Results 1 to 4 of 4

Thread: ttpugfoj.exe

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Junior Member
    Join Date
    Sep 2013
    Posts
    3

    Default ttpugfoj.exe

    File came as a What's App VM message email. Download the .zip file, it runs an exe that installs a fake AV program. This file then locks the system, prevents opening task manager to kill the process and it was a bear to locate. Avast ~and~ Spybot say the .exe is totally safe, and I guess it more or less is, because it only opens the door for malware via websites - a process Avast did block. If I were a normal user, I'd have totally freaked out about the 32 or so critical malware detections it indicated.
    I found the name of the file because it sits in the notification area and shows the file's name. I finally managed to kill the process by logging on to another user account, opening Task manager in it, showing all processes for all users and was able to terminate (with extreme prejudice), this nasty little critter. Then I had to hunt it down manually, as it hides itself in \AppData\local from the Windows search util and am now shredding it.

    Just noticed in my FF downloads file that this malware is associated with bestholidaystoindia.com.
    Last edited by The_Evil_Dr_R; 2013-09-11 at 00:46.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •