Hi guys,
I have those things in the Run section of Registry

Key Name: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Class Name: <NO CLASS>
Last Write Time: 12/2/2008 - 1:07 PM
Value 0
Name: CTFMON.EXE
Type: REG_SZ
Data: C:\WINDOWS\system32\ctfmon.exe

Value 1
Name: CPMebc86926
Type: REG_SZ
Data: Rundll32.exe "c:\windows\system32\dumepiwo.dll",a

Value 2
Name: e8fb5aba
Type: REG_SZ
Data: rundll32.exe "C:\WINDOWS\system32\suvatepe.dll",b

Value 3
Name: hovevifedi
Type: REG_SZ
Data: Rundll32.exe "C:\WINDOWS\system32\lameweka.dll",s

Any idea what they are?
Thanks.

Apparently they are not there anymore, there are 3 rundll messages come up with error loading ......
Google it does not come up with anything.


Powerthink

Dani AI

Generated

The entries described by — Run-key values that launch DLLs through rundll32 and then later produce rundll load errors — are classic signs of DLL-based persistence. Malware often creates randomly named Run values that call a DLL export with a short name (single-letter exports are common). The disappearing DLLs plus error popups usually mean the files were removed but their startup entries were left behind, which still triggers rundll32 to try loading them.

's suggestion to run Malwarebytes is appropriate. A practical cleanup workflow that complements that scan:

  • Boot to Safe Mode (or Safe Mode with Networking) and update an on-demand scanner such as Malwarebytes. Run a full scan and remove all detections.
  • Use Sysinternals tools to find and remove leftovers. Autoruns will show Run keys, Scheduled Tasks and service autostarts; uncheck or delete suspicious entries and save the Autoruns report. Process Explorer helps inspect running processes and loaded modules if anything still runs.
  • Inspect Scheduled Tasks, Services, Winlogon/Userinit, and the usual Run keys (HKCU/HKLM). If DLL files are locked, deletion from a recovery environment or offline scan/rescue media is effective.

Additional notes and cautions: removable drives are common infection vectors — any USB stick involved should be scanned from a clean system before reuse. Important user data should be backed up and scanned separately; if system integrity is uncertain after cleanup, reimaging is the safest final step. Keep MBAM and Autoruns logs for later review or forensic needs.

Recommended Answers

All 2 Replies

The first is a system file, the others pests.
==Please download Malwarebytes' Anti-Malware
from: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
or: http://www.besttechie.net/tools/mbam-setup.exe
=Dclick that file, mbam-setup.exe, to install the application,
-ensure that it is set to update and start, else start it via the icon.
Select "Perform Quick Scan", then click Scan; the application will guide you through the remaining steps.
ENSURE that EVERYTHING found has a CHECKMARK against it, then click Remove Selected.
If malware has been found [and removed] MBAM will automatically produce a log for you... do not click the Save Logfile button.
When it completes examine the log: if some files are listed as Delete on Reboot then restart your machine before continuing.
Post the Notepad log [it is also saved under Logs tab in MBAM].

Hi Gerbil,
Thanks for your advice.
At this time of the year I have to reimage that laptop. But for more information that happened when an African guy plug the usb into her laptop.
Cheers

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.