W32.Baki.A

W32.Baki.A is a worm that can lower security settings on the infected system by ending security-related process. It can spread by  copying itself to local and removable drives. W32.Baki.A will also add on entry on Windows registry to run itself when the system is booted.

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Windows Vista

Additional Information:

Analysis
W32.Baki.A will disable registry editor by closing any windows containing the classname RegEdit_RegEdit.

It runs a text messages on Windows start up from this registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon\”LegalNoticeText” = “KIBAKI FOR PRESIDENT VOTE KIBAKI FOR A BETTER FUTURE. We need a person who have thought of tomorrow and willing to salvage our country .Kibaki have done so in the past five years. KIBAKI TOSHA TENA ”

To run the worm when the infected drive is accessed, it will create this file.
%DriveLetter%\AUTORUN.INF

How to Remove W32.Baki.A

Scan with Norton Power Eraser

Norton Power Eraser is a virus removal tool created by Norton Antivirus to remove unfamiliar threats without using the traditional AV signatures. Download the tool and start scanning with Norton Power Eraser .