Author Topic: Avast keeps flagging tcqqtwikpows.sys What is it?  (Read 1314 times)

0 Members and 1 Guest are viewing this topic.

Offline dcriley1

  • Newbie
  • *
  • Posts: 5
Avast keeps flagging tcqqtwikpows.sys What is it?
« on: March 06, 2024, 05:01:51 PM »
Whenever I boot up my PC, Avast flags tcqqtwikpows.sys (which is located in c:/windows/temp) as a suspicious file.  If I delete the file, it shows up again after a reboot.  I can't tell if this is malware or not, but I can't find any reference to it on Google or otherwise.  Does anyone know what this is, and how I can remove it permanently if it is malware?  It doesn't show up under a malwarebytes scan so I'm not positive it is.  thx!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #1 on: March 06, 2024, 05:22:02 PM »
A search for this filename results in zero hits, I would certainly consider it suspicious at the very least.

You say if you delete the file, are you sending it to the Avast Quarantine or manually deleting it ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #2 on: March 06, 2024, 05:36:57 PM »
Could you attach a screen grab of said alert next time it pops up?
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814

Offline dcriley1

  • Newbie
  • *
  • Posts: 5
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #3 on: March 06, 2024, 05:44:15 PM »
A search for this filename results in zero hits, I would certainly consider it suspicious at the very least.

You say if you delete the file, are you sending it to the Avast Quarantine or manually deleting it ?

Both.  Avast always quarantines it, but if I go and delete it, it always reappears and then AVAST flags it again.  I've tried a BUNCH of malware scans (malawarebytes, rkill, TDSSKiller, Rogue Killer, and eset) and nothing turns up, but AVAST flags it every time.  Wondering if it's a crypto miner or something but not sure how to dig it out.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #4 on: March 06, 2024, 05:59:29 PM »
This file is unknown, so no one will detect it.

Submit this file to VirusTotal.com.  By doing this you will enable the malware industry to become aware of this unknown .sys file.  https://www.virustotal.com/gui/home/upload

Recommend capturing the actual alert box when it shows again and attaching it here in your next reply.

The reason this file is suspicious is because of where Avast detects it:  TEMP folder.  No .sys file should resided in the TEMP folder.

https://www.lifewire.com/what-is-a-system-file-2626015

Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814

Offline dcriley1

  • Newbie
  • *
  • Posts: 5
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #5 on: March 06, 2024, 06:22:07 PM »
This file is unknown, so no one will detect it.

Submit this file to VirusTotal.com.  By doing this you will enable the malware industry to become aware of this unknown .sys file.  https://www.virustotal.com/gui/home/upload

Recommend capturing the actual alert box when it shows again and attaching it here in your next reply.

The reason this file is suspicious is because of where Avast detects it:  TEMP folder.  No .sys file should resided in the TEMP folder.

https://www.lifewire.com/what-is-a-system-file-2626015

Yeah, I suspected as much.  But nothing flags them other than AVAST.  I just submitted these files to the Virustotal page you listed and it flagged them from 1 vendor (1 security vendor and 1 sandbox flagged this file as malicious) which was Acronis.  The rest didn't.  Not sure what to make of this?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #6 on: March 06, 2024, 06:27:33 PM »
Wait.

You have more than one file being detected?

Please provide an url (website) link to VT.com so we can see your file(s).

Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814

Offline dcriley1

  • Newbie
  • *
  • Posts: 5
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #7 on: March 06, 2024, 06:29:49 PM »
Could you attach a screen grab of said alert next time it pops up?

Here's the screen grab

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #8 on: March 06, 2024, 06:36:07 PM »
Thanks for attached.

Now we can see what you are seeing.

Alert box states that Avast Self-defense was  triggered and blocked this threat.  This would likely mean an action by this file caused Avast to defend and protect itself from being disabled or modified by this file.  Which is why you are getting this alert.

Next, can you post a link to your Virus Total scan?
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814

Offline dcriley1

  • Newbie
  • *
  • Posts: 5
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #9 on: March 06, 2024, 06:44:52 PM »
Thanks for attached.

Now we can see what you are seeing.

Alert box states that Avast Self-defense was  triggered and blocked this threat.  This would likely mean an action by this file caused Avast to defend and protect itself from being disabled or modified by this file.  Which is why you are getting this alert.

Next, can you post a link to your Virus Total scan?

Here's a link to the system file upload.  Both files had the same url link.  Both gave me the same result.
https://www.virustotal.com/gui/file/11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #10 on: March 06, 2024, 07:09:43 PM »
Thank you for that.

Actual file name appears to be 'WinRing0.sys'  with a file hash of '11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5'.

This is important information.

See:
https://www.hybrid-analysis.com/sample/11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5/5f522ae23fea84253a2c4f05
https://thedfirreport.com/2023/12/04/sql-brute-force-leads-to-bluesky-ransomware/  (Not necessarily connected to your detection) but feature of 'WinRing0.sys' used.
https://news.sophos.com/en-us/2021/01/21/mrbminer-cryptojacking-to-bypass-international-sanctions/  Could be this type of malware.

You should head over to https://www.bleepingcomputer.com and ask for help at their virus forums to ensure your system is clean.

You can also report your file as a false positive to Avast here:  https://www.avast.com/false-positive-file-form.php#pc 

You should expect a reply in two days or so.
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5719
  • Spartan Warrior
Re: Avast keeps flagging tcqqtwikpows.sys What is it?
« Reply #11 on: March 06, 2024, 07:10:25 PM »
Submit a link for the second file please.
Windows 11 Home 23H2
Windows 11 Pro 23H2
Avast Premier Security version 24.8.6127 (build 24.8.9372.868)
UI version 1.0.814