Help - Search - Members - Calendar
Full Version: Mdelk.exe / Worm_bagle.ko
BleepingComputer.com > Security > Am I infected? What do I do?
   
duhhan
I had norton anti-virus software installed on my computer, i was sending some emails and disabled it for a while, this was my biggest regret after my friend send me a program to send mails, and when i click on this file it says "select a file to crack" and nothing happens, after this my anti-virus program was not working anymore and i couldn't install any anti-virus program at all! I also can't start my computer in safe mode, when I select to start it in safe mode, after 10 seconds from loading the files on the screen it simply reboots.

So My only chance was an online webscanner (trendmico housecall), that did found the following:

Worm_Bagle.ko (c:\windows\system32\mdelk.exe) was infected
troj_generic
troj_proxydis.A
win32\dnet trzdnet.drop trojan.win32.disntnet6656
(c:\windows\system32\iosdt\iosdt.com) (was infected)

most were cleared BUT the mdelk.exe still can't be removed! it keeps installing itself. I managed to remove it for a while with the AD-AWARE since it gave me the option to remove it after reboot. But immediately after it was removed and the windows xp media centre started again, a window saying "select file to crack" was loaded again, then i relised from where the infection came from and deleted this program (as described earlier in the beginning of the problem)

until now i have these two files that contain mdelk:

C:\Windows\Prefetch\MDELK.EXE-0EF461CE.pf
C:\Windows\System32\mdelk.exe (the icon of the mdelk.exe file is like a bunch of 3 keys)

Can anyone please help me on how to kill this process from being born again?

thankyou
Orange Blossom
Hello duhhan and welcome to BC welcome.gif

Can you tell us the name of the "program" your friend sent you?

What is your operating system: Windows XP, Vista, etc.?

Do you have any other security programs installed?

If so, what are they?

Orange Blossom fruits_cherry.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.