Sponsor for PC Pals Forum

Author Topic: Trojan Downloader.Agent.KUM  (Read 2198 times)

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Trojan Downloader.Agent.KUM
« on: May 18, 2007, 12:25 »
I have had two trojans now in the past week, same trojan, downloader.Agent.KUM.   (And no I haven't been visiting porn sites)

I googled it, but the only entry was in, I think, German. So not much help. :dunno:

The first one was in c:/windows/system32/WM.EXE

The second one in c:/system volume information/_restore

AVG picked up both of these and they are in the vault.

I have uninstalled  ZoneAlarm and installed Comodo, don't know if this will help me. (and yet another piece of bloody software to work out how to use ???)

So why am I getting the same one, just unlucky or is it hiding somewhere. I ran Hijackthis last night and everything was fine except for one entry which was missing its file, so I fixed it.  :dunno:
Those who can make you believe absurdities,
can make you commit atrocities.

Offline Sandra

  • Ultimate Member
  • *******
  • Posts: 12155
Re: Trojan Downloader.Agent.KUM
« Reply #1 on: May 18, 2007, 12:38 »


The second one in c:/system volume information/_restore


Thats where its hiding MB.

Turn system restore off then restart in safe mode and run your scan again.
It will delete the one thats in the restore file and once you have made sure that its definately gone then re enable system restore.

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Trojan Downloader.Agent.KUM
« Reply #2 on: May 18, 2007, 12:40 »
Thanks Sandra, but I can't remember how to do that?  :dunno:
 
Those who can make you believe absurdities,
can make you commit atrocities.

Offline Sandra

  • Ultimate Member
  • *******
  • Posts: 12155
Re: Trojan Downloader.Agent.KUM
« Reply #3 on: May 18, 2007, 12:43 »
Right click on My computer, go to properties and click on the system restore tab in the window which opens.
Turn it off in there.

Restart the pc and keep pressing F8 for safe mode  :)

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Trojan Downloader.Agent.KUM
« Reply #4 on: May 18, 2007, 13:54 »
Ok did that, though AVG didn't find anything.   :dunno:

Not sure if I did it right as after F8 it didn't say anything about safe mode.

I don't know if this matters but I using msconfig and in boot ini, boot options isn't selected.
Those who can make you believe absurdities,
can make you commit atrocities.

Offline Simon

  • Administrator
  • *****
  • Posts: 77112
  • First to score 7/7 in Quiz of The Week's News 2017
Re: Trojan Downloader.Agent.KUM
« Reply #5 on: May 18, 2007, 14:21 »
I wonder how the trojan got in in the first place?  I know you've probably said, but what's your security set up again?  Your anti-virus / anti-spyware should have stopped it.  The firewall (ZA / Comodo) won't stop it getting in, but it should stop it transmitting anything, providing you haven't inadvertently allowed it, which is quite easy to do, given the confusing pop ups some firewalls produce.
Many thanks to all our members, who have made PC Pals such an outstanding success!   :thumb:

Offline Sandra

  • Ultimate Member
  • *******
  • Posts: 12155
Re: Trojan Downloader.Agent.KUM
« Reply #6 on: May 18, 2007, 14:36 »
When you press F8 repeatedly you should ge a screen asking what you want to do.
Start windows normally, Use last known good configuration, Safe mode plus a few others.
You use the up and down arrows to select which option then press enter.

Did you get a boot order screen when you pressed F8 as some raid and Sata motherboards have that option.
If you got that then it can be awkward to time the pressing F8 at the right time to get the safe mode option screen up.
It needs to be pressed after the first screen with all the text appears and before the second one fully completes.

If you didnt get the boot order screen then you arent pressing the F8 button early enough or possibly long enough, do not keep it pressed, you have to press it on and release and press again quickly repeatedly.

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Trojan Downloader.Agent.KUM
« Reply #7 on: May 18, 2007, 14:38 »
I have AVG-Anti Virus, which is what caught it.

Windows Defender, which isn't bad either.

I have SpyBot, Spy Blaster, A Squared and AdAware.

And I'm having a hard time understanding Comodo.
Those who can make you believe absurdities,
can make you commit atrocities.

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Trojan Downloader.Agent.KUM
« Reply #8 on: May 18, 2007, 14:46 »
Sandra, I really can't remember at the moment, I'm really tired. It blew an absolute gale here last night and the noise kept waking me up. And I have a shade sail attached to the side of the house, underneath my bedroom window and it came loose early this morning and kept banging against the wall. :aarrgh:

So I'm off to bed, so hopefully it will make more sense in the morning. :yawn:
Those who can make you believe absurdities,
can make you commit atrocities.

Offline Simon

  • Administrator
  • *****
  • Posts: 77112
  • First to score 7/7 in Quiz of The Week's News 2017
Re: Trojan Downloader.Agent.KUM
« Reply #9 on: May 18, 2007, 20:06 »
You don't have a USB keyboard do you, MB?  I do, and can't get into safe mode using it, because it doesn't come to life until Windows is half loaded.  I have to use a PS/2 keyboard (with the purple connector) if ever I need to access safe mode.
Many thanks to all our members, who have made PC Pals such an outstanding success!   :thumb:

Offline Clive

  • Administrator
  • *****
  • Posts: 74295
  • Won Quiz of the Year 2015,2016,2017, 2020, 2021
Re: Trojan Downloader.Agent.KUM
« Reply #10 on: May 18, 2007, 20:20 »
Don't forget to switch system restore back on again afterwards as it may just come in handy.

Offline Sandra

  • Ultimate Member
  • *******
  • Posts: 12155
Re: Trojan Downloader.Agent.KUM
« Reply #11 on: May 19, 2007, 02:51 »
Good point Simon, I forget that people often have USB or wifi keyboards these days for some obscure reason, although newer mobo bios seems to be having USB keyboard support available which helps a little if its enabled   :)

Offline Simon

  • Administrator
  • *****
  • Posts: 77112
  • First to score 7/7 in Quiz of The Week's News 2017
Re: Trojan Downloader.Agent.KUM
« Reply #12 on: May 19, 2007, 09:20 »
Ah, that's a question I have been meaning to ask for ages, Sandra.  How do you enable USB keyboard support?  Oddly enough, I was working on a PC much older then mine sometime last year, and I could use my USB keyboard to get into safe mode with no problem, so I'm wondering if it's not enabled on mine? 

:dunno:
Many thanks to all our members, who have made PC Pals such an outstanding success!   :thumb:

Offline sam

  • Administrator
  • *****
  • Posts: 19966
Re: Trojan Downloader.Agent.KUM
« Reply #13 on: May 19, 2007, 11:37 »
you can enable it in the mobo settings normally simon...
- sam | @starrydude --

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Trojan Downloader.Agent.KUM
« Reply #14 on: May 19, 2007, 11:48 »
It did dawn on me last night that if AVG caught the trojan, letting me know by alert, and I moved it to the vault until I knew what it was exactly. Then doesn't that now mean, that there is no longer a trojan in restore. But Michael had a point when he asked, "how did AVG detect a trojan in restore, in the first place?"

Having said all that, I used msconfig to boot in safe mode, a lot easier for me, turned off restore and ran a scan which last almost one and a half hours  :( and found absolutely nothing.  :)
Those who can make you believe absurdities,
can make you commit atrocities.


Show unread posts since last visit.
Sponsor for PC Pals Forum