Help - Search - Members - Calendar
Full Version: trojan horse downloader
Suggest A Fix PC Support Forums > Security > Malicious Code: Viruses, Trojans, Spyware and Browser HiJacking
bustfusted
i have a trojan horse downloader on my system named downloader presario.a. when i boot-up, my pc runs for around 8- 10 minutes, then reboots itself. it will reboot continously untill i cut the power. any help would be helpful.
thanks,
Digital.Control
bustfusted,

Does your antivirus specify a file that is infected when it finds the downloader? A file like..

C:\Windows\system32\mscmtSrvc.exe or
C:\Windows\Notepad.exe

These are common places for the presario.a downloader to occupy.

To remove a file that your antivirus told you is infected do the following:

Turn off System Restore (Instructions Here)

Boot into safe mode (instructions here)

Open a command prompt by clicking on the start menu, going to run, typing command in the box and pressing return.

in the command prompt, type:

del C:\WINDOWS\SYSTEM32\msCMTsrvc.exe (or the file your antivirus tells you is infected)

Restart,

Re-run your antivirus, if it still comes up and warns you, or your system keeps restarting, post a follow up message and let us know the files infected. If you need another antivirus to try, check the "Free Virus Removal Utilities" sticky in the forum.

Ric
(Digital.Control)
Angoid
Hi Bustfusted, and welcome to SAF smile.gif

In addition to that, it's worth also seeing your HijackThis log: please see our Introduction to HijackThis for instructions on how to post a log.

Post it back into here: it will list areas of the system where bad stuff is known to lurk, and will alert us to any other problems you may have lurking in there.

As for deleting the files mentioned above, especially Notepad.exe, you'd need to check the properties before deleting it to make sure you're not deleting a valid Windows program! A lot of malware tries to hide behind legitimate program names, and as a result people don't always spot them or are afraid to remove something that should be removed due to fear of getting the wrong file.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.