Author Topic: Help required - TPPWRIF.SYS  (Read 12543 times)

0 Members and 1 Guest are viewing this topic.

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2297
Re: Help required - TPPWRIF.SYS
« Reply #15 on: October 15, 2010, 03:31:03 PM »
1. Should I restore the file from the Chest?
Yes, if you will add exclusion for the destination directory, or wait until the new VPS will be released (don't ask me when ;-)).

Quote
2. May I ask what exactly triggered the false positive?
Yes, you can ask.

The answer is that we didn't have the file in our cleanset.

Milos
« Last Edit: October 15, 2010, 03:37:01 PM by Milos »

Avastfan1

  • Guest
Re: Help required - TPPWRIF.SYS
« Reply #16 on: October 15, 2010, 03:38:43 PM »
Thanks for the prompt reply Milos.

Strange that the file was not in the cleanset. I used the Lenovo System Update several times during the last few months, and that file would certainly have been flagged before!?!?!?!?!

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2297
Re: Help required - TPPWRIF.SYS
« Reply #17 on: October 15, 2010, 03:44:09 PM »
Thanks for the prompt reply Milos.

Strange that the file was not in the cleanset. I used the Lenovo System Update several times during the last few months, and that file would certainly have been flagged before!?!?!?!?!

No, it wasn't detected before. The detection was improved and tested on our cleanset and it passes, so it was released today morning (CET) in VPS 101015-0.

Milos

CharleyO

  • Guest
Re: Help required - TPPWRIF.SYS
« Reply #18 on: October 15, 2010, 03:50:14 PM »
***

suservice.exe      (I am wondering why is this here?)
Virusscan   
McAfee Streaming Update Service

Thanks Charley0 for your time and research.

I believe that the above file belongs to IBM update (http://www.bleepingcomputer.com/startups/suservice.exe-19075.html).

Do you have any further suggestions for the six items I highlighted from the HJT log?

1. - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe - ? - very safe - This is an unknown process
2. - C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe - ? -       - This is an unknown process
3. - O4 - HKLM\..\Run: [LenovoAutoScrollUtility] C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe - ? -   -  unknown application
4. - O4 - Global Startup: Digital Line Detect.lnk = ?   -  neutral - Unknown application.
The entry is unnecessary and can be fixed.
5. - O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing) - X - very safe -     Unnecessary (deactivated) entry that can be fixed. This entry was classified from our visitors as good.
6. - 023 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe - ? -     - Unknown service. (MICMUTE.exe)

Thanks in advance!

Best wishes,

Avastfan1

The only 2 that need fixing with HJT are your numbers 4 & 5.
The others are legitimate entries according to the research I did above.

You are welcome as I am glad to help.

Take care!


***

Avastfan1

  • Guest
Re: Help required - TPPWRIF.SYS
« Reply #19 on: October 15, 2010, 03:56:05 PM »
Thanks Charley0.

I found another entry in the log:

7. O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)

What is your opinion on this one?

Thanks!

Avastfan1

CharleyO

  • Guest
Re: Help required - TPPWRIF.SYS
« Reply #20 on: October 15, 2010, 04:05:03 PM »
***

Thanks Charley0.

I found another entry in the log:

7. O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)

What is your opinion on this one?

Thanks!

Avastfan1


That one is related to IBM's Professional Services Automation products.

http://www.bleepingcomputer.com/startups/PsaSrv.exe-19074.html

Since the file is missing, it can also be fixed with HJT.


***