Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Very weird process running on startup / Malwarebytes' Anti-Malware log  (Read 4786 times)

0 Members and 1 Guest are viewing this topic.

alyoob

    Topic Starter


    Intermediate

    Thanked: 1
    • Experience: Experienced
    • OS: Windows 8
    I found this weird program that has a checked next to it on msconfig with the name NFEBBYTVWVXQWVU it is located in the folder C:\WINDOWS\SYSTEM32\NFEBBYTVWVXQWVU.DLL. The program was detected with malwarebytes. Here is what it also found when it scanned my computer. What should I do with the results? Should I deleted all the entries.

    Malwarebytes' Anti-Malware 1.30
    Database version: 1429
    Windows 5.1.2600 Service Pack 3

    11/28/2008 9:30:41 PM
    mbam-log-2008-11-28 (21-30-41).txt

    Scan type: Quick Scan
    Objects scanned: 66435
    Time elapsed: 14 minute(s), 30 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 4
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{6e9abc7b-5ef6-7638-2daa-70daba80a092} (Adware.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{6e9abc7b-5ef6-7638-2daa-70daba80a092} (Adware.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{9ffb97e7-fb35-8a66-8452-94ec67204007} (Adware.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9ffb97e7-fb35-8a66-8452-94ec67204007} (Adware.BHO) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\ljyogiusmncuabbo (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\nfebbytvwvxqwvu.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\pmgubosyuby.dll (Adware.BHO) -> Quarantined and deleted successfully.

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS

    CBMatt

    • Mod & Malware Specialist


    • Prodigy

    • Sad and lonely...and loving every minute of it.
    • Thanked: 167
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Re: Very weird process running on startup / Malwarebytes' Anti-Malware log
    « Reply #2 on: November 29, 2008, 03:35:40 AM »
    Actually, the files have already been deleted by MBAM.  But please follow the link posted above and post all 3 logs.
    Quote
    An undefined problem has an infinite number of solutions.
    —Robert A. Humphrey

    alyoob

      Topic Starter


      Intermediate

      Thanked: 1
      • Experience: Experienced
      • OS: Windows 8
      Re: Very weird process running on startup / Malwarebytes' Anti-Malware log
      « Reply #3 on: November 29, 2008, 09:26:43 AM »
      Here are the logs requested

      [Saving space - attachment deleted by admin]

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Very weird process running on startup / Malwarebytes' Anti-Malware log
      « Reply #4 on: November 29, 2008, 01:10:05 PM »
      Everything looks OK. How is the computer running now?

      Your Java is out of date.

      Older versions have vulnerabilities that malicious sites can use to infect your system.

      First install the new Sun Java Runtime Environment

      Be sure to close all browser windows before beginning the install.

      Remove the old version(s)

      Download JavaRa
      • Unzip the file and open the JavaRa.exe
      • Click Remove Older Versions
      • JavaRa will search for and remove any outdated version of Java and remove any that are found.
      • Click Additional Tasks
      • Place a check next to Remove Useless JRE Files and click Go
      • Exit JavaRa
      • Delete the JavaRa files from the Desktop

      alyoob

        Topic Starter


        Intermediate

        Thanked: 1
        • Experience: Experienced
        • OS: Windows 8
        Re: Very weird process running on startup / Malwarebytes' Anti-Malware log
        « Reply #5 on: November 29, 2008, 04:25:07 PM »
        The computer is running fine thanks for your help.

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Very weird process running on startup / Malwarebytes' Anti-Malware log
        « Reply #6 on: November 29, 2008, 04:36:29 PM »
        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.