By通过 Kristopher克里斯托 Kristopher Bio: I began writing about spyware in college, working for a software company. 克里斯托 自述:我就在大学间谍写,在一个软件公司工作。 After school I kept writing, and created a fashion blog that's been featured in VOGUE .fr. 放学后我不断地写作,并建立了一个博客时尚的功能风行一时。神父。 Between blogging about It bags, I noticed there wasn't a simple enough PC security site. 之间的博客中讨论它袋,我注意到没有一个很简单的PC的安全性网站。 I started 411 with the belief that getting rid of spyware should be easy-- unlike figuring out fashion. 我开始了这样的信仰得到的间谍软件清除应该可以很容易计算出不同方式- 411。

How to Remove Win32/Bagle.HE worm如何删除Win32/Bagle.HE蠕虫

Updated Jul 3, 2008更新2008年7月3日

Win32/Bagle.HE worm Threat Level: Win32/Bagle.HE蠕虫威胁级别: Win32/Bagle.HE蠕虫病毒是害虫

Win32/Bagle.HE worm screenshot Win32/Bagle.HE worm is a “threat” that appears in security scans by Win32/Bagle.HE蠕虫是一种“威胁”,在出现的安全扫描 fake antispyware假反间谍软件 WinDefender 2008. WinDefender 2008。

The danger of Win32/Bagle.HE worm is supposed to scare you into wasting $49.95 on WinDefender 2008.在Win32/Bagle.HE蠕虫的危险不应该吓唬浪费WinDefender 2008年你为49.95美元。

Unless you like getting ripped off, don't download the software the Win32/Bagle.HE worm popup links to.除非你喜欢把自己扯掉,不要下载软件的Win32/Bagle.HE蠕虫弹出链接。 You're not really infected with Win32/Bagle.HE worm — you're infected with scamware that you need to remove.你不是真的感染了Win32/Bagle.HE蠕虫-您与scamware您需要删除感染。

I'll show you how to get rid of Win32/Bagle.HE worm and WinDefender 2008, for free.我会告诉你如何摆脱Win32/Bagle.HE蠕虫和WinDefender 2008免费。

Do You Have Win32/Bagle.HE worm?你有Win32/Bagle.HE蠕虫?

When you're infected with badware — whether it's Win32/Bagle.HE worm, spyware, adware, a Trojan, or a virus — there are a few key symptoms.当你感染了恶意软件-无论是Win32/Bagle.HE蠕虫,间谍软件,广告软件,木马,或病毒-有几个关键的症状。 Have you noticed…你有没有注意到...

  • Slow computer performance : It just takes one parasite like Win32/Bagle.HE worm to slow your computer dramatically. 降低计算机性能 :它只是需要一个像Win32/Bagle.HE蠕虫寄生虫降低您的计算机显着。 If your PC takes longer than usual to reboot, or if your Internet connection is unusually slow, you may be infected with Win32/Bagle.HE worm.如果您的电脑需要比通常要重新启动,或者如果您的Internet连接不再是异常缓慢,你可能感染了Win32/Bagle.HE蠕虫。
  • New desktop shortcuts or switched homepage : Badware like Win32/Bagle.HE worm may change your Internet settings to redirect your homepage to another site. 新的桌面快捷方式或交换网页 :像Win32/Bagle.HE蠕虫恶意软件可能会更改您的Internet设置您的网页重定向到另一个站点。 Badware can even add desktop shortcuts to your PC.恶意软件甚至可以添加桌面快捷方式到电脑中。
  • Annoying popups : Badware can bombard your computer with popup ads, even when you're not online.恼人的弹出式窗口 ,恶意软件可以轰击你的弹出广告的计算机,即使你不在线。 Through these popups, you may be tricked into downloading more spyware.通过这些弹出式窗口,您可能会欺骗用户下载更多的间谍软件。

How to Remove Win32/Bagle.HE worm Manually如何删除Win32/Bagle.HE蠕虫手动

Win32/Bagle.HE蠕虫病毒警告 Before we get started, you should backup your system and your registry, so it'll be easy to restore your computer if anything goes wrong.在我们开始之前,您应该备份您的系统和注册表,所以它很容易将计算机还原如果有什么差错。

To remove Win32/Bagle.HE worm manually, you need to delete Win32/Bagle.HE worm files.要删除Win32/Bagle.HE蠕虫手动,您需要删除Win32/Bagle.HE蠕虫文件。 Not sure不知道 how to delete Win32/Bagle.HE worm files如何删除Win32/Bagle.HE蠕虫文件 ? Click here点击这里 , and I'll show you. ,我带你去。 Otherwise, go ahead and…否则,请继续...

