Windows Troubles Solver

In order to remove Windows Troubles Solver rogue program, you must scan the PC with a real anti-malware tool.

Windows Troubles Solver was discovered as a fake security and hard drive utility program. It spreads over the Internet by means of Trojan and fake online virus scanner web pages. This malicious tool will attempt to persuade users into purchasing the full version by means of deceiving tactics. This includes issuing of fake pop-up alerts and warning messages. Additionally, it will run a system scan each time you start Windows. This scan will look very similar to legitimate anti-virus program. In fact it looks so real that it able computer users to that system is really infected with viruses.

Once Windows Troubles Solver is installed inside victim’s computer, it will modify system settings and add its own entry on the registry. When loaded on Windows start-up, Windows Troubles Solver will be able to manipulate systems operation. It may end any security related process. The malware will also redirect Internet browser to a predefined malicious web sites where users may download other malware hosted in it. Worst, the fake software will block execution of any installed programs and state that they are infected. Do not believe what the rogue program finds on your PC. It is necessary to remove Windows Troubles Solver as early as possible when spotted. Early removal can avoid further harm it may cause on compromised computer.

Screenshot Image:

Fake Antivirus

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Windows Troubles Solver Removal Procedures

Manual Removal:
1. Press Ctrl+Alt+Del on keyboard to stop process associated to “Windows Troubles Solver”. When Windows Task Manager opens, go to Processes Tab and find and end the following process:
(random characters).exe

2. You need to update your installed antivirus application to have the latest database.
3. Thoroughly scan the computer and any detected threats must be removed. If removal is prohibited, it is best to quarantine the infected item. Manually locating and deleting of malicious files should also be performed. Please see files below that are related to Windows Troubles Solver Virus.
4. Registry entries created by Windows Troubles Solver must also be remove from the Windows system. Please refer below for entries associated to the rogue program. [how to edit registry]
5. Exit registry editor.
6. Get rid of Windows Troubles Solver start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
(random characters).exe

7. Click Apply and restart Windows.

Windows Troubles Solver Removal Tool:
In order to completely remove the threat, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.

Kaspersky Bootable USB Flash Drive
A tool from Kaspersky will allow you to create a bootable virus scanner that can be run from any computer. This can be boot and run from media drives such as CD, DVD or USB Flash Drive. Download and follow the procedures here.

Technical Details and Additional Information:

Malicious Files Added by Windows Troubles Solver:
%UserProfile%\Application Data\Microsoft\[random].exe

Windows Troubles Solver Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe “Debugger” = ‘svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe “Debugger” = ‘svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe “Debugger” = ‘svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe “Debugger” = ‘svchost.exe
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = ’0′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = ’0′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestoreDisableSR ” = ’1′

What to do next...