W32.BAGLE virus – wintems.exe hldrrr.exe srosa.sys

I must say that with all my of experience that one was one of the hardest to remove ..
It disables your current antivirus software, prohibit you from accessing system in safe mode , and changes names each time it starts.

So.. Here are the steps

Go to http://www.majorgeeks.com/GMER_d5198.html and download GMER
Run the tool and when it finds wintems.exe process kill him..

  1. Run regedit go to HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache and see all entries regarding “C:WINDOWSsystem32drivers” .
  2. In Explorer window Go to> tools>folder options>view and select show hidden files
  3. Browse to your C:WINDOWSsystem32drivers .. find drivers folder and try to delete all files listed in HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamMUICache
  4. Scan your system with panda online scanner (the only one that actually cleans , not only detects
  5. Install anti virus program, download last updates and do a full scan to your system

Of course there is always an option to reapply service pack or do a reinstall to your system.

The problem is solved !

Thanks to Eran Amir