Antivir Solution Pro

Discussion in 'Malware Help (A Specialist Will Reply)' started by the mekanic, Jul 13, 2010.

Thread Status:
Not open for further replies.
  1. the mekanic

    the mekanic Major Mekanical Geek

    It would seem that I've found a new bug.

    This little annoyance calls itself "Antivir Solution Pro", and I can't seem to kill it.

    I "borrowed" my clients PC, and pulled the HDD to scan it. I've used MalewareBytes, AVG, and even WindowsDefender, all which found nothing useful. I connected it USB via an Apricorn adapter. AVG did pick up on one file, which was allegedly from Microsoft, and not "digitally signed properly".

    The most surprising of all is the MalwareBytes not finding anything.

    Upon a cold restart, I have managed to beat this thing loading, and open Add/Remove Programs, but it's not on the list. I'm going to try again to "beat it", and open Task Manager so I can at least kill the process. Hasn't worked so far.

    Once loaded, and the icon is in the System Tray, it blocks ALL apps from functioning.

    Any advice?
     
  2. the mekanic

    the mekanic Major Mekanical Geek

    I beat it to the punch, and got Task Manager open.

    The name of the process is:

    tfwwvpttssd.exe

    I'm now going to see about manually killing it...
     
  3. the mekanic

    the mekanic Major Mekanical Geek

    OK, found the app file in the Local Settings folder.

    C:\Documents and Settings\User\Local Settings\Application Data\mplbpjjym

    -AND-

    C:\WINDOWS\Prefetch contains the following file:

    TFWWVPTTSSD.EXE-2B2F6B5E.pf
     
  4. the mekanic

    the mekanic Major Mekanical Geek

    Deleted both files, reset IE8 back to it's OEM settings, and the PC is good to go.

    This was an easy one, and I hope the basic stuff I posted helps someone.

    P.S.

    Old Dell Dimension desktop, WinXP SP3.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The concept is fine ;); however the file names and folders are never the same and sometimes there can be multiple folders and files. In addition that folder name only applies to Win 2K and XP not to Vista or Win 7. Also this infection name (Antivir Solution Pro) is just one of a thousand or so fake programs whose name changes a couple of times per day. This is also why the particular infection may go undetected for a while and even when detected, some of the files and folders related it still will not be found since they are totally random. ;)

    All of the above is why we recommend our full cleaning procedure to be run so that all permutations and any additional malware are found and removed.
     
  6. the mekanic

    the mekanic Major Mekanical Geek

    Well, all I can say is I got it knocked out, and AVG has kept the PC clean as of the present time...

    :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's great we are happy to hear it. I was just pointing out that the infection is almost never exactly the same.;)
     
  8. the mekanic

    the mekanic Major Mekanical Geek

    Nope, I've seen more than one gibberish process that had to be killed....

    :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what "Nope" is in response too.

    My point "infection is almost never exactly the same" seems to be what you are now agreeing with.
     
  10. the mekanic

    the mekanic Major Mekanical Geek

    Agreed.

    It's never the same twice, but AVG seems to have it's number now.

    It hasn't popped up again, YET...

    :major
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds