1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Win32/VMalum.BXRF ?? [False detection in CA signatures]

Discussion in 'Malware and Virus Removal Archive' started by Tari, 2008/03/04.

  1. 2008/03/04
    sgtpug

    sgtpug Inactive

    Joined:
    2008/03/04
    Messages:
    6
    Likes Received:
    0
    Wow your brave.:eek:

    I barely trust msn. Let alone their beta versions. :)
     
  2. 2008/03/04
    muratalibaba

    muratalibaba Inactive

    Joined:
    2008/03/04
    Messages:
    6
    Likes Received:
    0
    cool

    seems to be problem solved then! back to work : )
     

  3. to hide this advert.

  4. 2008/03/04
    Vers

    Vers Inactive

    Joined:
    2008/03/04
    Messages:
    3
    Likes Received:
    0
    lol, i hate beta versions, but I feel a bit suicidal today.
    Children, dont do that at home :D
     
  5. 2008/03/04
    sgtpug

    sgtpug Inactive

    Joined:
    2008/03/04
    Messages:
    6
    Likes Received:
    0
    YAY everything AOK

    Restarted computer, tested msn-all works fine (little bit slow though).

    I suppose i better watch the end of the cricket (looks like India has won :() then go to bed.

    Thanks to all who helped figure this problem out. Have a good day/night. :D
     
  6. 2008/03/04
    Deadly Bagel

    Deadly Bagel Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    It's happening with VET antivirus too. So not just CA.
     
  7. 2008/03/04
    fstop

    fstop Inactive

    Joined:
    2008/03/04
    Messages:
    2
    Likes Received:
    0
  8. 2008/03/04
    ksweb

    ksweb Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    I am running on XP with Kaspersky anti-virus which does not pick up on this virus, i have scan most folders and it does not detect it. However I was chatting to someone now who said that Messenger told them I was trying to send a virus to them.

    I'm using Windows Live 8.5.1
     
  9. 2008/03/04
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi All
    Would someone that is still infected run a Decker System Scan and post the log.

    Please download Deckard's System Scanner (dss.exe) and save it to your Desktop.
    Note: You must be logged onto an account with administrator privileges to complete the following.
    • Close all other windows before proceeding.
    • Double-click on dss.exe and follow the prompts.
    • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy and then paste the contents of main.txt and extra.txt in your next reply.

    Thanks
    Geri
     
  10. 2008/03/04
    Baht at

    Baht at Inactive

    Joined:
    2008/03/04
    Messages:
    2
    Likes Received:
    0
    Read my lips:

    this report win32/vmalum does not indicate the detection of a virus merely detection of "suspicious" behaviour by CAs heuristics.
     
  11. 2008/03/04
    haroldeveryman

    haroldeveryman Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    ca false antivirus warning re. MSN Messenger

    I just called CA and they are aware of the problem - the tech told me to ignore the warning and proceed to use MSN messenger. They are going to post a fix for the problem sometime today Tuesday March 4th . . . :)
     
  12. 2008/03/04
    astroboy

    astroboy Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    Win32/VMalum.BXRF & INI/Helpud.CL

    Hi all,

    After updating the virus definitions in CA Antivirus this evening the real time scanner detected INI/Helpud.CL in the Desktop.ini file in old backed up profile folders that were stored on the hard drive.

    eg: D:\Documents and Settings\XX\My Documents\XX\XX old profile\XX\My Documents\My Pictures\

    It did this to every old profile I had stored on the hard drives of the two pc’s on my home network that were running CA 2007 that had automatically updated the virus definitions (one of my pc's had 4 old profiles so it quarantined 4 Desktop.ini files).

    It then detected Win32/VMalum.BXRF in C:\Program Files\MSN Messenger\msnmsgr.exe and quarantined the exe.

    On one of the pc's I uninstalled CA and installed AVG Free and ran a full scan and it didn’t detect anything. Also ran http://housecall.trendmicro.com/au/ and it also detected nothing.

