
BadTrans Worm
Information
about BadTrans Worm:
BadTrans
is an encrypted worm spreads via MAPI
function of Microsoft Outlook and it also
drops Trojan.PSW.Hooker.b in the victims
PC. The virus author can steal username
and password details using the password
stealer.
I-worm/BadTrans
arrives as an e-mail attachment, when the
infected e-mail attachment is executed,
it will display the following message box
and copies itself to the file INETD.EXE
in the windows folder.

The worm also
decrypts and drops KERN32.EXE and
HKSDLL.DLL in the Windows system folder.
It adds "RUN=INETD.EXE" entry
in WIN.INI file to load on the next
startup. The password stealer is
activated on next startup by adding the
following key in the registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RunOnce\kernel32=kern32.exe
On the next
startup, it attempts to mail all unread
messages in the Microsoft Outlook
folders. The worm attachment name will be
one of the following.
fun.pif
Card.pif
YOU_are_FAT!.TXT.pif
images.pif
Humor.TXT.pif
hamster.ZIP.scr
New_Napster_Site.DOC.scr
news_doc.scr
Me_nude.AVI.pif
Pics.ZIP.scr
README.TXT.pif
SETUP.pif
searchURL.scr
docs.scr
s3msong.MP3.pif
Sorry_about_yesterday.DOC.pif
Remvoing
BadTrans Worm from your system:
Fire has
incorporated I-Worm/BadTrans in its
signature file, with the aim of helping
users affected by this Worm attack to
detect and eliminate it from their
systems. Fire anti-virus users can update
this signature file by using online
update facility. It is available
with the registered version of Fire
anti-virus Kit.
You
can check the system manually.
I-Worm/BadTrans worm creates the file
"INETD.EXE"
in the Windows folder and
"KERN32.EXE",
"HKSDLL.DLL" in the Windows
system folder. The presence of these
files ensures you are infected with this
worm.
A
free download
of FireLite
[ 1100KB]
version is also available to detect
I-Worm/BadTrans. Fire anti-virus
kit removes I-Worm/BadTrans without
problems. If you find this worm,
use registered version of Fire to remove.
To get the registered version of Fire
call us at 044-28170440 or mail
to service@fireav.com
or
purchase Fire online using
[Analysis:
Mr.Ramesh, Mr. Surend Raj, Prognet
Technologies Pvt. Ltd, April. 2001]

|