Il virus BadTrans O vírus BadTrans der BadTrans Virus Le virus BadTrans El virus BadTrans

Introduction to the BadTrans virus

The BadTrans virus (code name W32.BadTrans.B or W32/Badtrans-B) is a worm which spreads by e-mail. It also uses another method to spread:

  • Microsoft Internet Explorer security flaws

The BadTrans.B virus particularly affects those who use Microsoft Outlook in the operating systems Windows 95, 98, Millennium, NT4, and 2000, as the virus is activated in Outlook simply by viewing the message (as opposed to clicking on the attachment).
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp

What the virus does

The BadTrans virus scans the address list in the infected user's address book, as well as web pages contained in the browser cache and the My Documents folder.

Then the BadTrans virus sends each of the addresses an e-mail:

  • with the body either empty, or containing the sentenceTake a look to the attachment.
  • with the subject Re: <Subject of e-mail found>
  • with the attachment having a three-part name
    • First part: One of the following messages:
      • CARD
      • DOCS
      • FUN
      • HAMSTER NEWS_DOC
      • HUMOR
      • IMAGES
      • ME_NUDE
      • New_Napster_Site
      • News_doc
      • PICS
      • README
      • S3MSONG
      • SEARCHURL
      • SETUP
      • Sorry_about_yesterday
      • YOU_ARE_FAT!
    • Second part: One of the following extensions:
      • .DOC
      • .MP3
      • .ZIP
    • Third and final part: One of the following extensions:
      • .pif
      • .scr
Therefore, the message's attachment may look like:
  • Me_Nude.MP3.scr
  • News_doc.DOC.scr
  • HAMSTER.DOC.pif
  • PICS.doc.scr
  • HUMOR.MP3.scr
  • README.MP3.scr
  • FUN.MP3.pif
  • YOU_are_FAT!.MP3.scr
  • and so on.

Symptoms of infection

Workstations infected by the BadTrans worm will have the following file on their hard drive:

  • kdll.dll. This is a Trojan horse which records all your keystrokes, in order to recover your passwords.

To check if you are infected, do a search for the files named above on all of your hard drives (Start / Search / For Files or Folders...).

Eradicating the virus

The best method for eradicating the BadTrans worm involves first disconnecting the infected machine from the network, then running an up-to-date antivirus software.

What's more, the virus spreads by exploiting a security hole in Microsoft Outlook, which means that you may be contaminated by the virus without clicking on the attachment. To fix the security hole, you must download the patch for Microsoft Outlook. Please check your e-mail client, and download the patch if needed:
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp

More information about the virus



Last update on Thursday October 16, 2008 02:43:16 PM.This document entitled « The Bad Trans virus » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.
Best answers for « The Bad Trans virus » in :
The Nimda virus Show Introduction to the Nimda virus Le Nimda virus (code name W32/Nimda) is a worm which spreads by email. It also has four other ways to spread: The web Shared folders Microsoft IIS security holes File transfer At particular risk are users of...
Scan files transferred in WLM with Avast Show Scan files transferred in WLM with Avast Windows Live Messenger allows you to transfer and receive files easily to your contacts. But how would you determine that the file you are about to download is safe and does not contain a virus? To...
[Virus] System Volume Information Show[Virus] System Volume Information The System Volume Information folder is used by Windows XP for storing data on system configuration and is also used by the System Restore tool to store information and restore points. Restore points...
File transfer via SSH ShowSSH - Secure SHell SSH allows the use of pipelines controls, and use inputs / outputs pipes as any other commands , on the basis that redirection is done to or from the remote machine. This may be used to transfer files: ssh server...
How to remove the virus CONFICKER / DOWNADUP / KIDO? ShowHow to remove the virus CONFICKER / DOWNADUP / KIDO What is the Conficker? How to avoid being infected by Conficker? Disinfect a computer affected by Conficker Preliminary Remove infection What is the Conficker? Conficker (also...
Download Clean Virus MSN ShowViruses meet hereafter a bit on the net by all thinkable means everywhere. After mails , supporting they attack instantaneous freight forwarding. Clean Virus MSN is a tool which discerns automatically the viruses which circulate on MSN Messenger....
Download GX::Transcoder ShowGX :: Transcoder is a universal audio and video converter. It allows to convert files into a large number of formats: AAC, MP4, M4A, Bonk, SPLASH, LPAC, NOON, MP2, MP3, MPC, MPP, MP +, OptiomFrog, Ogg Vorbis, rkAudio, VQF, WavPack, TTA, WMA,...
Download Medieval Bluetooth OBEX File Transfer ShowMedieval Bluetooth OBEX File Transfer is an administrator for file transfer between your PC and your telephone, PDA, Palm or Notebook and through your Bluetooth connection.The management of files is done by drag and drop operations and you can view...
Data transmission - Cabling ShowCabling types Several physical data-transmission media are available to connect together the various devices on a network. One possibility is to use cables. There are many types of cables, but the most common are: Coaxial cable Double twisted...
Data transmission - Transmission modes ShowTransmission modes A given transmission on a communications channel between two machines can occur in several different ways. The transmission is characterised by: the direction of the exchanges the transmission mode: the number of bits sent...
Data transmission techniques on Wi-Fi wireless networks (802.11 ShowTransmission channels A transmission channel is a narrow frequency band that can be used for communication. In every country, the government generally regulates use of the radio spectrum, as it is the largest user of the spectrum due to military...