Block Win32/Bagle.HE worm sites: 座Win32/Bagle.HE蠕虫网站:

http://win-defender.com/ http://win-defender.com/

Stop Win32/Bagle.HE worm processes: 停止Win32/Bagle.HE蠕虫程序:

WDefDemo.exe WDefDemo.exe

Delete Win32/Bagle.HE worm registry keys: Win32/Bagle.HE蠕虫删除注册表项:

HKEY_LOCAL_MACHINE\SOFTWARE\WinDefender2008 HKEY_LOCAL_MACHINE \软件\ WinDefender2008
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinDefender2008 HKEY_LOCAL_MACHINE \软件\微软\窗口\ CurrentVersion \卸载\ WinDefender2008
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “WinDefender2008″ HKEY_LOCAL_MACHINE \软件\微软\窗口\ CurrentVersion \运行€œWinDefender2008″

Note: In any Win32/Bagle.HE worm files I mention above, “%UserProfile%” is a variable referring to your current user's profile folder. 注:在任何Win32/Bagle.HE蠕虫文件我上面提到,“为%USERPROFILE%”是一个变量指当前用户的配置文件夹。 If you're using Windows NT/2000/XP, by default this is “C:\Documents and Settings\[CURRENT USER]” (eg, “C:\Documents and Settings\JoeSmith”). 如果您使用默认情况下Windows NT/2000/XP下,这是“C:\ Documents和Settings \ [当前用户]”(如类,“C:\ Documents和Settings \ JOESMITH”的)。 If you have any questions about manual Win32/Bagle.HE worm removal, go ahead and leave a comment. 如果您对手工Win32/Bagle.HE蠕虫删除,前进和发表评论的任何问题。

How Do You Remove Win32/Bagle.HE worm Files?你如何删除Win32/Bagle.HE蠕虫文件?

Need help figuring out how to delete Win32/Bagle.HE worm files?需要帮助搞清楚如何删除Win32/Bagle.HE蠕虫文件? While there's some risk involved, and you should only manually remove Win32/Bagle.HE worm files if you're comfortable editing your system, you'll find it's fairly easy to delete Win32/Bagle.HE worm files in Windows.虽然有一些涉及的危险,你应该只手动删除Win32/Bagle.HE蠕虫文件,如果你舒适的编辑系统,你会发现它很容易在Windows Win32/Bagle.HE删除蠕虫文件。

How to delete Win32/Bagle.HE worm files in Windows XP and Vista: 如何删除Windows XP和Vista Win32/Bagle.HE蠕虫文件:

  1. Click your Windows Start menu, and then click “ Search .”单击您的Windows 开始菜单,然后单击“ 搜索 ”。
  2. A speech bubble will pop up asking you, “ What do you want to search for? ” Click “ All files and folders .”阿讲话泡沫会弹出问你,“ 你要查找 ?”点击“ 所有文件和文件夹 。”
  3. Type a Win32/Bagle.HE worm file in the search box, and select “ Local Hard Drives .”请在搜寻框中Win32/Bagle.HE病毒文件,并选择“ 本地硬盘驱动器 。”
  4. Click “ Search .” Once the file is found, delete it.点击“ 搜索。”一旦找到该文件,删除它。

How to stop Win32/Bagle.HE worm processes: 如何有效地防止Win32/Bagle.HE蠕虫程序:

