I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
Worm Bagle
SHA256: 461d8100dda06da2d6565353a613f50365c040f17fb7fe417e2239148733c34a
SHA1: 34c458b6c7d0f11a18a25325c70e15ee0ff4c67e
MD5: f7882c8dac0e8611814fb74baaa0fec1
File size: 29978 bytes
Created files:
%Program Files Common%\Microsoft Shared\ACDSee 9.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Adobe Photoshop 9 full.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Ahead Nero 7.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Matrix 3 Revolution English Subtitles.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Microsoft Office 2003 Crack, Working!.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Microsoft Office XP working Crack, Keygen.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Opera 8 New!.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Porno pics arhive, xxx.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Porno Screensaver.scr – Worm Bagle
%Program Files Common%\Microsoft Shared\Porno, sex, oral, anal cool, awesome!!.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Serials.txt.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\WinAmp 5 Pro Keygen Crack Update.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\WinAmp 6 New!.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Windown Longhorn Beta Leak.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\Windows Sourcecode update.doc.exe – Worm Bagle
%Program Files Common%\Microsoft Shared\XXX hardcore images.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\ACDSee 9.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Adobe Photoshop 9 full.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Ahead Nero 7.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Matrix 3 Revolution English Subtitles.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Microsoft Office 2003 Crack, Working!.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Microsoft Office XP working Crack, Keygen.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Opera 8 New!.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Porno pics arhive, xxx.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Porno Screensaver.scr – Worm Bagle
%Program Files%\Movie Maker\Shared\Porno, sex, oral, anal cool, awesome!!.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Serials.txt.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\WinAmp 5 Pro Keygen Crack Update.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\WinAmp 6 New!.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Windown Longhorn Beta Leak.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\Windows Sourcecode update.doc.exe – Worm Bagle
%Program Files%\Movie Maker\Shared\XXX hardcore images.exe – Worm Bagle
%WinDir%\cjector.exe – Worm Bagle
%SysDir%\bawindo.exe – Worm Bagle
Worm Bagle created autostart registry keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\bawindo: %WinDir%\System32\bawindo.exe