Should I delete it? SecureIconsProvider.dll

GmMMM

Estimable
Oct 28, 2014
1
0
4,510
I seemed to have caught a nasty and friggen persistant virus, happened in the day between reinstalling windows and downloading my Av software :/ any way I thought antivir and malwarebits cleaned it but it kept coming back. Tried nod32 and it picked up a vew extra things but a day latter it has poped up again, I believe I have tracked it down as explorer crashed in safe mode, 3 times before I gave up. So I killed explorer in taskmanager and straight away C:\ProgramData\Microsoft\Secure\Icons\iconscachehelper.dll apeared and was cleaned by nod32 straight away, killed taskmanager again and started and it appeared again. There is a file in C:\ProgramData\Microsoft\Secure\Icons\ called SecureIconsProvider.dll that can't be deleted. I can't find any info about this file but it can't be deleted because it is open in windows explorer. It says it is a microsoft dll but the details says it's original filename was SecureOverlay.dll hmmm does anyone have a file called SecureIconsProvider.dll in C:\ProgramData\Microsoft\Secure\Icons and what is it's size? Should I delete it in command prompt after killing explorer? Or am I playing wack a mole?

tl/dr
C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll anyone have this file in windows 7 and what is it's size please.

* Thanks, I went ahead a moved it to a different folder after ending explorer and that other dll didn't appear when I restarted explorer. There is very little information about SecureIconsProvider.dll and on virustotal only AhnLab-V3 picked it up as a Trojan/Win64.Sathurbot although RogueKiller says it is suspicious, nod32 and antivir both say it is clean. Will run a boot disk scan but if it comes back a reinstall looks like the only way to go. Thanks,
 

Onus

Distinguished
Jan 27, 2006
724
0
19,210
You may be able to delete it in Safe Mode, possibly from the command prompt (Windows Explorer won't be running). A search for viruses by name will typically find removal instructions. You may need to start fresh and re-install Windows again, this time IMMEDIATELY install AV.
 

sora

Honorable
Oct 30, 2013
388
0
11,010
I don't have C:\ProgramData\MicrosoftSecure\Icons\SecureIconsProvider.dll... I'm pretty sure it definitely is a virus. If you run your computer in Safe Mode like Onus suggested or start Windows with only the basic processes and services than you should most definitely be able to delete that DLL.
 

fchpnorth

Estimable
Dec 20, 2014
1
0
4,510
Hi,
I was having same problem here. I have windows 7 64. And I have Kaspersky installed. The program couldn´t remove and everytime remembering about the malware. So, I decided to do like "old fashion way", and I have started Windows on SAFE MODE with prompt (good and old DOS). Then I found the directory: "C:\documents and settings\all users\microsoft\secure\icons\". After that I have simply deleted both files, iconscachehelper.dll and the other that I forgot the name. Simply like that. Restarted my windows and it is perfect!!!!
Good Luck!!