beacucqitear.exe trying to run? Also Ptch_zaccess.six malware.

PatrickGSR94

New member
Member
VIP
Local time
1:30 AM
Messages
182
Wow did I really stump Google search on this? Read on...

This afternoon my Win7 x64 machine at my office started having its Trend Micro pop up about once every 1-2 minutes saying that some threat had been taken care of. It mentioned "PTCH_ZACCESS.SIX" and said the problem was in the Services.exe file in the system32 folder.

So I clicked on the details link which took me to this Trend site: PTCH_ZACCESS.SIX | Low Risk | Trend Micro Threat Encyclopedia

I decided to use the SFC method mentioned at the bottom. I rebooted into safe mode, and ran SFC on the services.exe file only. It said it was corrupt and said it repaired the problem. So I rebooted normally.

After my system came back up, I started Outlook 2010. Within seconds after Outlook 2010 started, the UAC popped up saying some file was trying to run, from C:\users\patrick\ and the file was beacucqitear.exe. I kept clicking NO but the thing kept popping up with no end.

So I did a hard shut down, rebooted again into safe mode. I navigated to that folder, and did a Shift+Delete on the file. After that I ran a registry search and deleted anything with "beacucqitear.exe" in it. Also ran a complete SFC operation and no problems were found.

I rebooted again normally and everything seems to be good now. What's odd is that I did a Google search on "beacucqitear.exe" and it found NO RESULTS! Really? Am I the first person in the entire world to have this file pop up on their system? Is there really ZERO information on the internet about it?

I don't know if that file has anything to do with that PTCH_ZACCESS thing or what. Hopefully I got everything sorted.
 

My Computer My Computer

At a glance

Windows 7 Professional x64Core i7-4790K Devil's Canyon Quad Core 4.0 GHzG.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x ...EVGA (nVIDIA) GTX 960 4 GB GDDR5
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom-built PC workstation
OS
Windows 7 Professional x64
CPU
Core i7-4790K Devil's Canyon Quad Core 4.0 GHz
Motherboard
ASUS Z97-E/USB3.1 ATX
Memory
G.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x 8GB)
Graphics Card(s)
EVGA (nVIDIA) GTX 960 4 GB GDDR5
Sound Card
on-board
Monitor(s) Displays
2x Dell Ultrasharp 24" U2415
Screen Resolution
2x 1920x1200
Hard Drives
Crucial MX200 500GB 2.5" SSD SATA III 6 GB/sec
PSU
Rosewill Glacier 700M 700-watt
Case
Fractal Design Define R4 Silent PC mid-tower
Cooling
OEM PSU cooler, 3x 140mm case fans (2 intake, 1 exhaust)
Keyboard
Logitech
Mouse
Logitech
Internet Speed
100+ Mbps
Antivirus
BitDefender
Browser
Firefox/Chrome
Beacucqitear.exe appeared on my computer a few hours ago. Shortly after that McAfee kept saying that it had detected and removed ZeroAccess trojan from my computer. This happened every time I rebooted and was followed by beacucqiter.exe trying to change my hard drive.

I tried various other software such as hitman pro, but nothing seemed to work. So in the end I just deleted beacucqiter.exe from c:\Users\thomas before removing anything in the registry containing the words beacucqiter. Things seem to be okey for now.

Googling beacucqitear.exe lead me here, which is the only place I've found that mentions beacucqiter.exe. Very strange!

Anyone have any thoughts?
 

My Computer My Computer

At a glance

Windows 7 Home premium 32bit
OS
Windows 7 Home premium 32bit
Lol yeah NOW Google has something on that file. But before I made this post it had nothing on it which is absolutely shocking to me.
 

