WinBagleALmm free removal tool description
Free removal tool for Win32.Bagle.AL@mm

Symptoms:
- Presence of file %SYSTEM%WINdirect.exe.
- Presence of file %SYS@mm

Symptoms:
- Presence of file %SYSTEM%WINdirect.exe.
- Presence of file %SYSTEM%windll.exe.
- Presence of registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunwin_upd.exe = %SYSTEM%WINdirect.exe or
HKCUSOFTWAREMicrosoftWindowsCurrentVersionRunwin_upd.exe = %SYSTEM%WINdirect.exe.
- Presence of registry key HKCUSOFTWAREMicrosoftWindowsCurrentVersionRu1n.

Technical description:
The worm comes in the form of a small file, that drops another file ( namely WINDirect.exe) in the %SYSTEM% directory.

This file then tries to raise it’s privilege level and then starts a thread in which it keeps looking at all the processes and when it finds one within a list ( in order to prevent updating an AV product or the use of a firewall ) it tries to terminate it. Then it starts another thread that tries to download the main part of the massmailer from a list of addresses, each 10 hours.

External Mirror 1




Author:
admin
Time:
Saturday, May 10th, 2008 at 11:55 pm
Category:
AntiVirus
Comments:
You can leave a response, or trackback from your own site.
RSS:
You can follow any responses to this entry through the RSS 2.0 feed.
Navigation:

Responses to “Win32.Bagle.AL@mm free removal tool 1.0 Download”

  1. yandri Says:

    plese to download

  2. afriansyah Says:

    good

  3. jaikumar Says:

    fine & good

  4. ting Says:

    good

  5. saeed Says:

    thanks

  6. hunny Says:

    i need antivirus

  7. atif Says:

    i can slove my problem through this antivirus

  8. Maro Says:

    I need antivirus for emergency

  9. atul.trimalle Says:

    hi

  10. AMJD Says:

    thank for you

  11. manmohan Says:

    give me this pac

Leave a Reply