Author Topic: win32/malum.dkfm  (Read 5683 times)

0 Members and 1 Guest are viewing this topic.

Prof-rabbit

  • Guest
win32/malum.dkfm
« on: June 25, 2007, 03:02:08 AM »
I have just had a phone call from a friend, Avast home has reported the virus win32/malum.DKFM
quote: lock into c:\windows\cdrun.exe>c.exe
(no treatment available)

A google search shows only one reference from CA

Any help would be appreciated

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: win32/malum.dkfm
« Reply #1 on: June 25, 2007, 02:58:28 PM »
Whilst you report no treatment available, I haven't a clue what that means. avast offers a number of options Repair (which is unlikely to work if the file is completely malicious and or not covered by the VRBD), Move to chest, Move/Rename, Delete, etc. The Move to chest is usually the recommended option 'first do no harm' and investigate.

So we need more information on this 'no treatment available' statement, what option did they choose and what happened ?
What is their operating system ?

If XP have them enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, Menu, 'Schedule boot-time scan...' and when detected send to the avast Chest. Or see http://www.digitalred.com/avast-boot-time.php

I don't know what you were searching for but cdrun.exe and c.exe return many hits.
http://spywaredlls.prevx.com/RRHICF20440/CDRUN.EXE.html

If you searched for the virus name then you are less likely to turn up as many hits ast there is no standard naming convention so it may be easier to search for the file name or just the virus family name, win32:malum for general information in the virus, http://www.google.com/search?q=win32%3Amalum, lots of hits.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Prof-rabbit

  • Guest
Re: win32/malum.dkfm
« Reply #2 on: June 25, 2007, 03:43:32 PM »
Whilst you report no treatment available, I haven't a clue what that means. avast offers a number of options Repair (which is unlikely to work if the file is completely malicious and or not covered by the VRBD), Move to chest, Move/Rename, Delete, etc. The Move to chest is usually the recommended option 'first do no harm' and investigate.

So we need more information on this 'no treatment available' statement, what option did they choose and what happened ?
What is their operating system ?

The virus was detected during an autoscan, O/S is XP sp2, the "no treatment available" is in the avast screen, the move/rename/chest options are greyed out (unavailable)
I have not seen the computer at this point so this is about as much as I know, searching for win32/malum on several anti-virus sites brings up very little although "malum virus" is slightly better.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: win32/malum.dkfm
« Reply #3 on: June 25, 2007, 03:56:54 PM »
I have 'never' seen this "no treatment available" that you are talking about, can you do a screenshot as I don't know if there might be a problem with your friends avast installation ?

Using the / in the virus name may through the search engines and it is usually a colon : used as a separator or a period, that doesn't seem to effect the search engines.

Try a repair of avast. Add Remove programs, select 'avast! Anti-Virus,' click the Change/Remove button and scroll down to Repair, click next and follow. You need to be on-line to do this.

Then have him schedule a boot-time scan.

This is where trying to resolve a problem via a third party is difficult, is ther a reason why your friend can't participate ?
Other than the obvious infection, have him rename the file to cdrun_exe.old that should stop anything that would call the original file name unable to use it. Notice I didn't say delete it as that really is the nuclear option and we aren't even at war yet.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Prof-rabbit

  • Guest
Re: win32/malum.dkfm
« Reply #4 on: June 25, 2007, 04:01:59 PM »
I have 'never' seen this "no treatment available" that you are talking about, can you do a screenshot as I don't know if there might be a problem with your friends avast installation ?

Using the / in the virus name may through the search engines and it is usually a colon : used as a separator or a period, that doesn't seem to effect the search engines.

Try a repair of avast. Add Remove programs, select 'avast! Anti-Virus,' click the Change/Remove button and scroll down to Repair, click next and follow. You need to be on-line to do this.

Then have him schedule a boot-time scan.

This is where trying to resolve a problem via a third party is difficult, is ther a reason why your friend can't participate ?

Yes I intend to do a boot scan when I go over there, I can't get him on (not really computer savvy re. forums and slow speed dial up)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: win32/malum.dkfm
« Reply #5 on: June 25, 2007, 04:18:16 PM »
Slow speed dial-up here too, we promise not to bite ;D that way her may learn something into the bargain.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Prof-rabbit

  • Guest
Re: win32/malum.dkfm
« Reply #6 on: June 25, 2007, 05:26:02 PM »
Slow speed dial-up here too, we promise not to bite ;D that way her may learn something into the bargain.

Well if you can wait till wednesday Aussie time I'll see what I can do   :>

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: win32/malum.dkfm
« Reply #7 on: June 25, 2007, 06:15:50 PM »
No problem, it isn't a requirement, you can keep helping as best you can.

Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: win32/malum.dkfm
« Reply #8 on: June 25, 2007, 08:26:11 PM »
Hi Prof-rabbit

Win32.Rbot.DUA is an IRC controlled backdoor (or "bot") that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is highly configurable, and is being very actively developed, however the core functionality is quite consistent between variants.

IMPORTANT NOTE: Backdoor Trojans are very dangerous because they provide a means of accessing a computer system that bypasses security mechanisms. Remote attackers use backdoor Trojans as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge. If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums. You should consider all your passwords to be compromised. They should be changed by using a different computer and not the infected one. Do not change passwords or do any transactions while using the infected computer because an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breech.

Turn off system restore (Right click my comp./propertys/system restore/ put a check in "turn off system restore")
Download install & update Trojan Remover then boot to safe mode, (F8 while you are booting up) then run a good AT program  in safe mode , then run your anti-virus program in safe mode also
Reboot to normal mode

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!