YW9467.exe?

Discussion in 'Malware Help (A Specialist Will Reply)' started by VictoriaL, Jun 21, 2006.

  1. VictoriaL

    VictoriaL Private E-2

    I found a process running by the name of YW9467.exe. I tried Googling it but Google did not match any documents. Anyone know what this is?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Where is it located as in which folder location?

    If you right click it and choose properties in version info does it give you any hints to the company that developed it?


    Are you experiencing any adverse effects as in popups, spyware etc? if so then please follow our standard cleaning procedures below.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    .
     
  3. VictoriaL

    VictoriaL Private E-2

    When I search for the exe on my hard drive, it's located in C:\Windows\Temp and when I right click to properties, it doesn't give me any property values whatsoever. The only bit of info I gained from checking is it's location on my hard drive, it's size (172 KB), it's last modification on Nov. 5, 2005 however it also says it was created and accessed on Jun 21, 2006, and it's icon is a little running olive green scotty type dog with a black collar. :confused:
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the directions posted by Halo, this staps are necessary to provide you help. THe logs from the procedure will give us a clearer picture of what we are dealing with.
     
  5. VictoriaL

    VictoriaL Private E-2

    When I started my computer this morning I checked to see if the process was running. The name YW9467.exe doesn't appear in my processes log, however a different process named UMB3B1.exe was running. When I did a search for the latter process, it took me to the same location, same icon, the only difference is the name change. Another thing I've noticed is it's memory usage never changes. Never more, never less than 2,448K.

    I don't know if this makes a difference, however this is my work computer, we're on a network, we have a network admin. etc. I know we have a firewall,Trend Micro is always running, I don't open email attachments from unknown sources and I don't download anything from the internet, so I'm not convinced this is something I picked up. I've always thought my employer has a running program that "spies" on our computers, maybe this is it?

    It makes me a little nervous to follow your suggestions because I don't know if it will have any effect my computer and/or how it runs on the network? I don't know if that even makes sense to you, but what I'm trying to say is I don't want the "clean-up" process to do something to where I'd end up having to get network admin. involved. If you guys say it won't, then I'll go ahead and give it a shot.
     
  6. VictoriaL

    VictoriaL Private E-2

    Ok, just out of curiosity I restarted my computer to see if the process would change names, and it did. Now it's name is PLABEE.exe...nothing comes up from Googling it either.
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Stop rebooting your computer.

    Follow the instructions posted, and do not reboot your computer until your a told to do so.

    Until you complete the instructions given and post the requireed logs; we do not know what we are dealing with.
     
  8. VictoriaL

    VictoriaL Private E-2

    So you're saying it's ok to do this considering my situation mentioned in my previous post?
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    We are trying to help you. Until you complete the instructions that were given we can not formulate a fix for you particular set of infections.

    Once you have completed all the scans, in order, as stated in the instructions and reboot back to Normal Mode to run HijackThis do not reboot again until you are instructed to do so.

    It does no good to tell you to delete a file, when all that will happen is it will respawn with a different name because we haven't removed the files and registry keys responsible for this behavior. I can't tell you what needs to be deleted and what cleaning procedures to use until you follow the instructions that were given and post the required logs.

    EDIT: If this is a company computer than you need to contact your IT department for your employer. If your employer is running software to monitor their employees computer actvities, than that is their prerogative and completely legal.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds