Author Topic: wmram.exe  (Read 16691 times)

0 Members and 1 Guest are viewing this topic.

sabit

  • Guest
wmram.exe
« on: July 26, 2005, 09:25:01 AM »
There is an exe file in c:\winnt\system32 named wmram.exe it periodically spawn several of its own instances and bogs down the system to halt. Avast or Spybot does not detect it as suspicous activity. Where should I post the exe for inspection?

Omar

  • Guest
Re: wmram.exe
« Reply #1 on: July 26, 2005, 11:38:49 AM »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: wmram.exe
« Reply #2 on: July 26, 2005, 01:59:37 PM »
I'm sad to note another detection failure  :'(  :P
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89131
  • No support PMs thanks
Re: wmram.exe
« Reply #3 on: July 26, 2005, 02:55:54 PM »
Google only finds one hit for this (.pl site) so if it was known, I would have expected many more, so this could quite well be a new or modified variant of adware/spyware.

The .pl link shows three hits, this is one http://forum.gazeta.pl/forum/72,2.html?f=430&w=25418562&a=25419031 and this shows it being shown in HiJackThis so it should be able to fix it by deleting the run command, stopping the process in task manager and then delete the file.

Also useful as a diagnostic tool - Download HiJackThis.zip - HJT Information HiJackThis Tutorial 1 or HiJackThis Tutorial 2
For an on-line analysis - HiJackThis Log file - On-line Analysis
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
OR HiJackThis Log file - On-line Analysis 2

OR
- Post your hijackthis-Log here for a diagnosis: tomcoyote.org/hjt
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: wmram.exe
« Reply #4 on: July 26, 2005, 06:47:02 PM »
Hello sabit,

I have read the advice on the polish reference at Gazeta.pl forum (the biggest online magazine of Poland) and I suggest you download Toolbarcop 3.3. at this link:
http://www.majorgeeks.com/download4126.html to take this BHO out in a decent way, success,

Have a nice day,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89131
  • No support PMs thanks
Re: wmram.exe
« Reply #5 on: July 26, 2005, 07:15:50 PM »
Very handy having someone on the forums who can read Polish 'polonus', as my favourite toolAlta Vista Babel Fish doesn't translate Polish
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: wmram.exe
« Reply #6 on: July 26, 2005, 09:00:42 PM »
Czesc DavidR,

Well sometimes it comes in handy, actualy  the polish thread on the Gazeta Forum advized  to use killbox to take this "robak" out (robak=vermin is the Polish term for worm, sometimes they say robak-worm). There are not that many Dutch with a fair command of Polish, but in order to be able to communicate with your  in-laws one does a lot.  I finally mastered it, although it was murderously difficult, especially for people that speak a germanic language like Dutch, but then later you also have access to antivirus-forums (dostep do forum antywirusowego). Glad I could help you out here. You're welcome.

Greets (=pozdrawiam)

polonus
« Last Edit: July 26, 2005, 09:03:59 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

riowalker

  • Guest
Re: wmram.exe
« Reply #7 on: August 05, 2005, 08:16:08 AM »
Hi,

The only way to kill this file is to download killbox.exe http://www.bleepingcomputer.com/files/killbox.php , very safe. Find the file path, (Replace on Reboot) make sure you check use dummy file (very important). File gone.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89131
  • No support PMs thanks
Re: wmram.exe
« Reply #8 on: August 05, 2005, 03:21:53 PM »
Quote
The only way to kill this file is to download killbox.exe
I strongly doubt that this is the only way to kill this, not only did 'polonus' give a link to toolbarcop, which by all accounts can get rid of this (possibly supported by the fact that the original poster didn't come back for more help).
There are many tools to kill a file on next boot, HiJackThis for one so they too would delete the file. However simply getting rid of the file may not resolve the problem as there are associated registry entries which will need removal and for this I would suggest the link 'polonus' gave for a tool bar removal tool or HiJackThis.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

riowalker

  • Guest
Re: wmram.exe
« Reply #9 on: August 05, 2005, 08:02:50 PM »
Hijack will not work, trust me, I've tried everything.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89131
  • No support PMs thanks
Re: wmram.exe
« Reply #10 on: August 05, 2005, 09:59:21 PM »
HJT has a function to 'delete a file on reboot' in the Configuration, Misc Tools section.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: wmram.exe
« Reply #11 on: August 05, 2005, 10:00:15 PM »
Hi riowalker and DavidR,

I agree with DavidR that toolbarcop can do the job. There are a few other things to consider in this why riowalker may have reacted in the way he did. In the first place cleaning files and killing processes is best done in safe mode. And the second thing and not a lot of people know this: SpywareBlaster can be a two-sided sword if it is installed on a machine that is not clean. It can actually keep the trash on your comp. This is a known fact. SpywareBlaster is a great security tool but ONLY THEN when it is installed on a 100% clean system.

yours truly,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

riowalker

  • Guest
Re: wmram.exe
« Reply #12 on: August 05, 2005, 11:32:45 PM »
It seems possible that their are many ways to delete the wmram.exe . Good luck.

Martin221

  • Guest
Re: wmram.exe
« Reply #13 on: September 07, 2005, 02:45:42 PM »
wmram.exe is part of a virus
unstoppable, undeletable, creating multiple instances
and even recreating after deletion with ultimate boot CD
it's part of a brand new virus !

This virus got the name
TR.Grobot
as H+BEDV Datentechnik GmbH the programmers of
AntiVir explained in an email I got today.

Next version ov AntiVir will know this virus signature.

The virus was seeded by the freeware "Change Harddisk .. ID"
offered by Softpedia who deleted their offer in the meantime.

The best way to get rid of this virus: Backup your data on CD
and rebuild your whole system from scratch beginning with
formating your harddisk.

adam666

  • Guest
Re: wmram.exe
« Reply #14 on: September 17, 2005, 11:36:31 AM »
regular ms birthdays do ensure maximum system performance :)

anyhow,

download 'Autoruns' [http://www.sysinternals.com/utilities/autoruns.html]
and extract it somewhere

reboot into safemode

load autoruns, and check out all the stuff that usually starts up :)
plenty of crap to untick right?!!

look for section:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run         

and entry:

wininfo   System Information   (Not verified) Microsoft Corporation   c:\windows\system32\wmram.exe

untick it (and the rest of that stuff that doesnt need to be there!) and presto ur set to reboot and back to normal...

NOTE:
           Im not convinced it s a virus as such but it certainly is annoying,
I did NOT download the earlier specified program by 'sophos or watever' and as such have no idea how this file came to be on my pc. which is frustrating!

but this gets rid of it if cant be arsed reformat/installing  ;D

cheers
Adam