  1. Click the Start menu, select Run .单击开始菜单,选择运行
  2. Type taskmgr.exe into the the Run command box, and click “ OK .” You can also launch the Task Manager by pressing keys CTRL + Shift + ESC . 键入 taskmgr.exe到运行命令框,并点击“ 确定 。”你也可以通过按下发射 CTRL任务管理器+ SHIFT键 + ESC键
  3. Click Processes tab, and find Win32/Bagle.HE worm processes.单击进程选项卡,找到Win32/Bagle.HE蠕虫进程。
  4. Once you've found the Win32/Bagle.HE worm processes, right-click them and select “ End Process ” to kill Win32/Bagle.HE worm.一旦你找到了Win32/Bagle.HE蠕虫程序,右击并选择“结束进程 ”杀死Win32/Bagle.HE蠕虫。

How to remove Win32/Bagle.HE worm registry keys: 如何删除Win32/Bagle.HE病毒注册表项:

Win32/Bagle.HE蠕虫病毒警告 Because your registry is such a key piece of your Windows system, you should always backup your registry before you edit it.因为您的注册表,这样的您的Windows系统的关键部分,你应该始终备份您的注册表,然后再对其进行编辑。 Editing your registry can be intimidating if you're not a computer expert, and when you change or a delete a critical registry key or value, there's a chance you may need to reinstall your entire system. Make sure your backup your registry before editing it.修改您的注册表可能会感到很害怕,如果你不是一个电脑专家,当您更改或删除关键的注册表项或值,有一个机会,你可能需要重新安装整个系统。 确保您的备份您编辑注册表之前它。

  1. Select your Windows menu “ Start ,” and click “ Run .” An “ Open ” field will appear.选择您的Windows菜单“ 开始 ”,单击“ 运行 ”。“ 开放 ”的领域将出现。 Type “ regedit ” and click “ OK ” to open up your Registry Editor.键入“regedit”并单击“ 确定 ”打开注册表编辑器。
  2. Registry Editor will open as a window with two panes. 注册表编辑器将打开一个与两个窗格的窗口。 The left side Registry Editor's window lets you select various registry keys, and the right side displays the registry values of the registry key you select.在注册表编辑器左侧的窗口,可以选择不同的注册表项,并在右侧显示的注册表项您选择的注册表值。
  3. To find a registry key, such as any Win32/Bagle.HE worm registry keys, select “ Edit ,” then select “ Find ,” and in the search bar type any of Win32/Bagle.HE worm's registry keys.为了找到一个注册表项,如任何Win32/Bagle.HE蠕虫病毒的注册表项,选择“ 编辑 ”,然后选择“ 查找 ”,并在搜索栏中键入任何Win32/Bagle.HE蠕虫病毒的注册表项。
  4. As soon as Win32/Bagle.HE worm registry key appears, you can delete the Win32/Bagle.HE worm registry key by right-clicking it and selecting “ Modify ,” then clicking “ Delete .”只要Win32/Bagle.HE蠕虫病毒注册表项中,您可以删除右键单击它并选择“ 修改 ”,然后点击“ 删除 Win32/Bagle.HE蠕虫病毒注册表项。”

How to delete Win32/Bagle.HE worm DLL files: 如何删除Win32/Bagle.HE蠕虫DLL文件:

  1. First locate Win32/Bagle.HE worm DLL files you want to delete.首先找到Win32/Bagle.HE蠕虫DLL文件要删除。 Open your Windows Start menu, then click “ Run .” Type “ cmd ” in Run, and click “ OK .”打开你的Windows 开始菜单,然后单击“ 运行 ”。键入“cmd中运行”,然后单击“ 确定 ”。
  2. To change your current directory, type “ cd ” in the command box, press your “ Space ” key, and enter the full directory where the Win32/Bagle.HE worm DLL file is located.要更改当前目录,键入“cd在命令框”,按你的“ 空间 ”键,并输入完整的目录的Win32/Bagle.HE蠕虫病毒的DLL文件的位置。 If you're not sure if the Win32/Bagle.HE worm DLL file is located in a particular directory, enter “ dir ” in the command box to display a directory's contents.如果你不知道Win32/Bagle.HE蠕虫DLL文件是在一个特定的目录中,输入“ 迪尔在命令框”,以显示一个目录的内容。 To go one directory back, enter “ cd .. ” in the command box and press “ Enter .”去一回的目录,输入“的命令框,然后按光盘..”“输入 ”。
  3. When you've located the Win32/Bagle.HE worm DLL file you want to remove, type “ regsvr32 /u SampleDLLName.dll ” (eg, “regsvr32 /u jl27script.dll”) and press your “ Enter ” key.当您找到Win32/Bagle.HE蠕虫DLL文件要删除,键入“regsvr32 / U系列SampleDLLName.dll”(例如,“键入regsvr32 / ü jl27script.dll”),然后按你的“Enter”键。

