W32.Bakain
Aliases: W32/Bakain
Variants: N/A
Classification: Malware
Category: Computer Worm
Status: Active and Spreading
Spreading: Slow
Geographical info: N/A
Removal: Easy
Platform: W32
Discovered: 18 Dec 2006
Damage: Low
Characteristics: The malware W32.Bakain is a network worm that spreads by copying itself to weakly protected network shares.
W32.Bakain Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Bakain from your computer.
More details about W32.Bakain
Also known as W32/Bakain, the W32.Bakain program infects the Windows systems and spreads by copying itself to computer network shares with weak security protection. It functions by locating remote machines and copying itself to folders that are open to the read and write function. It will scan all accessible network resources by utilizing local OS services and/or the Internet for susceptible systems. Once the worm detects a vulnerable system, it will connect to the system and gain complete access. When the W32.Bakain worm is executed in the computer system, it creates a host of files. These files include the desktop.ini and folder.htt in the folder C:\ Windows\ Web, service5.exe and iexplorer.exe in the C:\ Windows folder, and pcguard.exe in the folder C:\ Windows\ PCHEALTH.It also add the file welcome.exe in the folder C:\ Windows\ User Profile\ All Users\ StartMenu\ Programs\ Startup, script.exe in the folder C:\ Windows\ System\, desktop.ini, about linda.exe and sysfix.htt in the folder Network Share and sysfix.htt and desktop.ini in the folder User Profile. The W32.Bakain program also connects to the website http://notebook.GustoNetwork.com/inde[Removed]. It also alters several registry entries to allow its automatic execution whenever the Windows starts. Experts suggest that this worm should be removed immediately through manual removal process to ensure complete and thorough eradication.
Browse for more malware information
- W32.Bakain
- W32.Baki.A
- W32.Banish.A@mm
- W32.Banleed.A
- W32.Banwarum.G@mm
- W32.Banwor
- W32.Barten@mm
- W32.Basbot
- W32.Beagle!gen
- W32.Beagle.A@mm
- W32.Benjamin.Worm
- W32.Besam
- W32.Bezilom.Worm
- W32.Bibrog.B@mm
- W32.Binghe
- W32.Bitter
- W32.Bizex.Worm
- W32.Blackmal.B@mm
- W32.Blastclan
- W32.Blatic.A
- W32.Blebla.Worm
- W32.Bluven
- W32.Bobax!gen
- W32.Bolgi.Worm
- W32.Borm
- W32.Botou
- W32.Bratsters
- W32.Bropia
- W32.Browaf
- W32.Buffy.D