Re: Thanks :) Re: Hi Message bodies are randomly chosen from a predefined list: :) :)) Attachment names can be one of the following names with EXE, SCR, COM, and CPL Bagle.AT uses the following text strings as subjects for infected e-mails that it sends: Re: Re: Hello Re: Thank you!

Name bawindo Filename bawindo.exe Command Unknown at this time.

The worm also tries to kill processes of the Bropia MSN-worm: Beautiful Ass.pif John Kerry as Super

Is bawindo.exe harmful to my computer? In most cases, it helps to check the Windows registry for bawindo.exe errors!

The worm main executable requires some delphi runtime DLLs to be present so it might not work on all systems.

  1. Firstly, it's very important to identify the error that is causing the slow down and lacklustre performance.
  2. Assessment: danger Imprint | Privacy PolicyCopyright©2012 Process Information.
  3. It also tries to propagate itself via network shares and peer-to-peer (P2P) file sharing applications like Kazaa by dropping copies of itself to folders with names containing the string shared.

Infection Bagle.AT arrives a file attachment to an e-mail message, which has varying subject lines and body texts. In some cases, this also includes bawindo.exe. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first.

Technical Details Assiral.A arrives as a Windows PE executable. The downloaded file is saved on disk under the following name: %SystemDir%\re_file.exe At the time of this writing, some of the URLs are functional. Users running other Windows versions can proceed with the succeeding procedure sets. The file bawindo.exe is part of the program unknown from the manufacturer unknown.

Autostart Technique To enable its automatic execution at every Windows startup, this worm creates the following registry entry: HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Run bawindo = "%System%\bawindo.exe" (Note: %System% is the Windows system folder, which In the left panel, double-click the following: HKEY_CURRENT_USER>Software>Microsoft> Windows>CurrentVersion>Run In the right panel, locate and delete the entry: bawindo = "%System%\bawindo.exe" (Note: %System% is the Windows system folder, which is usually

It contains the following text: Assiral.A also drops a small Visual Basic Script file, C:\WINDOWS\System32\REG_32.vbs, and executes changing some of the policy settings from the Windows registry. Also, it contains a backdoor function.

The script also checks and modifies the registry: [HKCU \Software\Microsoft\WAB\EddieMail] so it send itself out only once per infected computer.

It also tries to copy itself on drives A-Z as "MS_LARISSA.EXE" and in Windows directory as "LOVE_LETTER.TXT.exe". Propagation (P2P) Bagle.AT is capable of spreading to shared folders of Peer-to-Peer clients.

Files with the following extensions are checked: .wab .txt .msg .htm .shtm .stm .xml .dbx .mbx .mdx .eml .nch .mmf .ods .cfg .asp .php .pl .wsh .adb .tbb .sht .xls .oft

Re: Thanks :) Message body: :)) Attachment: (any one of the following, with .com, .cpl, .exe, or .scr extension) Joke Price Payloads This worm terminates the following antivirus and security-related programs: The worm drops and executes the following files: C:\WINDOWS\WinVBS_32.vbs C:\WINDOWS\System32\REG_32.vbs C:\LARISSA_ANTI_BROPIA.html It also tries to open a web page on www.geocities.com and modify Internet Explorer home page settings. If system date is Apr 25th, 2006 the worm uninstalls itself from the infected system by deleting its startup key in the Registry and terminating its own process.

What are the problems with bawindo.exe Error exactly?