Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Bagle mdelk.exe, german.exe, wintem.exe


  • Please log in to reply

#1
Nic :o)

Nic :o)

    New Member

  • Member
  • Pip
  • 2 posts
Hi,

I've looked everywhere on the internet and tried many things but still cannot find a solution. A colleague has told me how excellent the response and advice is you give

The issue I have is as follows

I notice my laptop was running very slowly, I tried to run Norton to check it but realised it was not running. On trying to restart I received the message not valid Windows32 application.

I uninstalled Norton and purchased Kaspersky and installed but get the same message

I notice I have the following process running WinTems.exe, standard task manager will not kill this so I use APT and killed this.

I have run numerous online scans, BitDefender, KasperSky, Panda, Housecall and tried removing this way

I have the mdelk.exe file in my Windows\system32 folder and canít remove this

If I run XoftSpySE I get the message

Bagle IX Worm, Registry Key, software\firstrun
Downloader Bagle GI Trojan, Registry Value, software\microsoft\windows\currentversion\run\german.exe

When looking at the registry these do not exist

When I reboot windows I get a pop up appear asking what file I want to crack?

Iím now at a loss and hoping you can help out

Thanks

Nic
  • 0

Advertisements


#2
david28

david28

    Member

  • Member
  • PipPip
  • 10 posts
It seems that you may have some sort of malware :) I have noticed you posted this in the Malware Removal forum, but, there is no HJT log suplied with it. Try posting a HJT log in the Malware Removal forum. (Read this topic before you post the log though.

Regards,
David.

Edited by david28, 17 March 2008 - 04:44 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP