Win32/Lodi

Solved
Sakura_01 Posted messages 118 Registration date   Status Membre Last intervention   -  
Sakura_01 Posted messages 118 Registration date   Status Membre Last intervention   -
Hello,

When I turned on my PC earlier, Windows Defender gave me a message about a threat related to Win32/Lodi (I didn’t remember the full path).
I clicked on intervene and Windows Defender blocked it for me, is that enough?

I don’t recall downloading anything yesterday that could have “brought” this potential virus.

Thank you.
Have a good day.

Configuration: Windows / Firefox 96.0

1 réponse

bazfile Posted messages 58431 Registration date   Status Modérateur Last intervention   20 245
 
Hello,
Download FRST once downloaded save it to the desktop then right-click on FRST and choose Run as administrator you will get this:

Click on Analyze

Attention, wait for the messages saying that the analysis is complete to appear


At the end of the analysis, you will have two text files on the desktop FRST and Addition, .
Then send the FRST and ADDITION reports to CJOINT
see THIS TUTORIAL then provide the two links generated by Cjoint in your reply.

--
bazfile
Moderator/Security Contributor.
a hello, a reply, a thank you are always appreciated.
1
Sakura_01 Posted messages 118 Registration date   Status Membre Last intervention   3
 
Thank you, it's done.
Here are the links for FRST and Addition:

https://www.cjoint.com/c/LAplHFm1nQi

https://www.cjoint.com/c/LAplI1ONrzi
0
bazfile Posted messages 58431 Registration date   Status Modérateur Last intervention   20 245 > Sakura_01 Posted messages 118 Registration date   Status Membre Last intervention  
 
What Windows Defender found is FormatFactory.exe, located in
C:\Program Files (x86)\FormatFactory\FormatFactory.exe
. If you haven't installed this program, I can delete it; it has been installed on your PC since 02/20/2020. If you use this program, you can add it to Windows Defender's exclusions to stop being bothered by it https://support.microsoft.com/fr-fr/windows/ajouter-une-exclusion-%C3%A0-s%C3%A9curit%C3%A9-windows-811816c0-4dfd-af4a-47e4-c301afe13b26
It's your choice.
1
Sakura_01 Posted messages 118 Registration date   Status Membre Last intervention   3 > bazfile Posted messages 58431 Registration date   Status Modérateur Last intervention  
 
Yes, I use it from time to time. I uninstalled it last year because my antivirus often flagged this kind of "problem." Then I reinstalled it at the end of the year, setting the installation alert to "allowed" (I made sure to uncheck as many unnecessary boxes as possible during the reinstallation).

I'll check out the link, thank you very much :)

Edit: But is it really safe in terms of security? Is this what they call PUA?
0
bazfile Posted messages 58431 Registration date   Status Modérateur Last intervention   20 245 > Sakura_01 Posted messages 118 Registration date   Status Membre Last intervention  
 
But is there really no security risk? Is this what are called PUA?
No, there is no risk; otherwise it wouldn't be offered on CCM:
https://www.commentcamarche.net/telecharger/tv-video/10233-format-factory/
You need to be careful where you download it from; prefer CCM or the software publisher's website:
http://www.pcfreetime.com/formatfactory/index.php?language=fr

Some sites repack software and add adware, and if you're not careful during installation, you'll end up with unwanted software.

During installation, you need to uncheck the boxes that are offered; they are not always visible at first glance, for example:

0
Sakura_01 Posted messages 118 Registration date   Status Membre Last intervention   3 > bazfile Posted messages 58431 Registration date   Status Modérateur Last intervention  
 
Good evening,
Yes, I had downloaded it from the official pcfreetime site and unchecked everything that had to be unchecked.
Maybe an update without asking me, because everything was fine and I hadn't used it for at least 10 / 12 days.
FF seems to be quite well-known for its pushiness with useless software.
0