We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

What is sbubeper.dll?

13

Comments

  • RussJK
    RussJK Posts: 2,359 Forumite
    edited 23 April 2011 at 3:28PM
    Yes restart, then do a followup quick scan with Malwarebytes which should take less than ten minutes. Also please run a HijackThis log for me after the reboot (run as administrator, don't 'Fix' anything though just need the log).

    I would suggest you fix the defaults of Avira. I can't remember all the settings as I haven't used it in awhile, but the main points I've already mentioned (heuristics on scanner and on resident guard, and make sure it finds PUPs).

    I'm need to go out for a bit, but after you post the HijackLog then I'd suggest you go into Safe Mode and run a full system scan with Avira on highest settings.

    I'll post some other suggestions later on after you've cleaned up to help prevent this from happening again. Giraffe is correct that you need to be on SP3 for starters.
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    I restarted. Before it closed I got (I'm paraphrasing a bit): The instruction referenced memory that could not be read @ 0x771248c0. The memory cannot be read.
    I got a similar message last time I closed down but didn't take much notice (I was only using WMP and didn't take much notice cos I wasn't connected to the internet). I also got "MB Cannot Quit". I'm assuming Malwarebytes.

    Upon restart I got the same error loading message, except this time: uzumicojagiq.dll.

    Malwarebytes log coming up...
    The View Belongs To Everyone
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    I didn't fix the fault with AntiVir before restarting. Damn. There was no pop up this time though.
    The View Belongs To Everyone
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    No AntiVir pop-up.

    Malwarebytes found nothing malicious so didn't give me an option to save the log.
    The View Belongs To Everyone
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    I only turned on my computer for WMP (no internet intended). Blimey!
    The View Belongs To Everyone
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    What defaults can I change with AntiVir? I would have thought it would be set up properly.
    The View Belongs To Everyone
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    Just got a pop-up from Avira...

    A virus or unwanted program 'JAVA/Agent.JZ was found in the file 'G:\Documents and Settings\pd...\537dd90b-51d2ae42' (I don't know the full path after the ... ) This was only after connecting to the internet. I use my mobile as a modem if that's of any use. I've moved it to the quarantine this time though.
    The View Belongs To Everyone
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    Malwarebtaes log:

    Malwarebytes' Anti-Malware 1.50.1.1100
    https://www.malwarebytes.org

    Database version: 6424

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 6.0.2900.2180

    23/04/2011 16:57:11
    mbam-log-2011-04-23 (16-57-11).txt

    Scan type: Quick scan
    Objects scanned: 136314
    Time elapsed: 8 minute(s), 16 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    The View Belongs To Everyone
  • MilkyJoe
    MilkyJoe Posts: 505 Forumite
    Part of the Furniture Combo Breaker
    That could be the previous log actually. It's still scanning.

    Why did I have to drink so early?
    The View Belongs To Everyone
  • RussJK
    RussJK Posts: 2,359 Forumite
    MilkyJoe wrote: »
    What defaults can I change with AntiVir? I would have thought it would be set up properly.

    I've already said twice now - set heuristics to high (default is medium) on both the scanner, and on the resident guard; look at the Extended Threat Categories for Detection and check things like "potentially unwanted programs". There are other things as well, such as setting it to Guard Start mode that I would do. The only drawback of setting the heuristics to high is that you might get false positives.

    Don't worry about the errors you mentioned unless they keep happening.

    Just go through what I've written and make sure you've done each step, otherwise I'm just repeating myself.

    You still need to put in a HijackThis log... I've been literally asking since the beginning of the thread in post #2:
    http://forums.moneysavingexpert.com/showpost.php?p=43078036&postcount=2

    Have you disabled system restore as in post #7:
    http://forums.moneysavingexpert.com/showpost.php?p=43078606&postcount=7

    Also have you replaced the hosts file yet?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.2K Work, Benefits & Business
  • 600.9K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.