That's it.就是这样。 If you want to restore any Win32/Bagle.HE worm DLL file you removed, type “regsvr32 DLLJustDeleted.dll” (eg, “regsvr32 jl27script.dll”) into your command box, and press your “Enter” key.如果你想恢复任何Win32/Bagle.HE蠕虫您删除DLL文件,键入“regsvr32 DLLJustDeleted.dll”(例如,“Regsvr32的jl27script.dll”)到您的命令框,然后按你的“Enter”键。

Did Win32/Bagle.HE worm change your homepage? 没有Win32/Bagle.HE蠕虫更改您的主页?

  1. Click Windows Start menu > Control Panel > Internet Options .单击Windows 开始菜单 >“ 控制面板 ”> Internet选项
  2. Under Home Page , select the General > Use Default .根据主页选择常规>“使用默认
  3. Type in the URL you want as your home page (eg, “http://www.homepage.com”).在您的网址作为您的主页想类型(例如,“http://www.homepage.com”)。
  4. Select Apply > OK .选择应用“行
  5. You'll want to open a fresh web page and make sure that your new default home page pops up.您想打开一个新网页,并确保您的新的默认主页弹出。

Win32/Bagle.HE worm Removal Tip Win32/Bagle.HE蠕虫删除提示

Is your computer acting funny after deleting any Win32/Bagle.HE worm files?是您的计算机有异常后,删除任何Win32/Bagle.HE蠕虫文件? I recommend using a program like我建议使用一个程序一样 File Recover文件恢复 from PC Tools.从PC工具。 File Recover saves deleted files that otherwise can't be recovered by Windows operating sytem.恢复已删除的文件保存,否则不能被Windows操作系统sytem恢复的文件。

Want to save time finding Win32/Bagle.HE worm files?想节省时间找到Win32/Bagle.HE蠕虫文件? Download Spyware Doctor下载Spyware Doctor , let it find the Win32/Bagle.HE worm files for you, and then manually delete Win32/Bagle.HE worm files. ,让它找到适合您Win32/Bagle.HE蠕虫文件,然后手动删除Win32/Bagle.HE蠕虫文件。

How Did You Get Win32/Bagle.HE worm?你是怎么得到Win32/Bagle.HE蠕虫?

Wondering how Win32/Bagle.HE worm ended up on your PC?想知道如何Win32/Bagle.HE结束蠕虫在您的PC呢? If you're infected with Win32/Bagle.HE worm or other badware, perhaps you were using…如果你感染了Win32/Bagle.HE蠕虫或其他有害软件,也许你正在使用...

  • Freeware or shareware : Did you download and install shareware or freeware? 免费软件或共享 :你下载并安装共享软件或免费软件? These low-cost or free software applications may come bundled with spyware, adware, or programs like Win32/Bagle.HE worm.这些低成本或免费软件应用程序可能捆绑有间谍软件,广告,或者像Win32/Bagle.HE蠕虫程序。 Sometimes adware is attached to the free software to “pay” developers for the cost of creating the software, and more often spyware is secretly attached to free software to harm your computer and steal your personal and financial information.有时,广告软件连接到免费软件,“支付”为制造成本的软件开发人员,而且往往是秘密间谍软件附加到免费软件,以损害您的计算机,窃取你的个人和财务信息。
  • Peer-to-peer software : Do you use a peer-to-peer (P2P) program or other application with a shared network? 对等网络软件 :您使用的是点对点(P2P)的程序或共享的网络其它应用程序? When you use these applications, you put your system at risk for unknowingly downloading an infected file, including applications like Win32/Bagle.HE worm.当您使用这些应用程序,你将在不知不觉被感染的文件下载,包括像Win32/Bagle.HE蠕虫应用系统的风险。
  • Questionable websites : Did you visit a website that's of questionable nature?可疑的网站你访问一个网站,有问题的性质的? When you visit malicious sites that are fishy and phishy, badware may be automatically downloaded and installed onto your computer, sometimes including applications like Win32/Bagle.HE worm.当您访问是腥味和phishy恶意网站,恶意软件可能会自动下载并安装到您的计算机,有时还包括像Win32/Bagle.HE蠕虫应用程序安装。 I recommend you use Firefox web browser, if you don't already.我建议你使用Firefox网页浏览器,如果你不已经。

