We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Please help! Had Defender virus warning - Now desktop icons have vanished!

1111214161726

Comments

  • SaqibQ
    SaqibQ Posts: 81 Forumite
    OK, don't need to worry about SuperAntiSpyware or Malwarebytes.

    I believe you have Avast and not AVG, correct? Since you have disabled Avast, you are now OK to run ComboFix.
  • SaqibQ
    SaqibQ Posts: 81 Forumite
    I'm going through the log now, and will post some instructions soon.
    I do have that AVG on the desktop but I thought I'd only downloaded AVAST
    From what I understand and can see from the logs is that you have the AVG installaiton file (.exe) on your Desktop, but you have not installed it. However, you have Avast installed operating as your anti-virus? Is that correct? Let me know.
  • Yes SaqibQ Avast is the one I put on over the weekend and disabled earlier. How can you see these things from all that writing? I'm totally amazed at this genius you lot have!!
  • SaqibQ
    SaqibQ Posts: 81 Forumite
    Hi,

    I may ask you to repeat some stuff you've already done later.

    But for now, please do the following...

    1. I'd like some files scanned:
    • Go to VirusTotal
    • Copy and paste the following file path into the Search Box in the middle of the page:
      • c:\windows\system32\redivipo.dll
    • Now click on the Send File button
      • NOTE:
      • If you come to the "File has already been analysed:" page, select "Reanalyse file now" to get a fresh scan.
    • Save a copy of the Anti-Virus results only. Post the results in your next reply.
    Do the same for the following files...
    C:\windows\system32\hugeloko.dll
    c:\windows\system32\nodivivo.dll


    2. Open Notepad and copy/paste the text in the Quote Box below into it:
    File::
    C:\WINDOWS\system32\kugatugi.dll

    Registry::
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "Notification Packages"=hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00
    Note: I have bolded "Control" as the forum software adds a space between the letters which will lead to an incorrect fix.

    Save this as CFScript.txt to your Desktop

    CFScript.gif

    Referring to the picture above, drag CFScript.txt into ComboFix.exe

    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
  • This is all that came up when I sent that line to virustotal
    0 bytes size received / Se ha recibido un archivo vacio
  • SaqibQ
    SaqibQ Posts: 81 Forumite
    That's fine! Scan the other files and let me know the results in your next reply. Also, make a note of files you're currently scanning so I know which result belongs to which file.

    Thanks!
  • SaqibQ
    SaqibQ Posts: 81 Forumite
    My mistake...
  • SaqibQ
    SaqibQ Posts: 81 Forumite
    Did you scan all the files? For some reason, they are not being displayed properly on the forum.

    Could you scan the files again, individually, save them in Notepad and upload them here. Post the download links here so I can download the files.

    Thanks!
  • A Hijack or Combofix too?
  • SaqibQ
    SaqibQ Posts: 81 Forumite
    Nope, those are fine!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.2K Banking & Borrowing
  • 254K Reduce Debt & Boost Income
  • 454.9K Spending & Discounts
  • 246.3K Work, Benefits & Business
  • 602.4K Mortgages, Homes & Bills
  • 177.9K Life & Family
  • 260.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.