WINDOWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>

WEEKLY HIGHLIGHTS

DVD Cloner45
Spyware Doctor40
1Click DVD Copy40
Apollo DVD Copy40
ABC Amber BlackBer...45
Protected Music Co...40

7-DAY TOP DOWNLOAD

#
Program
Windows Live
Messenger 2009
14.0.8089.726

187,869
Avira AntiVir
Personal - Free
Antivirus 9.0.0.407

183,047
Avira Antivir Virus
Definition File
Update November 6,
2009

173,387
Nexus Radio 4.1.1
122,444
Windows Live
Messenger
8.5.1302.1018

113,099
FreeZ Online TV 1.30
93,662
Microsoft Office
2007

76,384
Y! Multi Messenger
8.x and 9.x

75,572
DVD Shrink 3.2.0.15
53,871
AVG Free Edition 9.0
Build 698a1730

52,233

WEEK'S BEST

  • Internet Explorer ...
  • Online Armor ++ 4....
  • cFosSpeed 5.01 Bui...
  • SONY Vegas Pro 9.0...
  • Firefox 3.6 Beta 1...
  • Nokia Photos 1.6.434
  • Windows Server 200...
  • Skype Portable 4.1...
  • Google Chrome Port...
  • PCMark Vantage Bas...
  • Kaspersky Anti-Vir...
  • Microsoft Virtual ...
  • Messenger Plus! Li...
  • WinX DVD Author [F...
  • SoftPerfect Networ...
  • System Mechanic Pr...
  • Ad Muncher 4.8 Bui...
  • Windows 7 Upgrade ...
  • Pidgin 2.6.3
  • OpenOffice.org 3.2...
  • VirtualDub 1.9.7 B...
  • Maxthon [Softpedia...
  • Spyware Doctor 7.0...
  • SUPERAntiSpyware 4...
  • Adobe Acrobat Prof...
  • Camfrog Video Chat...
  • Adobe Reader 9.2.0...
  • Foxit PDF Reader 3...
  • Microsoft Maliciou...
  • AVG Identity Prote...
  • Home / Windows / Antivirus
     Report spyware

    Resolve for W32/Badtrans 1.04

    Download button

    Downloads: 1,050  Add to download basket  Tell us about an update
    User Rating:
    Rated by:
    Good (3.0/5)
    16 user(s)
    Developer:

    License / Price:

    Size / OS:

    Last Updated:

    Category:
    Sophos Plc | More programs
    Freeware / FREE
    83 KB / Windows All
    August 1st, 2008, 00:42 GMT
    C: \ Antivirus

     Read user reviews (0)  Add a review  Refer to a friend  Subscribe

     

    Resolve for W32/Badtrans description

     

    A tool that removes W32/Badtrans

    Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.

    They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.

    W32/Badtrans-A is a worm which uses MAPI to spread. The worm arrives in an email message with the text "Take a look to the attachment".

    The attachment filename is randomly chosen from the following list:

    fun.pif
    Humor.TXT.pif
    docs.scr
    s3msong.MP3.pif
    Sorry_about_yesterday.DOC.pif
    Me_nude.AVI.pif
    Card.pif
    SETUP.pif
    searchURL.scr
    YOU_are_FAT!.TXT.pif
    hamster.ZIP.scr
    news_doc.scr
    New_Napster_Site.DOC.SCR
    README.TXT.pif
    images.pif
    Pics.ZIP.scr

    If the attached file is run, it displays the message "File data corrupt probably due to bad data transmission or bad disk access.", copies itself into the Windows directory with the filename INETD.EXE and changes win.ini so that the file is run at Windows startup.

    When a new message arrives the worm sends a reply with an infected attachment.

    The worm also drops a file kern32.exe, which is a password-stealing Trojan, Troj/Keylog-C, into the Windows system directory and changes the registry key

    HKLMSOFTWAREMicrosoftWindows
    CurrentVersionRunOnce so that the Trojan runs at Windows startup.

    W32/Badtrans-B is an email-aware worm which uses MAPI to spread. The worm forwards itself to addresses found on the infected computer as an email message with no message text.

