<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; drv</title>
	<atom:link href="http://www.tech-linkblog.com/tag/drv/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tech-linkblog.com</link>
	<description></description>
	<lastBuildDate>Fri, 30 Jul 2010 00:37:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<image>
  <link>http://www.tech-linkblog.com</link>
  <url>http://tech-linkblog.com/favicon1.ico</url>
  <title></title>
</image>
		<item>
		<title>Removing Win32/Bagle.HE worm</title>
		<link>http://www.tech-linkblog.com/removing-win32baglehe-worm/</link>
		<comments>http://www.tech-linkblog.com/removing-win32baglehe-worm/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 14:23:22 +0000</pubDate>
		<dc:creator>Paul Sylvester</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[411]]></category>
		<category><![CDATA[anti virus software]]></category>
		<category><![CDATA[antispyware]]></category>
		<category><![CDATA[Application]]></category>
		<category><![CDATA[application data]]></category>
		<category><![CDATA[B .  When]]></category>
		<category><![CDATA[Bagle]]></category>
		<category><![CDATA[CURRENT]]></category>
		<category><![CDATA[current user]]></category>
		<category><![CDATA[CurrentVersion]]></category>
		<category><![CDATA[danger]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[date]]></category>
		<category><![CDATA[documents and settings]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[drv]]></category>
		<category><![CDATA[e mail]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[eset]]></category>
		<category><![CDATA[future]]></category>
		<category><![CDATA[gen]]></category>
		<category><![CDATA[hidn]]></category>
		<category><![CDATA[HKEY]]></category>
		<category><![CDATA[hldrrr]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[microsoft windows]]></category>
		<category><![CDATA[order]]></category>
		<category><![CDATA[pc security]]></category>
		<category><![CDATA[popup]]></category>
		<category><![CDATA[process]]></category>
		<category><![CDATA[Run]]></category>
		<category><![CDATA[scamware]]></category>
		<category><![CDATA[security scans]]></category>
		<category><![CDATA[Settings]]></category>
		<category><![CDATA[Show]]></category>
		<category><![CDATA[site]]></category>
		<category><![CDATA[size]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[software microsoft]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Tooso]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan tooso]]></category>
		<category><![CDATA[user]]></category>
		<category><![CDATA[user software]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32 bagle]]></category>
		<category><![CDATA[wasting]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[Win]]></category>
		<category><![CDATA[windefender]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.tech-linkblog.com/?p=2358</guid>
		<description><![CDATA[<p><center><a href="http://www.tech-linkblog.com?wp_ct=103" target="_blank"><img src="http://affiliates.justhost.com/control/img/banners/justhost_468x60v2.gif" /></a></CENTER>
<br/><a href="http://www.tech-linkblog.com/removing-win32baglehe-worm/">Removing Win32/Bagle.HE worm</a></p>
Removing Win32/Bagle.HE worm Here is another virus that seems to be spreading lately.   From the looks of it, it sees to be another email worm.  Here is what eset says: Aliases Email-Worm.Win32.Bagle.gt (Kaspersky), W32/Bagle.gen (McAfee), Trojan.Tooso!gen (Symantec) Find Coupons here Win32/Bagle.HE is a worm that spreads via e-mail. The size of its executable is 40565 [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://www.tech-linkblog.com?wp_ct=103" target="_blank"><img src="http://affiliates.justhost.com/control/img/banners/justhost_468x60v2.gif" /></a></CENTER>
