I have a strange process

McSeven

New member
that I disabled. It's name is 'bcfcabcedfbedc.exe'.

Could this be a trojan or keylogger or something else bad?

How can I delete this process entry? I can't find it in 'msconfig'.

Thanks.

Windows 7 Prof x64
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HomieJunker
OS
W7 Prof 64 bit
CPU
i7-3770k
Motherboard
Sabertooth Z77
Memory
G.Skill Sniper 1866 16 GB
Graphics Card(s)
Evga GTX 770
Sound Card
Sound Blaster Z
Monitor(s) Displays
Asus VG278HE
Screen Resolution
1920 x 1080
Hard Drives
4 Seagate Barracudas 250 GB
2 Intel® X25-M 160GB
PSU
Corsair H1000X
Case
Lian-Li A77B
Cooling
Phantek 120 dual fans
Keyboard
Corsair K70 RGB
Mouse
Logitech G502
Internet Speed
FiOS Quantum
Antivirus
Avira
Browser
Chrome

My Computer

Computer Manufacturer/Model Number
Keeps changing - (Custom)
OS
Windows 7 Professional x64
CPU
Intel Core i7 860
Motherboard
Gigabyte GA-P55-UD4P
Memory
4GB DDR3 Mushkin 1600Mhz @ 7-8-7-20
Graphics Card(s)
MSI GTS250 1GB DDR3 Twin Frozr
Sound Card
Onboard realtek
Monitor(s) Displays
Samsung SyncMaster 24" P2450 + Samsung 20" 2033
Screen Resolution
1920 X 1080 and 1600 X 900 (#2 system 1440 X 900)
Hard Drives
Patriot Inferno 120GB SSD + 3 WD Blue 640GB drives
PSU
Corsair 750 HX Modular
Case
Lancool PC-K62
Cooling
Cooler Master TX3 CPU cooler and 4-140mm and 1-120mm case
Keyboard
Gigabyte USB keyboard
Mouse
Microsoft wireless laser mouse 5000
Internet Speed
7 Mb down 1.5 up
Other Info
System #2: AMD Phenom II X6 1055T (Freezer 7 Pro cooler) - Gigabyte 880GMA-UD2H - WD 500GB Black - 9500GT (1GB) 500W OCZ modular PSU - Antec 200 case. System #3 (LapTop) Core 2 Duo T6670 - 320GB 7200RPM HD - 4GB DDR3 RAM.
Try right clicking the process and go to properties.

Find where it is located.
Check spelling and post back.
 

My Computer

OS
Windows 7 Ultimate x86 SP1
that I disabled. It's name is 'bcfcabcedfbedc.exe'.

Could this be a trojan or keylogger or something else bad?

How can I delete this process entry? I can't find it in 'msconfig'.

Thanks.

Windows 7 Prof x64

use ccleaner to delete entry.. must scan with malwarebytes
 

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB
I have Avira and it had caught a Trojan. But this entry in the Process table is there and Disabled. I can not find the file on my computer. I had send the file to Avira and they are checking it out. But I don't think my computer currently at risk.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HomieJunker
OS
W7 Prof 64 bit
CPU
i7-3770k
Motherboard
Sabertooth Z77
Memory
G.Skill Sniper 1866 16 GB
Graphics Card(s)
Evga GTX 770
Sound Card
Sound Blaster Z
Monitor(s) Displays
Asus VG278HE
Screen Resolution
1920 x 1080
Hard Drives
4 Seagate Barracudas 250 GB
2 Intel® X25-M 160GB
PSU
Corsair H1000X
Case
Lian-Li A77B
Cooling
Phantek 120 dual fans
Keyboard
Corsair K70 RGB
Mouse
Logitech G502
Internet Speed
FiOS Quantum
Antivirus
Avira
Browser
Chrome
I have Avira and it had caught a Trojan. But this entry in the Process table is there and Disabled. I can not find the file on my computer. I had send the file to Avira and they are checking it out. But I don't think my computer currently at risk.

hopefully.. but if i were u.. then i must do scan with malwarebytes..
 

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB
Got rid of this bugger using Registry Crawler.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HomieJunker
OS
W7 Prof 64 bit
CPU
i7-3770k
Motherboard
Sabertooth Z77
Memory
G.Skill Sniper 1866 16 GB
Graphics Card(s)
Evga GTX 770
Sound Card
Sound Blaster Z
Monitor(s) Displays
Asus VG278HE
Screen Resolution
1920 x 1080
Hard Drives
4 Seagate Barracudas 250 GB
2 Intel® X25-M 160GB
PSU
Corsair H1000X
Case
Lian-Li A77B
Cooling
Phantek 120 dual fans
Keyboard
Corsair K70 RGB
Mouse
Logitech G502
Internet Speed
FiOS Quantum
Antivirus
Avira
Browser
Chrome
that I disabled. It's name is 'bcfcabcedfbedc.exe'.

Could this be a trojan or keylogger or something else bad?

How can I delete this process entry? I can't find it in 'msconfig'.

Thanks.

Windows 7 Prof x64

Whatever it is not too common. I put it into google and only one hit, guess what its your post. Anyway, Happy New Year.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
that I disabled. It's name is 'bcfcabcedfbedc.exe'.

