We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

JS/Downloader Agent

Yesterday while Googling for info about a hard drive, I clicked a link and immediately AVG detected the above virus.

It was moved to the vault.

Currently PC is being scanned in safe mode, and the only thing detected is a change to C:\WINDOWS\system32\shell32.dll (is this linked to a memory upgrade a couple of days ago)

I've Googled the name and to my novice eye it seems to be linked to Java, in particular the cache.

Smitfraudfix and trendmicro-sysclean are mentioned as cures.

Is it really necessary to run these if the PC appears clean after scanning?
Move along, nothing to see.

Comments

  • xJonny
    xJonny Posts: 54 Forumite
    Part of the Furniture Combo Breaker
    It may be worth running anti-spyware programs such as Spybot, or AdAware.

    http://www.safer-networking.org/
    http://lavasoftusa.com/

    AVG isn't as good as paid anti-virus software so it may not have picked up what it was but just a modification to that file. It could have been a false-positive, mind.
  • spud17
    spud17 Posts: 4,451 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    AVG isn't as good as paid anti-virus software

    Not exactly true, especially if you read threads on this forum.

    The AVG resident shield detected and isolated it the instant I clicked the link, it is now in the virus vault.

    Although I am running my various spyware/malware programs as a precaution this a Virus, and AVG is showing my PC as clear.
    Move along, nothing to see.
  • I would suggest that you run them in safe mode, thus eliminating any chance of not being able to remove any offending item

    Personally, I would turn off system restore before doing any scan, thus removing the possibility of having had a nasty being backed up, and turning it back on once scans give you the all clear
  • spud17
    spud17 Posts: 4,451 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Red Rose Exile
    I would suggest that you run them in safe mode, thus eliminating any chance of not being able to remove any offending item

    Are you referring to the smitfraudfix?

    In safe mode have now run AVG, SuperAntiSpyware, Spyware Terminator, Spybot and Adaware. All with latest updates.

    For some reason AVG Antispy is stalling.

    All scans show nothing, not even a tracking cookie.
    Move along, nothing to see.
  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    It's been quarantined and is not a problem now, hence the clean scans
    Ex forum ambassador

    Long term forum member
  • smitfraudfix should be run in safe mode anyway for best chance of success as should any virus removal tool
  • spud17
    spud17 Posts: 4,451 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Browntoa and Red Rose Exile

    Thanks for the replies, everything up and running again.

    All seems OK and thanks for the reassurance.

    Thanks also to AVG Free. :D
    Move along, nothing to see.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 603K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.