Have I got a virus?

  • Thread starter Martin ©¿©¬ postmaster
  • Start date
M

Martin ©¿©¬ postmaster

Greetings
I scanned my system with F-Prot for windows and got the following:
==========================================
muamgrd.exe in c:\windows\system32\ suspicious file
Is a security risk named w32/Sdbot.QS
Cannot delete file
And
serm32.exe in c:\windows\system32\ suspicious file
Is a security risk named w32/Spybot.TX
Cannot delete file
=================
Am I infected?

Martin
©¿©¬
 
N

null

On Fri, 27 Aug 2004 12:25:03 +0100, Martin ©¿©¬
Greetings
I scanned my system with F-Prot for windows and got the following:
==========================================
muamgrd.exe in c:\windows\system32\ suspicious file
Is a security risk named w32/Sdbot.QS
Cannot delete file
And
serm32.exe in c:\windows\system32\ suspicious file
Is a security risk named w32/Spybot.TX
Cannot delete file
=================
Am I infected?

Upload suspect files for av scanning here:

http://virusscan.jotti.dhs.org/

If other scanners don't alert, submit the files to FSI.


Art
http://www.epix.net/~artnpeg
 
N

null

Spybot is a common worm, also seems to be a trojan name too. Symantec
and other sites have plenty of info on it.

1. There are many variants.
2. Getting descriptions of recents variants isn't always possible.
3. Some AV scanners tend to have broad detections of Trojans leading
to misidentifications. (Not so much F-Prot though). It's always a good
idea to get the "opinions" of several other scanners and see what
malware names and variant they ID, if any. Also scanners sometimes
false alarm.


Art
http://www.epix.net/~artnpeg
 
N

null

On Fri, 27 Aug 2004 15:13:52 +0100, Martin ©¿©¬
Hi Art
I've got rid of serm32.exe
But I can't find muamgrd.exe anywhere, yet F-Prot keeps flagging it

See Response #5 here:

http://www.computing.net/windowsxp/wwwboard/forum/112662.html

I found no descriptions of the .QS variant. You can see what other AV
call it here:

http://www.virusbtn.com/resources/vgrep/vgrep.cgi?terms=spybot.qs&product=0

Do you see it as a running process that can be killed? Have you run
F-Prot in Safe mode?


Art
http://www.epix.net/~artnpeg
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top