chinadragon
Topic Starter
Hi all, my first post here, as so far I've been so lucky to avoid problems, but I recently copied some files from a colleague who has major problems on her pc (which I didn't know at the time) and had a big headache since.
The problem has several features:
1. Norton detects a trojan in windows\mdm.exe but can't fix it
2. Spybot detects same and also registry entry HKLM\software\microsoft\windows\currentversion\run\svchost=c:\windows\mdm.exe
Calls it "coolwwwsearch.olehelp"
3. Ad-aware finds the same reg entry, as does Trojanhunter, which calls it "agent.100"
4. Bazooka finds "exploit searchterror.com" "tcpdetect dialer" and "windir.svchost"
5. If mdm.exe and the reg entry are deleted, they regenerate themselves from elsewhere. I've cleaned all temp folders etc. but still happens.
6. I can't show hidden files anymore and I also can't switch off system restore - I guess this is the work of the hidden file which controls the malware.
7. In msconfig, there is a startup entry for the mdm.exe file, but this also comes back after unchecking.
By the way, all the above done in safe mode, so even this doesn't help. Always comes back. The only temporary solution is to stop the SVCHOST process (easy coz it's in caps) in taskmanager, but it's soon back!
Despite intensive searching on the net, couldn't find a solution, although there is mention of various problems with mdm.exe and svchost, but not same as mine. Anyway, really appreciate if you have any ideas about this. I guess the clue is finding the 'master file' which controls and regenerates the others.
Thanks
The problem has several features:
1. Norton detects a trojan in windows\mdm.exe but can't fix it
2. Spybot detects same and also registry entry HKLM\software\microsoft\windows\currentversion\run\svchost=c:\windows\mdm.exe
Calls it "coolwwwsearch.olehelp"
3. Ad-aware finds the same reg entry, as does Trojanhunter, which calls it "agent.100"
4. Bazooka finds "exploit searchterror.com" "tcpdetect dialer" and "windir.svchost"
5. If mdm.exe and the reg entry are deleted, they regenerate themselves from elsewhere. I've cleaned all temp folders etc. but still happens.
6. I can't show hidden files anymore and I also can't switch off system restore - I guess this is the work of the hidden file which controls the malware.
7. In msconfig, there is a startup entry for the mdm.exe file, but this also comes back after unchecking.
By the way, all the above done in safe mode, so even this doesn't help. Always comes back. The only temporary solution is to stop the SVCHOST process (easy coz it's in caps) in taskmanager, but it's soon back!
Despite intensive searching on the net, couldn't find a solution, although there is mention of various problems with mdm.exe and svchost, but not same as mine. Anyway, really appreciate if you have any ideas about this. I guess the clue is finding the 'master file' which controls and regenerates the others.
Thanks