My Computer My Computer

At a glance

Windows 7 Professional x64Core i7-4790K Devil's Canyon Quad Core 4.0 GHzG.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x ...EVGA (nVIDIA) GTX 960 4 GB GDDR5
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom-built PC workstation
OS
Windows 7 Professional x64
CPU
Core i7-4790K Devil's Canyon Quad Core 4.0 GHz
Motherboard
ASUS Z97-E/USB3.1 ATX
Memory
G.SKILL Ripjaws X Series 32 GB DDR3-1866 (4x 8GB)
Graphics Card(s)
EVGA (nVIDIA) GTX 960 4 GB GDDR5
Sound Card
on-board
Monitor(s) Displays
2x Dell Ultrasharp 24" U2415
Screen Resolution
2x 1920x1200
Hard Drives
Crucial MX200 500GB 2.5" SSD SATA III 6 GB/sec
PSU
Rosewill Glacier 700M 700-watt
Case
Fractal Design Define R4 Silent PC mid-tower
Cooling
OEM PSU cooler, 3x 140mm case fans (2 intake, 1 exhaust)
Keyboard
Logitech
Mouse
Logitech
Internet Speed
100+ Mbps
Antivirus
BitDefender
Browser
Firefox/Chrome
I came across the same beacucquitear.exe trying to run as a "dial up" pop up box asking for password and user; not letting me cancel any task;
so I forced the shutdown and started in safe mode.
Then searched for anything with that name (only one file appeared) cleaned it all and rebooted, searched again for anything beacucquitear.exe and finally it all seems clear and running OK - i also run antivirus scan and no threat detected

Seems this bug is quite new and no new in Google except for this forum
 

My Computer My Computer

At a glance

Windows 7 Home Premium 32bit
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home Premium 32bit
Hi,

Its a pity you guys deleted these files, if its something very new in the wild, it would be useful to upload it here:

https://www.virustotal.com/

Does anyone still have a sample?

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Hi,

Its a pity you guys deleted these files, if its something very new in the wild, it would be useful to upload it here:

https://www.virustotal.com/

Does anyone still have a sample?

Regards,
Golden

Sure do mate, was in my User profile sitting by itself. "Left Qualifier Winbond"

Uploaded n' scanned it just like you said, it came up with 3 hits :1 - ESET-NOD32 a variant of Win32/Kryptik.AJIK 2 - Kaspersky Trojan.Win32.Jorik.Totem.vr 3 - TrendMicro-HouseCall TROJ_GEN.F47V0802.

And Security essentials seems to be off and unable to reboot.
 
Last edited:

My Computer My Computer

At a glance

Vista 32bit
OS
Vista 32bit

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
So basically the defender did find a crap load of HKEY trojans and the like, it also found the file 'beacucqitear.exe' but it was unsure of it's nature so it sent it to Microsoft to determine if it was malicious or not. When I rebooted it was still the same, security Essentials was still locked down and the beacucqitear was trying to access permission. So I just did a system restore to 5 days ago and that worked. I did a full scan with SE, Malbytes, and a few other scanners after the restore and nothing was found.
 

My Computer My Computer

At a glance

Vista 32bit
OS
Vista 32bit
I would guess, based on what I've read about the new Sirefef variants, that these were either viruses imported by the main virus, or random generated names. The new Sirefef is capable of all these behaviors. It even has it's own storage space for viruses it imports.
 

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
I'm so new to this kind of thing... But I got that same Beacucqitear.exe poping up on my computer, and saying the whole "Left Qualifier Winbond" stuff.
I restarted in Safe Mode and deleted it.. It hasn't shown up since. Am I good? Or would it still be somewhere on my computer? Evry scan I run on McAfee says there's nothing there...

I'm a complete newbie, it took me about 15 minutes to even figure out how safe mode works. So i'm really unsure about what I should be doing. :/
 

My Computer My Computer

At a glance

Windows 7
Computer Manufacturer/Model Number
Acer
OS
Windows 7
Hi TooNew,

Follow my suggestion in post #7 above.

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Beacucqitear

I can't get rid of Beacucqitear. When I search and try to remove it says it can't be deleted because it is open in the Left Qualifier??
 

