Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

What is Bpfbme32.exe?

Status
Not open for further replies.

TheLumberingAdmin

IS-IT--Management
Sep 10, 2003
19
US
Have a WinXP Pro computer on our network that's been have a few problems. For the past few weeks, when the computer is shut down, a "waiting for program to close" box pops up with the above program (Bpfbme32.exe). It will close when you kill the process, but otherwise won't.

I had already run two scans with McAfee on this computer (after this started happening), but found nothing. This morning, McAfee listed this file as infected with a backdoor/trojan, and was unable to clean or delete the file. I rebooted into safe mode, and went looking for the file to delete it manually, but it was no longer there. There was, however, a prefetch file (in windows\prefetch) with that file's name in it.

Is it possible that the program file is only generated when triggered, and deleted at shutdown? Or do you think McAfee queued it for deletion at next startup and got rid of it?

I tried looking up the file name on every search engine I could think of, (and on McAfee's and Symantec's websites) but found absolutely no mention of it anywhere. Does anyone have a clue what said file is? Maybe just a virus/trojan with a randomly generated name?
 
Looks like it was just a randomly-named file (meant to look like a system file of some sort); it was a self extracting archive, containing the Backdoor-AJX trojan (a keystroke logger!). I guess it was attempting to extract, but wasn't able to, and that's why the program would not close at shutdown. Thanks for your help anyway, bcastner. I'm goign to run CWShredder on it anyway (already ran Ad-aware, came up with a few other bits), because if THAT was on there...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top