<br/><a href="http://www.tech-linkblog.com/removing-win32baglehe-worm/">Removing Win32/Bagle.HE worm</a></p>
<p>Here is another virus that seems to be spreading lately.   From the looks of it, it sees to be another email worm.  Here is what eset says:</p>
<h3>Aliases</h3>
<p>Email-Worm.Win32.Bagle.gt (Kaspersky), W32/Bagle.gen (McAfee), Trojan.Tooso!gen (Symantec)</p>
<p>Win32/Bagle.HE is a worm that spreads via e-mail. The size of its executable is 40565 B .</p>
<p>When executed the worm copies itself in the following locations:</p>
<ul>
<li>Documents and Settings\All Users\Application Data\hidn\<br />
hldrrr.exe</li>
<li>Documents and Settings\All Users\Application Data\hidn\<br />
hidn2.exe</li>
</ul>
<p>In order to be executed on every system start, the worm sets the following Registry entry:</p>
<p><span style="font-family: Courier New,Courier,mono;">HKEY_CURRENT_USER\SOFTWARE\<a href="http://www.amazon.com/gp/redirect.html?ie=UTF8&#038;location=http%3A%2F%2Fwww.amazon.com%2Fs%3Fie%3DUTF8%26rs%3D%26sort%3Dsalesrank%26ref_%3Dsr%5Fst%26keywords%3DMicrosoft%26qid%3D1267804500%26rh%3Dn%253A%25211000%252Ci%253Astripbooks%252Ck%253AMicrosoft%26pag"target="_blank"rel="nofollow"title="Microsoft" >Microsoft</a>\<a href="http://www.amazon.com/gp/redirect.html?ie=UTF8&#038;location=http%3A%2F%2Fwww.amazon.com%2Fs%3Fie%3DUTF8%26x%3D0%26ref_%3Dnb%5Fsb%5Fnoss%26y%3D0%26field-keywords%3DWindows%26url%3Dsearch-alias%253Daps&#038;tag=techlinkblogc-20&#038;linkCode=ur2&#038;camp=1789&#038;creative=390957"target="_blank"rel="nofollow"title="Windows" >Windows</a>\CurrentVersion\Run\drv_st_key </span></p>
<p><div style="float: left; margin-right: 5px; margin-bottom: 5px"><script type="text/javascript"><!--
amazon_ad_tag = "techlinkblogc-20"; amazon_ad_width = "300"; amazon_ad_height = "250"; amazon_ad_link_target = "new"; amazon_ad_border = "hide"; amazon_ad_discount = "remove";//--></script>
<script type="text/javascript" src="http://www.assoc-amazon.com/s/ads.js"></script></div><span style="font-family: Courier New,Courier,mono;">It seems to have a manual removal process, Unless you pay for the other software but according to the 411 on PC Security:</span></p>
<blockquote><p><strong>Win32/Bagle.HE worm</strong> is a “threat” that appears in security scans by fake antispyware WinDefender 2008.</p>
<p>The danger of Win32/Bagle.HE worm is supposed to scare you into wasting $49.95 on WinDefender 2008.</p>
<p>Unless you like getting ripped off, don’t download the software the Win32/Bagle.HE worm popup links to. You’re not really infected with Win32/Bagle.HE worm — you’re infected with scamware that you need to remove.</p>
<p>I’ll show you how to get rid of Win32/Bagle.HE worm and WinDefender 2008, for free.</p>
<p>[via 411 on <a rel="nofollow" href="http://www.tech-linkblog.com/MyRecommends/PC_Security/2358/1" target="_blank"><span style="color: #888888;">PC Security</span></a>]</p></blockquote>
<p>According to this site you can remove it by doing some steps.  I think <a rel="nofollow" href="http://www.tech-linkblog.com/MyRecommends/Kaspersky_has_an_easier_way_to_remove_it/2358/2" target="_blank">Kaspersky has an easier way to remove it</a> and it looks like most <a href="http://www.tech-linkblog.com/anti-virus-and-anit-spyware-resources/" target="_blank">anti-virus software will remove this</a>.   You need to remember that only you can prevent this from the future.   You should also update your <a rel="nofollow" href="http://www.tech-linkblog.com/MyRecommends/windows_update/2358/4" target="_blank">windows update</a> and make sure your system is up to date.</p>
<p>&copy;2010 <a href="http://www.tech-linkblog.com"></a>. All Rights Reserved.</p>.]]></content:encoded>
			<wfw:commentRss>http://www.tech-linkblog.com/removing-win32baglehe-worm/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
	</channel>
</rss>
