Options

How to remove trojan

I have a Trojan Horse Downloader.Presario.A

found in C:/windows/system32/msCMTsrvc.exe

Can someone tell me how to remove it? It's dated 10/29/2002, just curious, is it possible this was on the comp when I bought it less than a year ago? I barely do anything on the internet with this comp, don't download, never give out info & usually get very little junk mail. I even delete forwarded mail from friends without reading it, so was really surprised to find I had my first virus ever! Thanks, Rara

Comments

  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited May 2004
    Rara, what Antivirus program or malware program told you this??? And what version is it??? and, from the Help|About, what for the program, when was it written???And please check the file and path you gave if you did not cut and paste this. I cannot get a trojan name or file name match after searching many places, starting with Google. I've been on Symantec's security response searcher, AERT's hoax and virus DB, F-Prot's Database, and Kaspersky Labs AV Databases.

    The file name is illegal, I think (DO NOT delete it until I say TO, PLEASE), but need to find another way to search. So, IF I know whose AV you use, that is best bet. This is not a common virus name at all, except for the Downloader part, and there are literally hundreds with that in it and I have been looking through virus name and symptom indexes for this name you gave me or any part of it. From the file date, this is very old-- but if the date is right something is very wrong. Knowing what program found it will let me find that AV mfr's data base, if they have one. I would say to go http://vil.nai.com/vil/default.asp and submit a copy of the file to them. You COULD also email a copy of it as an attachment to this email address, jdii1215 AT johndanielsonii.com (put the @ sign in instead of AT, remove spaces in email address)which is MINE, and I can see what Bitdefender on Linux here thinks of it and what F-Prot on XP thinks of it. I do not want millions of these submits, but I would like to know what is up with this file myself. Please do not PM me with this attachment.

    John_D
  • edited May 2004
    I use AVG, had just put it on this comp but have been using it for some time on my other one for sometime. I don't know a lot about computers, if you mean by check the file and path, looking in the folder, it is where it says. I didn't touch it or try to remove it. If I don't know anything about it I know enough to leave it alone until I find out what to do. I thought the date was odd thats why I asked if it may have been on the comp when purchased because it's a compaq presario, don't know about these things though.
    How do I make a copy of file without causing a problem? Rara
  • MediaManMediaMan Powered by loose parts.
    edited May 2004
    msCMTsrvc.exe is a HOT DEALS application provided by Compaq for Presario PCs. Do you have a HOT DEALS icon on the desktop?

    Stop this service and delete the icon and any other traces of it. You should also be able to remove it from the WinXP startup by START>RUN type MSCONFIG and see if it is in the STARTUP tab.
  • edited May 2004
    No, don't see one, why is it named trojan in the folder and I keep getting an AVG Resident Shield popping up with the virus trojan warning. Rara
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited May 2004
    Rara wrote:
    I use AVG, had just put it on this comp but have been using it for some time on my other one for sometime. I don't know a lot about computers, if you mean by check the file and path, looking in the folder, it is where it says. I didn't touch it or try to remove it. If I don't know anything about it I know enough to leave it alone until I find out what to do. I thought the date was odd thats why I asked if it may have been on the comp when purchased because it's a compaq presario, don't know about these things though.
    How do I make a copy of file without causing a problem? Rara

    Ok, you can do this:

    Outlook Express, right??

    Send an email to me at the email address given in last post. Click attach (paperclip icon on the OE symbols button thing called a toolbar)with the email writting thing still open. send it. then go to your sent email folder, delte what you just sent, then open the deleted items folder and delete it there. Then close Outlook Express. Then empty your recycle bin. I CAN tell you this, grisoft's database for viruses cannot find it either, by that name. grisoft makes AVG. I was looking there while you were replying here.
  • edited May 2004
    Once I clicked send it said files could not be found or sent, so not sure if it worked. This is really getting weird. Rara
  • edited May 2004
    Did you get the file? If not I'll have to try again tomorrow, I'm in Florida too, it's pretty late. Thanks for helping! E-mail me if you find anything. Rara
  • botheredbothered Manchester UK
    edited May 2004
    I think john means, after you click the paper clip icon you have to browse to the file you want to send, select it then click OK. It will then attach that file to the email so john has a copy of it.
  • NecropolisNecropolis Hawarden, Wales Icrontian
    edited May 2004
    Moving to Spyware/Virus/Trojan Section
  • edited May 2004
    I know how to send attatchments, do it all the time. This one won't attatch. I tried to right click, drag, copy to desktop, it won't do that either. Whatever it is it's stubborn!
    Tried to drag to recyle bin says:

    Cannot delete msCMTsrvc: Access is denied.

    Make sure the disk is not full or write-protected
    and that the file is not currently in use.

    My anti-virus program keeps popping up constantly while trying to do anything with it. Rara
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited May 2004
    Rara and I discussed this in email, and there is a decent lesson in the resulting fix:

    Lots of hijackers do not run in safe mode. The things they depend on are off by default in an XP boot without networking. So, lots of things that the hijacker-removers kill can be removed by them easier with XP in safe mode and PHYSICALLY off the web while they are working.

    Rara's file deleted fine in Safe Mode, not in normal mode.

    If you have problems with a removal, try removing again, but in safe mode instead of in a normal boot mode. Just something to keep in mind. Actually for some of this junk, this is also true of every Windows from 98 SE and up through at least XP.

    Its gotten so I clean boxes with modem or network cable UNPLUGGED, with boxes in safe mode without networking enabled. Some Windows versions just have no option for without or with networking, those actually default to not running network drivers usually unless something really very weird is going on.
Sign In or Register to comment.