Maybe a trojan
January 21st, 2020
01/11/2008 12:22:05Real-time file system protectionfileC:\DOCUME~1\Joseph\LOCALS~1\Temp\GIoRtNN.tmpa variant of Win32/Agent.THO trojancleaned by deleting – quarantinedNT AUTHORITY\SYSTEMEvent occurred on a new file created by the application: C:\PROGRA~1\FlashGet\updates.exe.
01/11/2008 12:22:01Real-time file system protectionfileC:\WINDOWS\System32\dmserver.dllWin32/Patched.BU virusdeleted – quarantinedNT AUTHORITY\SYSTEMEvent occurred on a file modified by the application: C:\PROGRA~1\FlashGet\updates.exe.
Do i have a virus or is everything ok seeing as nod32 has these quarantined now?!
right click on C:\WINDOWS\System32\dmserver.dll, click on properties, then click on version.
post the version here
I could only find the file dmserveresl.dll?! Is it the same thing?
The version is 2600.5512.503.0. Wait it says orginall file name was dmserver.dll, did nod32 create the new one?
A scan of the WINDOWS folder just showed its clean.
hmm.. the name seems suspicious, but the version is correct. 2600.5512.503.0 is the last stable microsoft version of dmserver.dll, same as the one i have.
run a scan via
http://www.programchecker.com
and check
Id suggest downloading SpyBot: Search & Destroy , its a very good Antispyware software (including deleting trojans)
Your search 'dmserveresl.dll' had no matches in ProgramChecker's database
Avira warned me FlashGet “update” was a virus, I heard about the FlashGet program Update being hacked to download a virus instead, could this be related to that incident?
Nick
Can you check your system32 folder & see what the dmserver.dll is called? I.e is dmserveresl now?
cant find dmserver in my system32….
Just found this:
http://www.threatexpert.com/files/dmserveresl.dll.html
Odd…
Just try downloading SpyBot atm, see what it comes up with.