We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Please help! Had Defender virus warning - Now desktop icons have vanished!

12021232526

Comments

  • Seems spits has the same problem as me. Will be interesting to see if any of those instructions work. The guys here have had me do all of this I think except step 1. Thanks again.
  • paddywak
    paddywak Posts: 92 Forumite
    Thanks for the malwares site. There seems to be similar problems to mine on it with one person having the exact same trojan as me. Will be interesting to see if this can be sorted.
    The only problem I have is trying out some of the things they suggest. They tell me to use safe mode - do you know what this means? Then I have to run Regedit - what is this?
    Some advice would be appreciated.
    Thanks
  • Paddywak - I have not read the entire thread - What appears to be the problem?
  • Browntoa
    Browntoa Posts: 49,619 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    it's this line in mbam logs

    HKEY_CLASSES_ROOT\CLSID\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.BHO) -> Delete on reboot.

    that it fails to remove, i've posted a link to the thead on their support forum , hoping they find a cure soon , looks like a new infection
    Ex forum ambassador

    Long term forum member
  • Browntoa
    Browntoa Posts: 49,619 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    paddywak wrote: »
    Thanks for the malwares site. There seems to be similar problems to mine on it with one person having the exact same trojan as me. Will be interesting to see if this can be sorted.
    The only problem I have is trying out some of the things they suggest. They tell me to use safe mode - do you know what this means? Then I have to run Regedit - what is this?
    Some advice would be appreciated.
    Thanks

    they have not cured it yet, I would avoid following any advice from that thread unless Reluctant or I tell you to
    Ex forum ambassador

    Long term forum member
  • Could try a reg fix?
  • paddywak
    paddywak Posts: 92 Forumite
    Hi Browntoa and reluctant spender

    Thanks for your advice - will folow what you suggest browntoa. What is a reg fix reluctant spender? There is an exact line of the trojan from a post by knsudhir on that site so am watching that too. Will await your advice.
    Thanks
  • Don't follow someone elses fix. Although there could be similarity's it is not advised to do so.

    A reg fix will remove the line.
  • Browntoa
    Browntoa Posts: 49,619 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    up to you ;)

    I was waiting for MBAM to do the work
    Ex forum ambassador

    Long term forum member
  • ok, whilst waiting lets look a little deeper,
    • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.2K Banking & Borrowing
  • 254K Reduce Debt & Boost Income
  • 454.9K Spending & Discounts
  • 246.3K Work, Benefits & Business
  • 602.4K Mortgages, Homes & Bills
  • 177.9K Life & Family
  • 260.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.