    Definitely seems like CA is detecting it as a false positive, we'll just have to sit and wait for them to resolve it today (or overnight for those of us in Australia)
     
  13. 2008/03/04
    sukibabs

    sukibabs Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    Same problem

    We also have a computer with CA and just got the virus message. Clicking on the virus name Win32/VMalum.BXRF under Infection takes you to the CA site that has no information about this virus.
    "No results were found for your search. "

    If it was really a virus you would think that the CA software would remove it or at least have an option to remove it.

    Just logged into MSN messenger and it hung and then CA quarantined the file.
    Guess we'll have to download the new version too.
     
  14. 2008/03/04
    PsychNurse

    PsychNurse Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    Having same problem with CA & msnmsgr.exe being picked up as infected with this Win32/VMalum.BXRF. I d/l MSN Live again but CA again picked up the msnmsgr.exe filed as bing infected. I can't open MSN Live. Looking for help to get this straightened out & MSN Live running again! :confused: Thanks.
     
  15. 2008/03/04
    pablorh

    pablorh Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    Apart from getting msnmsgr.exe infected, I got C:\System Volume Information\_restore{A857AD0D-11AA-4BC9-8299-36B218EC8101}\RP23\A0005265.exe infected by the same Win32/VMalum.BXRF virus :confused:

    (I use CA Antivirus)
     
  16. 2008/03/04
    Chris M

    Chris M Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    Win32/VMalum.BXRF

    I am having the same problem here...won't let me log on to msn without updating messenger, which i don't even use but do have installed. I called the msn support line and got some foreign lady i couldn't understand telling me to give her my credit card number and she would fix the problem :mad:
    I use Zone Alarm and it's found the Win32/VMalum BXRF virus and spyware but can't get rid of it on it's own
     
  17. 2008/03/04
    fleshped

    fleshped Inactive

    Joined:
    2008/03/04
    Messages:
    2
    Likes Received:
    0
    just lovely

    I have the same ****. MSN was trashed. I deleted it. 2 files put up a fight but all I had to do was create a new folder, move them, and then I was able to finish deleting(referring to all MSN Messenger files). Now of course... it has been found in the
    C:\System Volume Information\_restore{A857AD0D-11AA-4BC9-8299-36B218EC8101}\RP23\A0005265.exe
    as well. My boss was curious if I had done something to cause this. Pray for a cure!
     
  18. 2008/03/04
    Soniaeiou

    Soniaeiou Inactive

    Joined:
    2008/03/04
    Messages:
    12
    Likes Received:
    0
    Almost the same...

    I did the same... uninstalled my msn.

    I do too have a "thread" (is it one finally?) in my system volume information/restore files. Only the numbers are differents. The file is actually in quarantine of Ez Antivirus (think is CA). But when I scan, cannot see anything wrong.

    I didn't do nothing to cause this... I shut off my pc for one hour or two, log back and this!!

    Thanks



    New info:

    Now I have an alert for a .ini file in my system volume information, restore file...

    Getting worried...
     
    Last edited: 2008/03/04
  19. 2008/03/04
    Aish29

    Aish29 Inactive

    Joined:
    2008/03/04
    Messages:
    1
    Likes Received:
    0
    Win32/VMalum.BXRF

    I also have CA Anti virus and after reading the posts on here, i called Ca directly. This is not actually a virus. This is a software issue Ca is having with the anti virus. I was told the problem would be fixed by the next signature update, within the next 24 hours.:D
     
  20. 2008/03/04
    fleshped

    fleshped Inactive

    Joined:
    2008/03/04
    Messages:
    2
    Likes Received:
    0
    that would make sence

    I sure as Hell hope they get their bugs straight before it costs me my job! I didn't do it but of course I got blamed! Grrrrrrr
     
  21. 2008/03/04
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    You would think they would at least put some info on their support site.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.