Computing.Net > Forums > Security and Virus > kernel32.vmm - unknown file

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

kernel32.vmm - unknown file

Reply to Message Icon

Name: Mat Wilson
Date: June 3, 2002 at 23:55:06 Pacific
Comment:

Today I have discovered that I have a program called kernel.vmm which has replaced my kernel32.exe (kernel32.exe was deleted) and the "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" "Windows Kernel" in the registry. I would normally just replace this with the original and change the registry but when I searched for kernel32.vmm I could find nothing on any search engine or database...

I am running windows 98 SE on a Pentium 3 computer with a cable (always on) connection.

This program also automatically hooks upto the net when the computer starts (I have now disabled it from acessing the net with my firewall).

If anyone would like a copy of this file please email me ( forest_rd@hotmail.com) and I will send it to you (54kb)



Sponsored Link
Ads by Google

Response Number 1
Name: murve
Date: June 4, 2002 at 07:45:59 Pacific
Reply:

hi mat,
I did a search on kernel32.vmm to see if it is a possible trojan and was unable to find it in any database as such. I also checked with simovits consulting to see if it was in their database of active trojans and it wasn't. so I suspect that indeed it is a trojan in the wild of the variety of sub7 or back orifice, keylogger,and or remote access variety, you may if you wish check out www.thepublicworks.com security section and click on links, simovits consulting, dark-e, trojan removal, dalantec. also download RegProt, Procmon and Netmon from Sysinternals.
also do a trojan and port scan of your puter at www.pcflank.com. also go to wilders.com and download a copy of Trojan Hunter 30 day trial and scan. since you said it was a start up i would also check win.ini sys.ini autoexec.bat, all the run services in registry in all hot keys, also check the roots in registry eg: bat, com, hta, pif at the command/open level.
you may have to remove that file and do a replace from your win98 c.d
good luck and cheers,
murve


0

Response Number 2
Name: WhitPhil
Date: June 4, 2002 at 08:34:36 Pacific
Reply:

Kernel32.exe is the Babylonia virus.

http://securityresponse.symantec.com/avcenter/venc/data/w95.babylonia.html

Kernel32.vmm in not a valid Windows file.
Run MsConfig and unselect any entries referencing it.

Then update your virus defs and do a full scan again.
The Trojan links above are also useful.


0

Response Number 3
Name: Mat Wilson
Date: June 5, 2002 at 20:11:46 Pacific
Reply:

I have had a good into this and have found the following.

The only registry items it seems to make is the Run key as said above and the one that sets the file type as being an application (can be changed from the Folder options in Explorer).

That it only connected to my DNS servers on port 53 and seems not to have actually done any harm.

It can be gotten rid of by simply editing the registry and removing the above run key and deleting the file.

I have absoutely no idea hw it got on my computer.


0

Response Number 4
Name: netdude
Date: June 7, 2002 at 09:43:25 Pacific
Reply:

I just found the same file after it tried to access the net through Zone Alarm. It works in conjunction with syscfg.exe(which is a valid windows file). Seems if syscfg.exe starts up so does this file. I deleted kernell32.vmm both in the Windows folder and in the registry. I think I got it from a porn site and no Norton did not pick it up with a full scan.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: kernel32.vmm - unknown file

Unknown File in Winsock LSP www.computing.net/answers/security/unknown-file-in-winsock-lsp/27798.html

Kernel32 www.computing.net/answers/security/kernel32-/1424.html

lop.com & other problems www.computing.net/answers/security/lopcom-amp-other-problems/9676.html