|
Description
free Win32.Bagle.AD@mm Removal Tool
Features
Symptoms:
- When run, the virus displays a fake message, stating: "Can't find a viewer associated with the file"
- Presence of the next files in %SYSTEM% folder:
loader_name.exe
loader_name.exeopen
loader_name.exeopenopen
- Presence of the next registry key or entry:
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] "reg_key"="%SYSTEM%loader_name.exe"
where %WINDOWS% points to Windows folder (or WinNT on Windows NT based systems) %SYSTEM% points to "System" folder on Windows 9x systems and "System32" folder on WinNT systems.
- Presence of files named:
Microsoft Office 2003 Crack, Working!.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Microsoft Office XP working Crack, Keygen.exe
Porno, sex, oral, anal cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
KAV 5.0
Kaspersky Antivirus 5.0
Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 7.exe
Windown Longhorn Beta Leak.exe
Opera 8 New!.exe
XXX hardcore images.exe
WinAmp 6 New!.exe
WinAmp 5 Pro Keygen Crack Update.exe
Adobe Photoshop 9 full.exe
Matrix 3 Revolution English Subtitles.exe
ACDSee 9.exe
in folders whose names contain the string "shar"
Technical description: The virus arrives via e-mail
If the attachment is in a password protected zip file, following messages can also be found in the Body:
For security reasons attached file is password protected. The password is ...
For security purposes the attached file is password protected. Password -- ...
Note: Use password ... to open archive.
Attached file is protected with the password for security reasons. Password is ...
In order to read the attach you have to use the following password: ...
Archive password: ...
Password - ...
Password: ...
|