unknown process running ipkbynop.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by FED UP, Apr 16, 2008.

  1. FED UP

    FED UP MajorGeek

    I have Zone Alarm telling me that Windows Explorer is trying to access web, as well as Sun Java . I recently downloaded an application that turned out to be malicious. I tried to clean up the mess, but i have ipkbynop.exe on my process list, Google has no results when i search for it, and Process Library has no information on it . Im wondering if this is a problem, and am denying access of Windows Explorer and Sun Java to the web until I found out if this is something malicious .
    Does anyone know what ipkbynop.exe is ?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    With such a random collection of characters its possible its a malware file, as they tend to hide themselves as such, Java and Win Explorer would generally try to connect to web or more so Sun Java as by default its updater is in your run hive, Win Explorer is likely to be wanting local access.

    But run the below to double check malware, attach all the requested logs so the malware experts can review them, if they find anything they will post some manual removal instructions for you

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. FED UP

    FED UP MajorGeek

    Ok . Processes completed, log files attached. Im pretty sure i did everything correctly .
    Spybot S&D came up clean (no logfile)
    final log in next message
     

    Attached Files:

  4. FED UP

    FED UP MajorGeek

    Superantispyware log attached here .
    Awaiting analysis by the pros !
    :major

    thanx y'all !
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like the scanners got rid of your main problems. I do have a couple minor things for you to do but are you actually having any problems now?


    Uninstall the below old versions of software:
    Java(TM) 6 Update 4


    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.
     
  6. FED UP

    FED UP MajorGeek

    Java Updated .
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) REMOVED . (What was that item related to, anyway ?)

    Things seem to be running smoothly . Only question i have now is, when shutting the computer down, and i have no applications active other than antivirus and firewall,no windows of any kind open, i hear the error tone "ding" but no error message shows . What is this about ?



    Thanks for your help
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A left over from Real Player.

    The system always has more running that you see. Just look at the process list in your HijackThis log in the MGlogs.zip file to see them.

    Unknown. Probably related to some application that Windows is trying to terminate during shutdown.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds