exe, so I didn’t. It worked anyhow. Why do you instruct the user to rename it?

    I’m very pleased, and thank you again for your help. Best wishes,

    Lou

  17. Thank you so much for taking the time to help people solve this problem. Like another poster on here, I am also a single parent and can’t afford to take my laptop to the shop to get rid of this cursed virus. I also often work from home for my job and would have struggled without the computer. It took me about three hours, but I think I got rid of the virus by at first using info from other sites (w/o success), and then finding yours and going through the step by step directions. Also like others, MSE detected and quarantined the virus, but would not remove it. Malwarebytes and Superantispyware did not even detect it and neither did TDSSKiller, even with renaming it to iexplorer, etc. I think somewhere in or after the Combofix part of the process, I was finally able to get rid of the virus. I don’t know how I got it but suspect either an Adobe update or just being on an innocent-looking website. Thank you so much for your help!

  18. Thank you! Thank you! Thank you! My heart dropped when I got this trojan from a java link. I am a single Mom who uses my computer for extra income. I did not have $100+ dollars to put it in the shop. As others mentioned. Rogue Killer seems to have worked. MSE kept finding this virus but didn’t get rid if it. This was very frustrating. Can’t thank you enough!

  19. Thank you for your easy step by step instructions. Like most here, I think the remover was roguekiller but the other programs were helpful in determining the exact locations and assaulted areas of concern. Brilliant minds!!

  20. Having been bitten by this pestiferous bug I approached the cleaning-up with some trepidation, being afraid to make more damage than good. However your step-by-step instructions, clear screen shots and detailed comments were a real boon for an old codger, and I’m glad to report that everything now looks fine. I am very grateful indeed. Combofix was a bit touchy, as was HitmanPro (didn’t complete the “one-off scan” but was OK when I changed the option). Again many thanks and a belated Happy New Year!
    8{)

  21. BLESS YOU- my computer is completely fixed now! I’ve heard a lot of warnings against using Combofix, but it worked like a dream for me! Roguekiller was good too. Thanks a ton! ^___^

  22. Hello Helen,
    Combofix may detect some left over files from Norton and give you that notification.Just to be on the safe side, skip the Combofix scan for now and go ahead with the rest of the guide.

  23. Thank you for the step-by-step instructions. They worked! I think the tool combination of ComboFix and RogueKiller worked on my computer, removing the malware, Trojan:JS/Medfos.B. The other tools were useful as well, cleaning up some other nits. Microsoft’s Security Essentials, while putting the malware into quarantine, could not remove it; the MSE website was not helpful. Thankfully, I found this website and its useful instructions. Time invested was about 6.5 hours running the tools, Malwarebytes having the longest run time, but it was time well spent. Thank you again for a most useful website, spot-on guidance, and effective instructions.

  24. In Step 2, above, when I started Combofix it told me that Norton Virus Security was running. As I don’t have Nortons installed on the machine and no other programs or processes were running apart from Combofix, I decided to continue. The scan has now been running for over half an hour – should I just let it continue? I am running in Safe Mode – is that likely to stop it working properly?

  25. Think we got it.
    Microsoft Security Essentials tech support minimum charge for this is Usd $99.oo

    Users should take note of “update” to get latest data on each of steps, as well as the “be sure to” advisories about how to install & run. Don’t panic, wait for the dialogue box to advise, and remember that some changes don’t happen (or happen completely) until after a restart.

    BE YOUR OWN TECH SUPPORT!
    Cheers Steleian.
    rgds, J.

  26. I too had this slippery little bugger on my computer, which had been picked up by both Avira and Malwarebytes but after scanning and removing it they simply couldn’t pick it up anymore and it was only MSE that did, otherwise i’d have been oblivious to it now.

    There wasn’t a problem locating it, as mentioned in the article it was getting rid of it, eventually found this and put my trust in it even though i thought it was way over my head. Anyway, to cut a long story and some threasts towards the git that created it (at the sceen i may add), i took a short cut and went straight for the Hitman Pro, then followed the destructions from there; and yes it got it without too much pain to be honest, i’m just over the moon i had found this article and it WORKED!!!!

    ”JUST SO PEOPLE ARE AWARE; IT ALL STARTED WITH AN ADOBE UPDATE (IT LOOKED EVERYTHING LIKE THE ONE YOU GET WHEN TURNING THE COMPUTER ON) BUT TOOK ME 40MINS TO GET PAST IT AS I WAS REFUSING TO UPDATE AND ONCE I SAID YES, THATS WHEN IT ATTACKED”

    THANK YOU SOO MUCH

  27. A solution at last. Like previous comments many applications such as MSE found and quarantined this infection only for it to be reinstalled a few minutes later. Lke the others, step 3, “RogueKiller” worked a treat for me.
    Thanks for the info.

  28. Thanks for this information. My laptop was recently infected with Medfos. MSE kept quarantining it, but couldn’t remove it. I tried MalwareBytes Anti-Malware. Same thing-found it, but couldn’t get rid of it. Tried HitmanPro. Same result. So far, RogueKiller has worked. I deleted everything related to Java, but I’m going to have to reinstall it so my kid can play Minecraft, but I’m going to disable all my browser plug ins. This Trojan is insidious and I really appreciate the information you’ve provided.

Comments are closed.