My Computer My Computer

At a glance

i dont know
OS
i dont know
running winxp but googling took me here so i'm posting my experience and the solution that worked for me.

had the same issue.

couldn't even delete beacucqitear.exe in safe mode with Admin rights, which was located in C:\Documents and Settings\Rich as a hidden file ....if u search for the file, be sure to include both hidden and system folders

i downloaded Windows Defender Offline but when i ran the program, it said i was missing and needed to install IMAPI 2.0 which i did at Download: Image Mastering API v2.0 (IMAPIv2.0) for Windows XP (KB932716) - Microsoft Download Center - Download Details

after running the M$ update, my drive actually vanished!.....even tried to get it back in the Device Manager / DVD/CD-ROM drives where the drive was being shown with a yellow exclamation point ie not recognizable or bad drive or missing driver.

i tried to update it but nothing, so i uninstalled my dvd drive and rebooted thinking it would come back, it didn't.

i therefore ran a system restore from a few days earlier [Start / Programs / Accessories / System Tools / System Restore

and now everything is back to normal and Norton is showing a clean computer.

even that beacucqitear.exe is gone after running a full search on it! :D
 

My Computer My Computer

At a glance

Windows XP x86
OS
Windows XP x86
Hey guys i just got this problem right now i sorta? fixed it but the file is still in my users area but nod 34 has it locked down but i still want it gone but im not a fan of going back 5 days as i have got lots of videos and other items that i need :P and un able to back up when i try to delete it it just says you do not have the rights -.- when i am the Admin on my pc so not sure what to do on this one ;O i am a pc nerd but when it comes to viruses im a derp :) any help would be most welcomed!

Also really worried as my Nod 32 seams to be turned off :( and i can not for the life of me turn it back on even with restarts
 

My Computer My Computer

At a glance

windows 7
OS
windows 7
Am not a profi...

yesterday Mc'Affee found ZeroAccess in several endings. (.ee .eu .el) and gets this message regularly.. told me it is removed.

today beacucqitear.exe popped up - that it wants to do changes on the computer.. i denied..

deleted

now the firewall is deactivated...

whenever i try to activate McAffee firewall.. it deactivates itself within one or two seconds...
 

My Computer My Computer

At a glance

Windows 7 Professional 32 bit
OS
Windows 7 Professional 32 bit
Am not a profi...

yesterday Mc'Affee found ZeroAccess in several endings. (.ee .eu .el) and gets this message regularly.. told me it is removed.

today beacucqitear.exe popped up - that it wants to do changes on the computer.. i denied..

deleted

now the firewall is deactivated...

whenever i try to activate McAffee firewall.. it deactivates itself within one or two seconds...

It was doing the same thing to me mate. Can you do a system restore to a earlier point? IE before it was doing it? Because I booted Windows Defender off a USB, and tons of scans but the only thing that really worked was doing a system restore to before it starting happening. Just type 'System Restore' in your windows search bar and run it. Try that.
 

My Computer My Computer

At a glance

Vista 32bit
OS
Vista 32bit

My Computer My Computer

At a glance

windows 7 home premium x64AMD Athlon 64 x2 5200+7.00GBNVIDIA GeForce 9600GT
OS
windows 7 home premium x64
CPU
AMD Athlon 64 x2 5200+
Motherboard
M2N-SLI DELUXE
Memory
7.00GB
Graphics Card(s)
NVIDIA GeForce 9600GT
Sound Card
High Definition Audio Device
Monitor(s) Displays
Q19wb
Screen Resolution
1400 x 900
Hard Drives
ST325082 0AS SCSI 232.88 GB

My Computer My Computer

At a glance

Windows XP x86
OS
Windows XP x86
Hi,

If this is a newer variant of the Sirefef malware, you are strongly advised to wipe your systems and install from scratch:

For wiping previous installations:
http://www.sevenforums.com/tutorials/52129-disk-clean-clean-all-diskpart-command.html

For retail Windows 7 installations:
http://www.sevenforums.com/tutorials/1649-clean-install-windows-7-a.html

For OEM (pre-installed) Windows 7 installations:
http://www.sevenforums.com/tutorials/219487-clean-reinstall-factory-oem-windows-7-a.html

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top