Solved Windows Defender pops up on restart

HoneycombAG

Overclocking the Web
Power User
Local time
8:15 AM
Messages
297
Just as I come from a reboot Windows Defender pops open. That's funny, “MSASCui -silent” is set in the start options. But whenever I ran the Quick Scan, it found an iteration of Adware:W32/OpenCandy.

Running a full scan
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Microsoft Windows 7 Home Premium 64-bit Service Pack 1
CPU
AMD A10-6800K APU with Radeon(tm)™ HD Graphics 4100
Motherboard
ASRock FM2A85X Extreme4-M
Memory
(2) G.Skill F3-12800CL10-8GBXL
Graphics Card(s)
ASUS R7 250 Series (0x6610)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Acer X213H LCD monitor, 21"
Screen Resolution
1920 x 1080 x 32 bits @ 60 Hz
Hard Drives
WD Black, 1.0TB, WDC WD1002FAEX-00Z3A0
PSU
Rosewill Quark-650
Case
Raidmax Comet SECC Steel ATX Mid Tower Computer Case
Cooling
1 x 80mm + 2 x 120mm + Stock cooler
Mouse
Gear Head Wireless Optical 5-button mouse
Internet Speed
FTTx 6000 / 1000
Antivirus
Avast! Free Antivirus 2015.10.0.2208
Browser
Google Chrome Version 40.0.2214.115
Other Info
*AMD Dual-Graphics
*Uses OpenDNS
*Uses Folding@Home
*HP 16x Super-Multi DVD Writer
*Superspeed 74-in-1 Card Reader
*Maximum overclock has not been determined.
After you run the full scan post up the results.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 8.1 Pro x64
CPU
Intel Core i5-4570 CPU @ 3.20GHz
Motherboard
Gigabyte Z87-D3HP-CF
Memory
8GB DDR3-1596 - Dual Channel
Graphics Card(s)
NVIDIA GeForce GTX 750 Ti SC
Sound Card
Onboard
Monitor(s) Displays
Samsung
Screen Resolution
1920x1080
Hard Drives
SSD - 120GB
Second - 1TB
Antivirus
MSE
Browser
Chrome
This came bundled with something you recently installed:

Encyclopedia entry: Adware:Win32/OpenCandy - Learn more about malware - Microsoft Malware Protection Center

Consider upgrading to MSE. It combines the function of Defender along with an active scanning AV.

MSE has detected OpenCandy on a couple programs before I installed them. It lists it as "Potentially Unwanted Software."

Microsoft Security Essentials - Free Antivirus for Windows

Also, try running Malwarebytes, be sure to check the boxes of anything it finds & quarantine it.

Malwarebytes : Malwarebytes Anti-Malware PRO removes malware including viruses, spyware, worms and trojans, plus it protects your computer
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Now I realize what was going on with Windows Defender's unusual startup behavior. MSASCui doesn't support the "-silent" switch, so even if the rest of the operating system starts the window still pops open. This was only meant for the older Windows versions which didn't come with Windows Defender pre-installed. I went to my tools collection and ran FixWin to restore the default behavior of Windows Defender.

I ran the MRT tool and it didn't find anything. I suppose that's what it was reporting before the stupid thing locked up and I had to forcibly power down my system, because the drive activity light wasn't even flashing as well. As of this point Windows Defender is set only on the C: drive.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Microsoft Windows 7 Home Premium 64-bit Service Pack 1
CPU
AMD A10-6800K APU with Radeon(tm)™ HD Graphics 4100
Motherboard
ASRock FM2A85X Extreme4-M
Memory
(2) G.Skill F3-12800CL10-8GBXL
Graphics Card(s)
ASUS R7 250 Series (0x6610)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Acer X213H LCD monitor, 21"
Screen Resolution
1920 x 1080 x 32 bits @ 60 Hz
Hard Drives
WD Black, 1.0TB, WDC WD1002FAEX-00Z3A0
PSU
Rosewill Quark-650
Case
Raidmax Comet SECC Steel ATX Mid Tower Computer Case
Cooling
1 x 80mm + 2 x 120mm + Stock cooler
Mouse
Gear Head Wireless Optical 5-button mouse
Internet Speed
FTTx 6000 / 1000
Antivirus
Avast! Free Antivirus 2015.10.0.2208
Browser
Google Chrome Version 40.0.2214.115
Other Info
*AMD Dual-Graphics
*Uses OpenDNS
*Uses Folding@Home
*HP 16x Super-Multi DVD Writer
*Superspeed 74-in-1 Card Reader
*Maximum overclock has not been determined.
Windows Defender did not find any further infection from OpenCandy. In the meantime, someone needs to tell me how to run a boot trace, because in-between the time I've been scanning, I was hit with some "REGISTRY_ERROR" BSOD's and I must notify the BSOD Team about what's been taking place.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Microsoft Windows 7 Home Premium 64-bit Service Pack 1
CPU
AMD A10-6800K APU with Radeon(tm)™ HD Graphics 4100
Motherboard
ASRock FM2A85X Extreme4-M
Memory
(2) G.Skill F3-12800CL10-8GBXL
Graphics Card(s)
ASUS R7 250 Series (0x6610)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Acer X213H LCD monitor, 21"
Screen Resolution
1920 x 1080 x 32 bits @ 60 Hz
Hard Drives
WD Black, 1.0TB, WDC WD1002FAEX-00Z3A0
PSU
Rosewill Quark-650
Case
Raidmax Comet SECC Steel ATX Mid Tower Computer Case
Cooling
1 x 80mm + 2 x 120mm + Stock cooler
Mouse
Gear Head Wireless Optical 5-button mouse
Internet Speed
FTTx 6000 / 1000
Antivirus
Avast! Free Antivirus 2015.10.0.2208
Browser
Google Chrome Version 40.0.2214.115
Other Info
*AMD Dual-Graphics
*Uses OpenDNS
*Uses Folding@Home
*HP 16x Super-Multi DVD Writer
*Superspeed 74-in-1 Card Reader
*Maximum overclock has not been determined.
Back
Top