How to Remove Trojan-Downloader.Win32.Bagle
The Trojan-Downloader.Win32.Bagle virus, which is also called the Lodear Trojan, installs itself to your machine when you open up an infected email attachment or navigate your browser to an infected website. The virus then installs other Trojans onto your computer, which disable your security options and attempt to steal your personal information. The Trojan can be removed by preventing its files from opening and then both running an antivirus program and manually deleting the registry entry created by the virus.
- Difficulty:
- Moderate
Instructions
-
-
1
Navigate your computer's web browser to a web page that offers an antivirus tool such as "AVG Anti-Virus" (see Resources). Download and install the antivirus program.
- 2
-
3
Scroll down through the list of processes currently running on your machine. Find the entry labeled as "hidr.exe." Highlight the entry by clicking on it and then click on the "End Process" button. Close down the Task Manager.
-
4
Open the Start menu and click on the Search box. Type in the phrase "hidr.exe" and hit Enter. Right click on the file when it appears in the search results and select the "Delete" option. Search for the file "srosa.sys" and delete it.
- 5
-
6
Choose the option to scan your computer's whole hard drive. Click on the "Start" button and then wait for the scan to finish. Click on "Remove Problems" once the scan has finished running.
- 7
-
8
Open up the folder in the registry editor named "HKEY_LOCAL_MACHINE." Expand the submenus underneath titled "Software," "Microsoft," "Windows" and CurrentVersion," then "Run."
-
9
Check through the list of registry entries on the right side of the window in the "Run" menu. Find the entry labeled as "auto__hloader__key = %System%\hloader_exe.exe." Right click on the entry, then delete it. Restart your computer to finish removing the Win32.Bagle Trojan from your machine.
-
1
Tips & Warnings
You can alphabetically arrange the entries in the Task Manager window for easier navigation by clicking on the "Image Name" button.
Don't delete or modify any other entries n the registry editing program. Your computer uses the registry entries to load its operating system, so if you delete the wrong file, your entire computer can stop working.
Related Searches
References
Resources
- Photo Credit Stock Xchng