Results 1 to 6 of 6

Thread: How to remove Win32.Bagle.{C-E}@mm from my personal computer?

  1. #1
    Join Date
    Dec 2009
    Posts
    32

    How to remove Win32.Bagle.{C-E}@mm from my personal computer?

    My uncle has gifted me a new personal computer. This computer has the following configuration.
    Operating System: Windows vista.
    Hard disk: SATA 250 GB Hard disk.
    Processor: AMD Athlon processor
    Graphic card: ATI Radeon HD 4350 (512 MB).
    Memory: 2 giga bytes of random access memory (RAM).
    I was using internet and started to receive mail from other email. Once I got the mail from unknown user and downloaded the attachment with it, after that my personal computer is giving me problem. When I scanned the system it showed me a message that “Win32.Bagle.{C-E}@mm virus is detected”. I have no idea how to delete this virus.

  2. #2
    Join Date
    Feb 2008
    Posts
    2,635

    Re: Win32.Bagle.{C-E}@mm attacks through email

    Win32.Bagle.{C-E}@mm which is detected on your personal computer is kind of virus/worm. Win32.Bagle.{C-E}@mm replicates itself again and again makes your system slow. Basically this virus Win32.Bagle.{C-E}@mm spreads through email from one user to another so be careful before downloading attachment sent from unknown user. Download macafee antivirus and this will solve your problem.

  3. #3
    Join Date
    May 2008
    Posts
    2,945

    Re: Preventive measures from Win32.Bagle.{C-E}@mm

    The virus named Win32.Bagle.{C-E}@mm can be removed from your system by using antivirus software, but you must be careful before downloading any attachment. Follow these steps to prevent yourself from such virus problems. Enable your firewall settings. Update your antivirus software. Scan your system at regular interval. Avoid using pirated software.

  4. #4
    Join Date
    Jan 2006
    Posts
    3,792

    Re: Files and registry related to Win32.Bagle.{C-E}@mm

    If you are suffering with Win32.Bagle.{C-E}@mm then you will be having the following registry key in your registry window.
    HKCU\Software\DateTime2\port with value "2745"
    HKCU\Software\DateTime2\frun with value "1"
    HKCU\Software\DateTime2\uid with random value
    And the following files will be present on your system.
    C:\Windows\System\readme.exe, 15872 bytes
    C:\Windows\System\readme.exeopen, 15994 bytes
    C:\Windows\System\doc.exe, 1536 bytes
    C:\Windows\System\onde.exe, 18944 bytes
    So if you find these files on your system, then delete those files from your system.

  5. #5
    Join Date
    Jan 2006
    Posts
    4,221

    Re: Method used by Win32.Bagle.{C-E}@mm virus for spreading.

    Win32.Bagle.{C-E}@mm virus normally arrives through emails. The email will have the following format.
    From: any unknown user id
    Subject: Subject will be like this (Registration confirmation, From Hair-cutter, You really love me? Or any of the title which attracts the user attention.)
    Body:
    The body will contain message which will promote user to download attachment.

    Once the user downloaded the attachment and opened the file then will get execute and drops four files in "C:\Windows\System" for following purpose.
    Readme.exe for regestring itself so that virus can get executed every time system restarts. Doc.exe for injecting the explorer.exe in address space. Onde.exe is the main component of the virus.
    Win32.Bagle.{C-E}@mm virus will do the following changes in your registry.
    HKCU\Software\DateTime4, with the only subkey "frun = 1".
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run, with the subkey "rate.exe = C:\Windows\System\i1ru74n4.exe"

  6. #6
    Join Date
    Apr 2008
    Posts
    3,339

    Re: Method for removing Win32.Bagle.{C-E}@mm virus

    Delete following files from your computer.
    doc.exe, readme.exe, onde.exe, readme.exe from window system files and then delete the following registry keys. From your registry windows.
    "gouday.exe = C:\Windows\System\readme.exe" under "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run".
    "frun=1", "port=2745", "uid=[random value]" under "HKEY_CURRENT_USER\Software\DateTime2".
    After deleting files and registry key scan your system to conform that the virus is deleted.

Similar Threads

  1. How to delete Worm.Win32.Autorun.Vmd from my personal computer?
    By BRANT45 in forum Networking & Security
    Replies: 5
    Last Post: 05-01-2010, 03:56 AM
  2. How to delete Win32.Gattman.A virus from my personal computer?
    By CAROLG in forum Networking & Security
    Replies: 5
    Last Post: 29-12-2009, 11:56 PM
  3. How to remove Win32.MyDoom.AE@mm from my personal computer?
    By BRANT45 in forum Networking & Security
    Replies: 5
    Last Post: 24-12-2009, 03:14 AM
  4. Replies: 5
    Last Post: 23-12-2009, 11:46 PM
  5. How to remove Win32.MyDoom.M@mm from my personal computer?
    By RICO12 in forum Networking & Security
    Replies: 5
    Last Post: 23-12-2009, 05:37 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,492,349.10719 seconds with 17 queries