seriously seriously urgent- mds search booster related- please advise

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by beanier, Feb 23, 2005.

  1. beanier

    beanier Specialist

    http://www.bleepingcomputer.com/forums/index.php?showtopic=10501&st=0&#entry66635

    this is a thread to another forum I got from google.

    I think I might need help quickly.

    I have this program installed, mds search booster, with a related cool web search infection, but I think the mds is the main problem.

    When I try to uninstall mds, windows media player starts, in safe and normal boot mode. Don't know what to do. Also a cool web search hijack, I think mabye the two might be related, without removing the mds, cws keeps coming back.

    I have tried the steps in the sticky spyware thread, cws is still there. Like before, I think mds might be the root of the problem.

    THIS MIGHT BE VERY IMPORTANT. PLEASE HELP ME GET RID OF THIS MDS SEARCH BOOSTER QUICKLY. Thanks a bunch, I'll post why I'm paranoid when this thing is off my computer.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See this thread here on MG's . It shows how to remove Haxdoor problems:
    http://forums.majorgeeks.com/showthread.php?t=53615

    You really should do the following though so we really no what you have:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you also have HorseServer problems, do the followiing:

    Download: http://www.atribune.org/downloads/HSFix.zip

    Extract the tool from the ZIP File to its own folder. Please boot to Safe Mode, open the Tool folder and DoubleClick hsfix.bat and let it run. It will produce a log here - C:\hslog.txt

    Please run the tool as directed and attach the log it produces along with a fresh HijackThis Log and we'll see where you stand.
     
  4. beanier

    beanier Specialist

    Basically I just saw I had cws, did the steps, and couldn't get rid of it. Looked in install/uninstall, saw the new prog, and looked it up... no real symptoms, other than the browser hijack...here is the log, I'll do the steps of removal again to see if the virus/trojans are there again... it will take a while, though. thanks.
     

    Attached Files:

  5. beanier

    beanier Specialist

    should I do the spyware steps? or just wait untill mds is gone? and then get rid of cws?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't have any of the problems you were referring to in your original thread. At least not from what I see right now.

    I'll post something for you to do in a few minutes.
     
  7. beanier

    beanier Specialist

    sorry, forgot. I went to msconfig to look around, and mcafee and zone alarm weren't there, shouldn't they be? just wondering. because zone alarm doesn't start at startup, and mcafee does, but turns from red(enabled) to black(disabled).
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search-paga.com/10039/
    F3 - REG:win.ini: run=C:\WINDOWS\inetdata\services.exe
    O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
    O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\inetdata\services.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was the previous log from safe mode? I'm not sure what you are trying to say above but it does look like some of your process are not loading at startup. Have you been playing with HijackThis to fix things before coming here for help?
     
  10. beanier

    beanier Specialist

    how do I- use Windows Explorer to delete:
    C:\WINDOWS\inetdata\services.exe

    and what do you mean - You don't have any of the problems you were referring to in your original thread. At least not from what I see right ..

    I just didn't understand the statement.. cws-y is still there, I just ran cwshedder and it found it... not trying to be rude at all, just didn't understand what you meant... thanks for helping...
     
  11. beanier

    beanier Specialist


    no, no safe mode... that's exactly what I'm trying to say, it doesn't look like my processes are loading! I disabled bho demon, to see if cws was hiding in there or something, that's it. and I don't screw with the registry, been there, done that...

    and services.exe keeps trying to access the internet, zone alarm stops it, I can start ZA, just not from startup..

    and I might be wrong about mcafee starting at startup, I think I have to start it from the start menu, then it turns black... probably the doing of whatever's on my system...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't know how to run Windows Explorer???

    Click Start and select Explore. Then navigate your way to C:\WINDOWS\inetdata and then locate the services.exe file in that folder and delete it. Do not delete services.exe from anywhere else.

    You need to follow the steps in my message in order from beginning to end with no interruptions and do not use your browser during those steps. Only open it again where I tell you to come back and post a log.

    The link you referred to in your first message refers to problems with:

    Horseserver.net, klikfeed.com & Backdoor.Haxdoor.D Analysis

    You show now signs of those!

    Is CWShredder giving you a file name?
     
  13. beanier

    beanier Specialist

    the link was because it mentioned mds search booster, which is on my computer

    "Adds itself to the Add/Remove programs as MDS Search Booster

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MDS Search Booster"


    cws is gone... mcafee + zone alarm don't start at startup... there's something I'm forgetting, don't know what...

    cws was giving me cws-y.exe, mabye without the dash...
     