Could this be a trojan or keylogger or something else bad?

How can I delete this process entry? I can't find it in 'msconfig'.

Thanks.

Windows 7 Prof x64

Whatever it is not too common. I put it into google and only one hit, guess what its your post. Anyway, Happy New Year.


lololol
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HomieJunker
OS
W7 Prof 64 bit
CPU
i7-3770k
Motherboard
Sabertooth Z77
Memory
G.Skill Sniper 1866 16 GB
Graphics Card(s)
Evga GTX 770
Sound Card
Sound Blaster Z
Monitor(s) Displays
Asus VG278HE
Screen Resolution
1920 x 1080
Hard Drives
4 Seagate Barracudas 250 GB
2 Intel® X25-M 160GB
PSU
Corsair H1000X
Case
Lian-Li A77B
Cooling
Phantek 120 dual fans
Keyboard
Corsair K70 RGB
Mouse
Logitech G502
Internet Speed
FiOS Quantum
Antivirus
Avira
Browser
Chrome
I would suggest running Malwarebytes' Anti-Malware, just to make sure you got all the malware off your machine.
Chances are, this file didn't come by itself.

download Malwarebytes' Anti-Malware to your desktop
|MG| Malwarebytes Anti-Malware 1.43 Download
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I would suggest deleting withou thinking about it twice.
I would be dumb(and every body else too) if you even think about believing that process with name such abcdbcdefgabc.exe could be legit process.
Try to remember did you visit one of the "black" sites(maybe unintentionally) with keygens,cracked apps,etc.,cause I remember that I get process named abcd.exe once,from that kind of site.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
intel x58 selfmade
OS
Windows 7 Ultimate x64
CPU
[email protected] (non overclocked)
Motherboard
x58
Memory
8gb DDR3
Graphics Card(s)
Asus 6850
Monitor(s) Displays
lg 22"
Hard Drives
1TB
PSU
Corsair 650w
Case
Gigabyte
Cooling
Scytech
Keyboard
noname
Mouse
Logitech wireless xy
Internet Speed
70GB
Antivirus
Windows Defender
Browser
Chrome (default)
I would suggest running Malwarebytes' Anti-Malware, just to make sure you got all the malware off your machine.
Chances are, this file didn't come by itself.

download Malwarebytes' Anti-Malware to your desktop
|MG| Malwarebytes Anti-Malware 1.43 Download
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.


Ok, I ran it and it found the following ...

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

But I don't know what it really means.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HomieJunker
OS
W7 Prof 64 bit
CPU
i7-3770k
Motherboard
Sabertooth Z77
Memory
G.Skill Sniper 1866 16 GB
Graphics Card(s)
Evga GTX 770
Sound Card
Sound Blaster Z
Monitor(s) Displays
Asus VG278HE
Screen Resolution
1920 x 1080
Hard Drives
4 Seagate Barracudas 250 GB
2 Intel® X25-M 160GB
PSU
Corsair H1000X
Case
Lian-Li A77B
Cooling
Phantek 120 dual fans
Keyboard
Corsair K70 RGB
Mouse
Logitech G502
Internet Speed
FiOS Quantum
Antivirus
Avira
Browser
Chrome
I would suggest running Malwarebytes' Anti-Malware, just to make sure you got all the malware off your machine.
Chances are, this file didn't come by itself.

download Malwarebytes' Anti-Malware to your desktop
|MG| Malwarebytes Anti-Malware 1.43 Download
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.


Ok, I ran it and it found the following ...

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

But I don't know what it really means.
Your system is clean
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Ok, I guess all is well for now, so I thank everyone's help!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HomieJunker
OS
W7 Prof 64 bit
CPU
i7-3770k
Motherboard
Sabertooth Z77
Memory
G.Skill Sniper 1866 16 GB
Graphics Card(s)
Evga GTX 770
Sound Card
Sound Blaster Z
Monitor(s) Displays
Asus VG278HE
Screen Resolution
1920 x 1080
Hard Drives
4 Seagate Barracudas 250 GB
2 Intel® X25-M 160GB
PSU
Corsair H1000X
Case
Lian-Li A77B
Cooling
Phantek 120 dual fans
Keyboard
Corsair K70 RGB
Mouse
Logitech G502
Internet Speed
FiOS Quantum
Antivirus
Avira
Browser
Chrome
Ok, I ran it and it found the following ...

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

But I don't know what it really means.

Don't worry, false Positive.
more info: (Hijack.DisplayProperties) - Malwarebytes Forum

Malwarebytes Staff said:
Hello

It is not an actual infection, but instead a non-default setting that is often altered by actual infections, however, in Windows Vista and Windows 7 Microsoft changed the default setting to the opposite of what it was in XP so on Vista and Windows 7 systems (such as your own) this detection should be ignored .

If you need anything else please post.

Thanks

McSeven From your log I can see that it was quarantined and deleted. You should fix it as it's Windows native component.
And then run quick scan and when it finds it tell it to ignore it.

How to fix it: (Hijack.DisplayProperties) - Malwarebytes Forum
 

My Computer

OS
Windows 7 Ultimate x86 SP1

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top