sysmtor.exe ???

  • Thread starter Thread starter Justin Emlay
  • Start date Start date
J

Justin Emlay

sysmtor.exe

There is no refference to this process on yahoo and only one side refference
to it on google. That alone tells me this process should not be running on
my machine. However can anyone verify exactly what this process is?

Killing this process allows my machine to run much faster. That is my
machine was extremly SLOW while this process was running even though it
averages 2% CPU time over the course of an hour. Very odd EXE.
 
Justin said:
sysmtor.exe

There is no refference to this process on yahoo and only one side
refference
to it on google. That alone tells me this process should not be
running on
my machine. However can anyone verify exactly what this process is?

Killing this process allows my machine to run much faster. That is my
machine was extremly SLOW while this process was running even though
it
averages 2% CPU time over the course of an hour. Very odd EXE.

Considering the one Google reference is on the CastleCops website
referring to malware, there's a very good chance the file is malware.
Go through these removal steps, doing everything with updated tools in
Safe Mode:

1) Scan in Safe Mode with current version (not earlier than 2004)
antivirus using updated definitions.

Before you remove malware, get LSPFix (or WinSockFix for XP which you
can get from MajorGeeks) - see links below.

2) Remove spyware with Spybot Search & Destroy and Ad-aware. These
programs are free, so use them both since they complement each other.
There is a new version of CWShredder from Intermute. I would not
install the other Intermute programs, however. Alternately, there are
CoolWebSearch malware removal steps at SilentRunners.

Be sure to update these programs before running, and it is a good idea
to do virus/spyware scans in Safe Mode. Make sure you are able to see
all hidden files and extensions (View tab in Folder Options).

If the malware remains even after you used Ad-aware and Spybot, you can
scan with HijackThis. HijackThis is an excellent tool to discover and
disable hijackers, but it requires expert skill. See below for
HijackThis links, including sites where you can post your HJT logs. A
combination of HijackThis and About:Buster works well in removing the
About:Blank homepage hijacker. Again, this is an expert tool and
novices should get help with it.

3) If you are running Windows ME or XP, you should disable/enable System
Restore after the system is clean because malware will be in the
Restore Points. With ME, you must disable System Restore completely.
With XP, you can delete all but the most recent (presumably clean)
System Restore point from the More Options section of Disk Cleanup
(Run>cleanmgr).

4) Make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update.

5) Run a firewall.

Links to help with malware:

Software/Methods:
http://www.safer-networking.org - Spybot Search & Destroy
http://www.lavasoftusa.com - Ad-aware
http://www.majorgeeks.com - good download site
http://www.intermute.com/spysubtract/cwshredder_download.html
http://www.silentrunners.org/sr_cwsremoval.html. - SilentRunners
http://www.cexx.org/lspfix.htm - Repair Winsock 2 settings after
removing spyware
http://www.spychecker.com/program/winsockxpfix.html - WinsockXPFix.exe

HijackThis:
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

General:
http://aumha.net - look under "Security" for various forums
http://rgharper.mvps.org/cleanit.htm
http://mvps.org/winhelp2002/unwanted.htm
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Malke
 
1) Download the following three items...

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend Pattern File.
http://www.trendmicro.com/download/pattern.asp

Adaware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download Sysclean.com and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt416.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) Update Adaware with the latest definitions.
3) Disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode and shutdown as many applications as possible
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
Trend Sysclean utility and Adaware
7) Re-enable System Restore and re-apply any System Restore preferences,
(e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point


* * * Please report your results ! * * *

--
Dave
http://www.claymania.com/removal-trojan-adware.html







| sysmtor.exe
|
| There is no refference to this process on yahoo and only one side refference
| to it on google. That alone tells me this process should not be running on
| my machine. However can anyone verify exactly what this process is?
|
| Killing this process allows my machine to run much faster. That is my
| machine was extremly SLOW while this process was running even though it
| averages 2% CPU time over the course of an hour. Very odd EXE.
|
|
 
This file is not detected by anything. I removed it myself. I was just
wondering what the heck it was and wondering how it was able to trash my
system so efficiently.

The Google reference is just a single person listing the file in his entire
list of processes. The Google reference is meaningless.
 
Here is the files info as read from the file:

Path: C:\WINDOWS\system32\sysmtor.exe
Name: sysmtor.exe
EXE Name: *
EXE InternalName: SYSMTOR*
EXE LegalCopyright: © BioNet Systems, LLC. 2003*
EXE Desc: SYSMTOR*
EXE Author: BioNet Systems, LLC*
OS: Windows XP
Windows:
Comments:
 
I use three spyware programs:

Webroot
Adaware
and now Microsoft AntiSpyware

None of them care about this file.

I just want to throw this out there. Webroot find items that Adaware can't
find. Adaware finds items that Webroot can't find. However so far
Microsoft AntiSpyware has found MORE then both Webroot and Adaware combined.
This is based on ghosting a drive and scanning that same image with each
scanner individually.
 
Well, meaningless to the file in question :)


Justin Emlay said:
This file is not detected by anything. I removed it myself. I was just
wondering what the heck it was and wondering how it was able to trash my
system so efficiently.

The Google reference is just a single person listing the file in his
entire list of processes. The Google reference is meaningless.
 
Well this solves this mistery!

BioNet Systems, LLC, Sells Net Nanny Internet Safety Solution in $5.3
Million Transaction

Someone got RIPPED OFF!!!!!

I installed this program a few weeks ago to test the chat sniffing feature.
The program was horrable and promptly removed. However that process hung
around to rip my system a new one. I just installed Net Nanny on a test
machine and sure enough that process showed up.

The thing that ticked me off the most about that program was that it
restarted my machine without asking OR EVEN TELLING me first. Jerks!
 
Justin said:
Well this solves this mistery!

BioNet Systems, LLC, Sells Net Nanny Internet Safety Solution in $5.3
Million Transaction

Someone got RIPPED OFF!!!!!

I installed this program a few weeks ago to test the chat sniffing
feature.
The program was horrable and promptly removed. However that process
hung
around to rip my system a new one. I just installed Net Nanny on a
test machine and sure enough that process showed up.

The thing that ticked me off the most about that program was that it
restarted my machine without asking OR EVEN TELLING me first. Jerks!
Glad you got it sorted. Thanks for taking the time to post the solution.
This will help others in the future.

Malke
 
Back
Top