  14. beanier

    beanier Specialist

    dstart.exe I think is part of the mds booster,could be wrong, it was on zone alarm, I took it off, now it's back on again...theres alot of crap on ZA notepad.exe, process 1924, pxsetup, setup.exe...services.exe...
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you use Add/Remove programs to uninstall Search Booster?

    Looks to me like someone deleted the Startup procedures for some of your applications. You may need to uninstall them, reboot, and then reinstall.

    You did not post the new HJT log.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use a program called Photodex Presenter? It's setup program is named pxsetup.exe
     
  17. beanier

    beanier Specialist

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also run what I gave you in message # 3.
     
  19. beanier

    beanier Specialist

    sorry, thought I did post a log. yeah, we do have some sort of photo presenter something... No, I can't uninstall mds, I click remove, and windows media player starts, and that's it.. it's still there...
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay some of you McAfee stuff is now showing up as loading at Startup. But not ZoneAlarm. May need to reinstall to make sure it is properly configured. Yes you could just copy the zlclient.exe to the startup folder but there could be other things messed up.

    Try this:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixmdsb.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Double-click on the fixmdsb.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes
     
  21. beanier

    beanier Specialist

    hs log:

    and I remembered what I forgot earlier... don't know if it makes any difference, but when I boot into safe mode, it gives me the option of being admin or owner, and in admin, everything is brand new, never changed, like a fresh install, while owner is the system I'm on all the time, my programs,etc.
    I just reinstalled windows a couple months ago, and I remember not making two users, it was too complicated when we did have two... so mabye I'm paranoid, but did the mds create a user? and that's why people can't get rid of it? total paranoia...

    and mcafee shows at startup, but the icon turns black(disabled) after a minute...
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Admin is always there in safe mode! Do what I gave you in message # 20
     
  23. beanier

    beanier Specialist

    I did the regedit thing you posted... in safe mode if that makes any difference...

    I don't see the prog in add/remove, but mcafee still turns black after a minute or two, and ZA doesn't go on startup... thanks for all your help.

    do you think it might be gone and now it's just left to fix mcafee and ZA?
     
  24. beanier

    beanier Specialist

    I could be wrong about all this, but,

    man, you need to see my ZA program control..

    d-start is there, I don't remember having it before...notepad.exe,process 1924,Run a DLL as an App, Self-extracting cabi...(!),setup.exe,...windows@installer...which is different than windows (space) whatever...
     
  25. beanier

    beanier Specialist

    just ran spybot , it said it found cws y.exe... it might just be hiding in some other log or quarantine list somewhere or something... don't know..
     
  26. beanier

    beanier Specialist

    just ran both cws shredders, they found nothing... deleted quarantine list in adaware, spybot still found cws again... I bet its a mistake somehow... am in the process of running all the antiviri's now....
     
  27. beanier

    beanier Specialist

    So mcafee still turns black about a minute after startup... I got ZA to come back on, so the mcafee I guess is the only thing left... do I need to go to software forum for the final fix?

    thanks a lot... and just to be sure, in the link on my first post, it mentioned keyloggers in conjunction with the mds prog... there weren't any, right? thanks for all the help...

    and here's one last hijackthis log, just to be sure everythings good...
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot can make a log on what it finds. Post the log. I would like to see where it is finding y.exe and why it keeps coming back.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is clean from what I can see. I would disconnect from the internet phyiscally and then do the following (make sure you have the installation programs first - and updates McAfee just updated again today):

    - uninstall McAfee
    - uninstall ZoneAlarm
    - reboot
    - reinstall McAfee & update
    - reboot and do full system scan
    - if anything was found in the scan, reboot after fixing
    - re-install ZoneAlarm
    - reconnect your cable

    See how things work now. Do you see all the proper processes in your HJT log?
     
  30. beanier

    beanier Specialist

    I just ran it, nothing came up... I think it was just a remnant of a log or list or something...

    thanks so much for your help... the reason I was crapping my pants last night was when I looked in that first link, about haxdoor & stuff, it mentioned the mds search booster... and KEYLOGGERS that reported back to unknown addresses... keyloggers+bank accounts NO MIXY MIXY...

    It is so wrong just to take someone's money that they work so hard for... phishers, etc... almost makes one a proponet of prison ****... you know what they do to geeks in prison, right? :] thanks again..
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds