AVG Virus Scanner Removes Critical Windows File

Yesterday the AVG virus scanner accidentally marked User32.dll as a virus.

AVG AntiVirus

Since this is a critical windows component, it has caused many machines not to boot. Two of our XP machines experienced the issue here, but it has not seemed to have bothered our Vista installs.

This happened because their scanner contained an incorrect virus signature that led it to think that user32.dll contained the Trojan Horse PSW.Banker4.APSA. AVG then prompted to delete the file (Heal). Luckily we did not do that :)

If you are running AVG, and you deleted the file, you will need to run system recovery or boot from a CD like BartsPE and restore it from c:\windows\system32\dllcache

Within a few hours AVG updated their signatures, and it no longer has the incorrect entry.

Filed Under: Windows

Leave a Reply

Please wait while we add your email address to our list

Join our Tips and Software Email List

Get free software, news, and tips
once a week by joining our email list
Enter your email address below

Just like you, we hate spam.

We promise to never sell, or spam your inbox

Thanks for joining our list, and have a great day!

Error adding address

There was an error adding your email address.
It might be because you are already on our list.
If this is not the case, please try again later. Thanks!