View Full Version : trojan-spy.lyndra
I just installed a copy of SD on XP SP3 and got this after scan. sorry if already posted, couldn't find it.
http://jpgshack.com/images/1_y6snp3.jpg
http://jpgshack.com/images/2_e3wlb.jpg
http://jpgshack.com/images/3_bh92mo.jpg
GoneToPlaid
11-28-2008, 11:42 PM
Qmgr.dll is supposed to be a file which is part of Windows Update. You can delete it if it truly is infected, and then simply go online and download and reinstall MS Windows Update from their web site. In any event, spy.lyndra is a keylogger trojan which will email your logins and passwords and bank account numbers to the attacker. From what I've read, some versions also download other files and replace common programs like calc.exe with infected versions, and also may add your computer to a botnet.
haapy
11-29-2008, 01:58 AM
It also could be an FP. I googled it and it seems that PCT is the one tagging it the most. I would request PCT to check it out further. You could also do a scan with Malwarebytes anti-malware and Avira AV to to some self validation.
Thanks for your replies. Well it is an FP, that's why I posted it. But I'm surprised that nobody else has ServiceDLL entry in BITS which triggers the alarm.
My qmgr.dll on virus total is clean. Avira found nothing and Malwarebytes just tagged two legit entries customizing the start menu. Let's see what PCT staff has to say.
http://jpgshack.com/images/22_92zmiq.jpg
http://jpgshack.com/images/11_tdc8i6.jpg
GoneToPlaid
11-29-2008, 06:37 PM
qmgr.dll on my XP SP3 machine is version 6.7.2600.5512 (xpsp.080413-2108). Its checksum is 52e2619b. You might want to check the version and checksum of your system's qmgr.dll and see what you find.
Start_ShowHelp on my system is set to 1, not 0, but StartMenuLogOff on my system is set to 1 just like yours is. Malwarebytes doesn't throw a FP for Hijack.StartMenu on my computer with the settings for these keys on my computer.
Powered by vBulletin™ Version 4.1.0 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.