Understanding Win32/Bagle.HE worm理解Win32/Bagle.HE蠕虫

If you're infected with Win32/Bagle.HE worm, you should know what you're fighting.如果您对Win32/Bagle.HE蠕虫感染,你应该知道你在战斗。 I'll explain some definitions related to Win32/Bagle.HE worm.我会解释有关Win32/Bagle.HE蠕虫的定义。

Win32/Bagle.HE worm May Be Rogue Anti-Spyware Win32/Bagle.HE蠕虫病毒可能会被流氓反间谍软件

Rogue anti-spyware refers to anti-spyware/antivirus software of questionable value.流氓反间谍软件是指其价值十分可疑anti-spyware/antivirus软件。 Rogue anti-spyware may not be proven to protect your computer from spyware, may popup fake alerts or create many false positives about your PC being infected, or may use scare tactics to try to get you to purchase the application.流氓反间谍软件可能无法验证,以保护您的计算机免受间谍软件,可能会弹出假警报或创建你的个人电脑的误报率受到感染,或者可能使用威吓手段,试图让你购买的应用程序。 Rogue anti-spyware software may be installed by a Trojan, come bundled with other software, or install itself through web browser security holes.流氓反间谍软件可能会安装一个木马,来与其他软件,或安装通过网络浏览器的安全漏洞本身捆绑。 While it is fairly rare, some rogue anti-spyware is created and distributed by known spyware or adware companies, and the rogue anti-spyware may install spyware or adware itself.虽然这是相当罕见,一些流氓反间谍软件是创建和已知的间谍软件或广告公司所分配,以及流氓反间谍软件可能会安装间谍软件或广告软件本身。

Often when you're infected with rogue anti-spyware like Win32/Bagle.HE worm, you'll see a false popup security alert like this:很多时候,当你感染了,流氓反间谍软件等Win32/Bagle.HE蠕虫,您会看到这样一幅虚假的弹出安全警报:

Win32/Bagle.HE worm  popup

Rogue Anti-Spyware Tactics 流氓反间谍软件策略

Typically, rogue anti-spyware such as Win32/Bagle.HE worm has one or more of the qualities listed below, which is why rogue anti-spyware is considered anti-spyware software of questionable value.通常情况下,流氓反间谍软件,如Win32/Bagle.HE蠕虫有一个或下面列出的素质,这就是为什么流氓反间谍软件被认为是反间谍软件的问题更多的价值。

  • False positives/fake alerts : Rogue anti-spyware may produce a large number of false positives or use fake alerts, noting that your computer is infected with spyware parasites or other threats that do not really exist. 假阳性/假警报 :流氓反间谍软件可能会产生假阳性或大量使用假警报,并指出您的计算机间谍软件寄生虫或其他威胁的实际上是不存在感染。
  • Copycat looks : Rogue anti-spyware may copy the look and feel of other legitimate or rogue anti-spyware applications. 模仿的样子 :流氓反间谍软件可以复制的外观和感觉的其他合法或流氓反间谍软件应用程序。 Often, rogue anti-spyware applications may appear as close clones of other rogue anti-spyware software.通常情况下,流氓反间谍软件应用程序可能会显示为其他流氓反间谍软件与克隆。
  • High pressure marketing : Rogue anti-spyware may use scare tactics or other aggressive advertising and marketing tactics to try to trick you into buying the rogue anti-spyware application. 高压营销 :流氓反间谍软件可能会使用威吓手段或其他攻击性的广告和营销策略,试图诱使人们购买流氓反间谍软件应用程序。 Often, rogue anti-spyware may produce false positives and fake alerts about your computer being infected.通常情况下,流氓反间谍软件可能会产生假阳性和假警报,感染您的计算机。
  • Poor detection/scan reporting : Rogue anti-spyware may produce poor reports when it scans your PC. 可怜的检测/扫描报告 :流氓反间谍软件可能会产生时扫描PC穷人的报告。 For example, rogue anti-spyware may say your computer is infected 11 parasites, but not specify which spyware parasites or what type of parasites.例如,流氓反间谍软件可能会说您的计算机感染11寄生虫,但没有说明是什么间谍寄生虫或寄生虫的类型。 Rogue anti-spyware may also report that your PC is infected with SafeAndClean, but not tell you which related files, DLLS, etc. were found on your computer.流氓反间谍软件也可以报告您的电脑与SafeAndClean感染,但没有告诉你哪些相关文件的文件,DLL等,则在您的计算机上找到。
  • Weak scanning/detection : Rogue anti-spyware may not only poorly report on computer infection, but rogue antispyware may also poorly scan your PC. 弱扫描/检测 :流氓反间谍软件不仅可能很差计算机感染报告,但流氓反间谍软件也可能很差扫描你的电脑。 Rogue anti-spyware may skip over important folders and files of your computer that should be scanned to detect spyware.流氓反间谍软件可能会跳过重要的文件夹和您的计算机文件应扫描检测间谍软件。

