Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: AVG or Windows Defender came up informing me of 2 infections

20 May 2011   #1
MissSencho

Windows 7 Home Premium 64 bit
 
 
AVG or Windows Defender came up informing me of 2 infections

Hi all,

I'm not sure if repair install could help me but I've never had anything of the sort occur with my computer before.

Last night I was surfing away, just looking at a few websites. I opened a new one (from google search) and either AVG or Windows Defender came up informing me of 2 infections. One was in the roaming directory, that is all I saw. I asked it to fix and remove said infections. It had just managed to do it when another one popped up. At this moment Yahoo messenger started acting in a bizarre manner and my computer just crashed. It rebooted and Startup Repair appeared. It told me it would try to fix it and then restarted. After the second time it told me it could not fix the problem automatically. The problem seems to be a corrupt file according to the extra information it provided. I think it's a virus as I believe (but may be mistaken in thinking) startup repair cannot protect against those.

I tried to do System Restore though I was sure that would not work and it didn't. Like an idiot I have not backed up any of my data. I would prefer not to have to re-install anything but and to fix it without all the hassle but at the very least I would just like to get all the files etc. This is what is most important to me. I don't mind having to spend hours reinstalling everything as long as I can access and somehow back-up my files.

Can repair install help? Any other options? I'd appreciate any help at all. Thanks for reading this rather verbose post.

-Tunde


My System SpecsSystem Spec
.
20 May 2011   #2
Ex_Brit

Win 7 Ult SP1/Win 10 Pro (all x64)
 
 

I suspect an infection and a Repair Install at this stage may be premature and probably would fail anyway.

Try booting to "Safe Mode with Networking" which is choice number 2 on the menu that you should get by tapping F8 repeatedly while booting up.

In that mode you should be able to access the Internet while at the same time preventing any malware from running

Go HERE and download the FREE version. Update it once installed (important) and then run a full scan and let it remove anything it finds, do all this in that mode. Reboot if it asks you to. Hopefully that will remove the bug whatever it is and then you can proceed with the rest of your life ;-)
My System SpecsSystem Spec
20 May 2011   #3
MissSencho

Windows 7 Home Premium 64 bit
 
 

Ex-Brit - Thanks for the swift reply and advice. I will give this a bash later and relay the results here.

From one Brit to an ex-Brit, hearty thanks.
My System SpecsSystem Spec
.

20 May 2011   #4
Ex_Brit

Win 7 Ult SP1/Win 10 Pro (all x64)
 
 

You're welcome and I hope it helps.
My System SpecsSystem Spec
20 May 2011   #5
Hopalong X

Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
 
 

Quote   Quote: Originally Posted by MissSencho View Post
Hi all,
Last night I was surfing away, just looking at a few websites. I opened a new one (from google search) and either AVG or Windows Defender came up informing me of 2 infections. One was in the roaming directory, that is all I saw. I asked it to fix and remove said infections. It had just managed to do it when another one popped up. -Tunde
This is a fake alert. It is malware or worse and you now have it installed.
You need to make a posting in the Security section. Malwarebytes may remove it by itself but usually not.
Install the Malwarebytes, Update and run the full scan.
Save the log to your desktop and upload the log in a new thread in the Security section with explanation of what happened.
Someone can check the log and assist you from there.
We need the log to find the name of the malware to find the proper remover if Malwarebytes does not remove it..

Repair Install is useless until you get rid of the problem.
The problem would still be on the system.

Mike
My System SpecsSystem Spec
20 May 2011   #6
marsmimar

Microsoft Community Contributor Award Recipient

 
 

Agree with Mike. In addition to Malwarebytes, Symantec has a tool called Norton Power Eraser which is designed to locate and remove scareware ... the stuff that says your computer is infected and you should buy their product to rid yourself of the malware, acne, and flatulence. Heed the warning: Because Norton Power Eraser uses aggressive methods to detect threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully.

Norton Rescue Tools
My System SpecsSystem Spec
20 May 2011   #7
stevieray

windows 7 x64 Home Premium
 
 

These scareware packages are getting more and more sophisticated. They can imitate Win 7 & XP alert boxes exactly... right down to the color and border transparency. They'll tell you you're infected, or that your hard drive and RAM are damaged and you need to buy "X" to fix it (as if damaged hardware can be fixed with a download)... and they look so real many folks fall for it.

I have always had good luck with malwarebytes (mentioned above) and superantispyware (link:SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!)... yeah, it's a dumb name, but it's a good product and it's free as well.

Good luck and happy hunting!
My System SpecsSystem Spec
20 May 2011   #8
Hopalong X

Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
 
 

If Malwarebytes identifies the culprit Jacee or Corrine may have an exact removal tool which is safer than Nortons.
My System SpecsSystem Spec
21 May 2011   #9
MissSencho

Windows 7 Home Premium 64 bit
 
 

Hi again,

I just tried the methods suggested above and it won't let me go in through Safe Mode with Networking. It takes me right back to Startup Repair.

I clicked on the diagnostic and repair details and it said within it that the root cause is: Boot critical file C:CL.dll is corrupt.

Is there perhaps something else I can do? Thank you all for the help so far. It would be ideal to be able to go in and extract the infection.

stevieray - Yeah, until you mentioned it it hadn't occured to me that it was Scareware. I'm even more annoyed with myself now.

-Tunde
My System SpecsSystem Spec
21 May 2011   #10
I be he

Win 7 64 premium
 
 

Sandboxie
My System SpecsSystem Spec
Reply

 AVG or Windows Defender came up informing me of 2 infections




Thread Tools




Similar help and support threads
Thread Forum
Multiple serious infections
Trying to help a friend whose system was frozen with files hidden. Avast boot scan found numerous infections which it doesn't seem to fix since I've run it three times. So did Combofix after rKill, which unhid the files and otherwise restored performance. Still we get a popup at every boot from...
System Security
HAPPILI and possible other infections/redirects
I recently came here to the forums to remove HAPPILI. I followed several of the steps in a certain thread but still got redirected to HAPPILI. Now (a couple days later) I have stopped seeing HAPPILI redirect but am getting redirected to another fake search results page...very generic looking,...
Performance & Maintenance
Infections EVEN after formatting and installation?
Hello, I've had a lot of problems with my computer recently, for example, not being able to boot up and system repair not working and many more. I reinstalled my system, transferred my files from the external hard drive back onto the computer but still the problem occured, only even worse. This...
System Security
virus infections
hey gang. I work at a service depot as a depot technician. I'm studying the MCTS, and a few of my collegues were discussing infections and how they're related to having or not having a NAT firewall device (hardware; i.e. router). Their argument was that not having a router vs. having a router...
System Security


Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 03:30.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App