I’ve been infected with the Windows Disk malware. I have followed the instructions for removing it using rkill and mbam. The procedure ran perfectly and at the end of the mbam scan a list of malware files were added to mbam and then removed to quarantine by me. They are in mbam quarantine right now.
However when i logged back on I noticed the 'windows disk' icon was still on my desktop. Then when my log-on is complete the 'windows disk' analyser (the procedure that ends up in you being asked to buy something) fires up and does its analysis. However when I close the 'windows disk' analyser by clicking on the cross in the top right hand of the screen it closes ok AND i do NOT get the usual 'windows disk' pop up warnings all over the place about memory, ram hard disk errors etc In fact the only problem im seeing right now is the 'windows disk' icon and the analyser which auto runs until I close it. Then it stops running ok and I can use my pc without any 'windows disk' pop ups appearing.
The residual LOG of Windows Disk processes and files seems to be>>>>>>>>>>>>>>
The residual ‘Windows Disk’ processes left on my pc are .................................
d0INnD4237k.exe (stopping this process stops the analyser running so its clearly the main culprit but it is hidden and i cannot find it to delete it)
rundll32.exe (im not sure what this process is telling me or if it is windows disk related)
In addition I have the following ‘windows disk’ files on my pc which just come back if I delete them in the conventional file-delete manner...........
%UserProfile%\Start Menu\Programs\Windows Disk\Windows Disk.lnk
%UserProfile%\Start Menu\Programs\Windows Disk\Uninstall Windows Disk.lnk
%UserProfile%\Start Menu\Programs\Windows Disk\
%UserProfile%\Desktop\Windows Disk.lnk
I need to find and delete the processes and files if you could possibly help me do that?
Many thanks
Rgds
Chris
post script................i have found the culprit program in the c/program data folder.
The windows disk filename is d0INnD4237k.exe located as above.
Its definately the culprit because its the destination for the windows disk short cut link and its the process that runs when the windows disk analyser is running and stops when the process is stopped in task manager.
However my problem now is that i cannot delete the culprit file because it is access denied.
So my problem now is how to delete the culprit file. Could you help please?
Rgds
Chris
EDIT: Posts merged ~BP
Edited by Budapest, 14 February 2011 - 04:34 PM.