Did Win32/Bagle.HE worm use these tactics to trick you into buying Win32/Bagle.HE worm?没有Win32/Bagle.HE 6665这些战术,诱骗购买Win32/Bagle.HE蠕虫吗?

Win32/Bagle.HE worm May Be a Trojan Win32/Bagle.HE蠕虫可能是一个木马

Trojans install themselves secretly onto your computer, most often through your downloading a simple email attachment (often Trojans pose as harmless pictures).木马安装自己偷偷到您的计算机,通过您下载一个简单的电子邮件的附件(通常木马成无害的图片构成最常)。 Most Trojans are able to gain complete control over your PC after installation.大多数木马能够得到安装后对PC的完全控制。 With this control, the Trojan and the hacker behind it may change your system settings, delete important files, steal your passwords, and watch your computer acitivity.通过这一控制,该木马以及其背后,有可能改变您的系统设置,删除重要文件,盗取您的密码,看着你的电脑acitivity黑客。

Infection Methods of Win32/Bagle.HE worm and Other Trojans 感染Win32/Bagle.HE蠕虫和其他方法木马

Most Trojans infect your computer by tricking you into launching an infected file.大多数木马通过诱骗感染被感染的文件启动您的计算机。 This poisoned file could disguised as a small file, such as a jpeg or other email attachment, or it might be downloaded via a website or FTP.这中毒文件可以伪装成一个小文件,例如JPEG或其他电子邮件附件,或者它可能是通过一个网站或FTP下载。

  • Email: Your PC may be infected with a Trojan when you download infected email attachments, or sometimes even when you simply open an email. 电子邮件:您的电脑可能感染了木马,当您下载受感染的邮件附件,或有时甚至当您只需打开一封电子邮件。 Many Trojans exploit security holes in Microsoft Outlook.很多木马利用Microsoft Outlook中的安全漏洞。 You may be able to reduce your chances of getting infected by a Trojan by using a spam-blocking software.您可能能够减少你的机会将在某个木马感染,使用垃圾邮件拦截软件。
  • Websites: Your PC may be infected with a Trojan when you visit a rogue site. 网站:您的电脑可能感染了特洛伊木马当您访问一个恶意网站。 Many Trojans exploit security holes in Internet Explorer web browser so that by simply visiting a website you may unknowingly download a Trojan.很多木马利用了IE浏览器的安全漏洞,使只要浏览一个网站您可能在不知情的下载一个特洛伊木马病毒。
  • Open ports: If your computer runs programs that provide file-sharing functions – such as AOL Instant Messenger (AIM), MSN Messenger, and more – you may open your computer up to vulnerabilities. 开放的端口:如果您的计算机运行的程序,提供诸如AOL的即时消息(AIM),MSN Messenger和更多的文件共享功能- -你可以打开你的电脑漏洞的影响。 Using file sharing through these applications may create a network that gives attackers the opportunity to remotely access your computer.通过这些应用程序使用文件共享可能会创建一个网络,使攻击者有机会远程访问您的计算机。