Author Topic: Virus Question - fdiskdumpp.exe  (Read 6283 times)

0 Members and 1 Guest are viewing this topic.

FutileEternity

  • Guest
Virus Question - fdiskdumpp.exe
« on: October 09, 2008, 05:51:58 PM »
While booting my system up today, Avast detected the following:

fdiskdumpp.exe in C:\Program Files

Virus description: Win32:SkiMorph [Cryp]

Does anybody have any idea of what this is?  Also, Is there anything else on my system that I should look for that could be lingering around in relation to this file?

Thanks!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Virus Question - fdiskdumpp.exe
« Reply #1 on: October 09, 2008, 06:23:49 PM »
This could well be a False Positive:
 [%PROGRAM_FILES%]\fdiskdumpp.exe        [%PROGRAM_FILES%]\fdiskdumpp.exe     Safe

Upload fdiskdumpp.exe to www.virustotal.com and report the results in an attached txt file,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

FutileEternity

  • Guest
Re: Virus Question - fdiskdumpp.exe
« Reply #2 on: October 09, 2008, 06:28:50 PM »
I tried uploading it to that site, but every time, I get the following:

0 bytes size received

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89208
  • No support PMs thanks
Re: Virus Question - fdiskdumpp.exe
« Reply #3 on: October 09, 2008, 08:32:06 PM »
Where are you trying to upload it from, the HDD location or the chest, etc. ?

Does the Standard Shield alert when you try to upload it to VT ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Virus Question - fdiskdumpp.exe
« Reply #4 on: October 09, 2008, 08:55:46 PM »
FutileEternity, can you copy the file to your desktop area and send it from there? (take care handling the file).
The best things in life are free.

FutileEternity

  • Guest
Re: Virus Question - fdiskdumpp.exe
« Reply #5 on: October 09, 2008, 10:50:05 PM »
FutileEternity, can you copy the file to your desktop area and send it from there? (take care handling the file).

That's exactly what I did, and I got what I posted previously.  And yes, the standard shield alert goes off when I try to upload it to VT.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Virus Question - fdiskdumpp.exe
« Reply #6 on: October 09, 2008, 10:56:36 PM »
FutileEternity, can you copy the file to your desktop area and send it from there? (take care handling the file).

That's exactly what I did, and I got what I posted previously.  And yes, the standard shield alert goes off when I try to upload it to VT.
Try changing the file name to fdiskdumpp.exe.txt
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89208
  • No support PMs thanks
Re: Virus Question - fdiskdumpp.exe
« Reply #7 on: October 09, 2008, 11:47:13 PM »
FutileEternity, can you copy the file to your desktop area and send it from there? (take care handling the file).

That's exactly what I did, and I got what I posted previously.  And yes, the standard shield alert goes off when I try to upload it to VT.

That is because avast scans when you try to access the file and even if you choose no action avast won't let you work with an infected file and this includes uploading it. That is why the file size is 0 bytes.

I don't know if changing the file type to .txt a supposedly inert file type would work or if it might also effect the file. You could pause the Standard Shield just to allow it to be uploaded an immediately it is uploaded enable again. However , I not keen on that idea of lowering your protection whilst on-line even for a short time.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security