Results 1 to 3 of 3

Thread: Khalmnpr.exe infected with Virtumonde?

  1. #1
    Junior Member
    Join Date
    Jan 2009
    Posts
    1

    Default Khalmnpr.exe infected with Virtumonde?

    - Operating System: Windows XP, Service Pack 3
    - Browser: IE 7.0.5730; FireFox 3.0.5
    - SpyBot-Version: 1.6.0.31
    - Last Update: 07.01.2009
    - False positive occured: Scan result
    - Spybot scan result:
    Virtumonde: [SBI $845EA7F9] Ausführbare Datei (Datei, nothing done)
    C:\WINDOWS\KHALMNPR.Exe


    Hi everyone,
    I was slightly surprised when I scanned my system with SpyBot today just to find out that one of the exe-files (situated in C:\Windows\Khalmnpr.exe) that usually comes with Logitech-mice is supposed to be infected with Virtumonde.

    I've checked the file with a couple of anti-virus programs, none of them confirmed Spybot's scan-result. I'd assume it's a false positive since I don't have any sort of problem with my computer or using IE/FireFox - no random pop-ups or other kinds of strange behaviour there.

  2. #2
    Member of Team Spybot Buster's Avatar
    Join Date
    Oct 2005
    Location
    Bochum/Germany
    Posts
    389

    Default

    Thanks for reporting this false positive. You are right. It will be fixed in our next update scheduled for next Wednesday. In order to help us preventing future false positives you may download our distributed testing client here.
    Last edited by Buster; 2009-01-08 at 13:01.
    "The advantage of wisdom is that you can always act the fool. The opposite is quite tough."

    K. Tucholsky

    _______________________________________________________________

    Please help us improve Spybot and download our distributed testing client.

  3. #3
    Junior Member
    Join Date
    Jan 2009
    Posts
    1

    Default Thanks for the confirmation

    I thought maybe I was plagued with the rootkit from hell.

    This would explain why Spybot reported Virtumonde in KHALMNPR.exe, and yet ...
    VundoFix
    FixVundo
    and ClamAV (of the Windows FS from a Linux dual boot)
    All reported nothing out of the ordinary.

    Whew! Thanks.

    Ken

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •