GSA SER Security Concern - Need Advice
Hi everyone,
I recently encountered a security issue on my Windows machine and wanted to check if anyone else has experienced something similar.
Windows Security Alert (Severe):
- Detected: Trojan/ScrInject.EK!MTB
- Status: Quarantined
- Affected file path: AppData\Roaming\GSA Search Engine Ranker\projects\[]...new_targets
- The alert mentioned that the program is dangerous and may execute commands from an attacker.
So far, Windows Defender has quarantined the threat, but I also noticed a “Remediation incomplete” message from an earlier detection, which is a bit concerning.
A few questions:
- Has anyone here encountered this specific threat before (especially related to GSA SER or similar tools)?
- Is Windows Defender quarantine sufficient, or should I take additional steps?
- Would you recommend running other tools (e.g., Malwarebytes, full system scan, etc.)?
- Should I completely remove and reinstall the affected software?
I’d appreciate any advice on best practices to ensure my system is fully clean and secure.
Thanks in advance.

Tagged:

Comments
Thanks for the clear explanation, @Sven. That makes a lot of sense, the software is just storing URLs/targets from those sites, not executing any code from them, so the detection is essentially a false alarm from Defender being overly cautious.
Just to update, I'm currently in the process of reinstalling my VM and planning to do a fresh install of GSA SER afterwards. Since this will be a clean setup, I want to make sure I don't lose any of my existing data and configurations.
Honestly, I'm not sure where to start when it comes to backing up GSA SER properly. Could you advise on what exactly needs to be backed up before I wipe everything? Things like projects, settings, target lists, verified URLs, I'm not even sure where all of that is stored or what format it's in.
Also, once I have the backup, what's the correct way to restore it on the fresh install? Is it just a matter of copying files over, or is there more to it?
Really don't want to lose months of work, so any guidance would be greatly appreciated!