    The worm finds addresses to send itself to by searching the address book. Additionally it searches the internet cache and "My Documents" folders for web pages, looking for further email addresses to which to send itself.

    If the worm is replying to mail found on the infected machine, it will use the infected user's address in the From: field of the email, otherwise it will use one of the following addresses in the From: field:

    " Anna"
    "JUDY"
    "Rita Tulliani"
    "Tina"
    "Kelly Andersen"
    " Andy"
    "Linda"
    "Mon S"
    "Joanna"
    "JESSICA BENAVIDES"
    " Administrator"
    " Admin"
    "Support"
    "Monika Prado"
    "Mary L. Adams"

    The email uses a known exploit in certain versions of Outlook Express 5 in order to launch the attached file automatically. Microsoft has released a patch which reportedly addresses this vulnerability. It is available at http://www.microsoft.com/technet/security/bulletin/MS01-027.asp.
    (This patch fixes a number of vulnerabilities in Microsoft's software, including the one exploited by this worm.)

    The worm generates a subject line by reading email on the infected machine and "replying" to it. For instance,

    Re:

    For email addresses found via web pages in the internet cache or the "My Documents" folder, the subject line is simply "Re:" with no further text.

    The worm attempts to create a name for the attached infected file by randomly generating it from three separate parts. The first part is taken from the list:

    CARD
    DOCS
    FUN
    HAMSTER
    NEWS_DOC
    HUMOR
    IMAGES
    info
    ME_NUDE
    New_Napster_Site
    PICS
    README
    S3MSONG
    SEARCHURL
    SETUP
    Sorry_about_yesterday
    stuff
    YOU_ARE_FAT!

    The second from the list:

    .DOC.
    .MP3.
    .ZIP.

    (a bug inside the worm means that it never selects the ".ZIP." option)

    and the last from:

    pif
    scr

    For this reason the attached file can be called a large number of different names, including:

    card.DOC.pif
    docs.DOC.pif
    fun.MP3.pif
    HAMSTER.DOC.PIF
    Humor.MP3.scr
    IMAGES.DOC.pif
    Me_nude.MP3.scr
    New_Napster_Site.MP3.pif
    Pics.DOC.scr
    README.MP3.scr
    S3MSONG.DOC.scr
    SEARCHURL.MP3.pif
    SETUP.DOC.scr
    Sorry_about_yesterday.MP3.pif
    Sorry_about_yesterday.MP3.scr
    stuff.MP3.pif
    YOU_ARE_FAT!.DOC.pif
    YOU_are_FAT!.MP3.scr

    If the attached file is run it may copy itself to the Windows or Windows system directory with the filename kernel32.exe and change the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunOnce so that the worm runs the next time Windows is started. Note that the registry key will refer to the original attachment if the worm has not created a copy in the Windows or Windows system directories.

    The worm also drops a file named kdll.dll, which is the Troj/PWS-AV password-stealing Trojan horse.

    W32/Badtrans-B uses the Trojan Troj/PWS-AV to log a user's keystrokes in a file named cp_25389.nls in the Windows system directory. The log of keystrokes may be encrypted.

    W32/Badtrans-B will attempt to send the log to one of the following email addresses:

    ZVDOHYIK@yahoo.com
    udtzqccc@yahoo.com
    DTCELACB@yahoo.com
    I1MCH2TH@yahoo.com
    WPADJQ12@yahoo.com
    fjshd@rambler.ru
    smr@eurosport.com
    bgnd2@canada.com
    muwripa@fairesuivre.com
    rmxqpey@latemodels.com
    eccles@ballsy.net
    suck_my_prick@ijustgotfired.com
    suck_my_prick4@ukr.net
    thisisno_fucking_good@usa.com
    S_Mentis@mail-x-change.com
    YJPFJTGZ@excite.com
    JGQZCD@excite.com
    XHZJ3@excite.com
    OZUNYLRL@excite.com
    tsnlqd@excite.com
    cxkawog@krovatka.net
    ssdn@myrealbox.com

    W32/Badtrans-A and W32/Badtrans-B can be removed from Windows computers automatically with the following Resolve tools:

    Windows disinfector
    BADTRGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
    · Open BADTRGUI.com file from your desktop after downloading it.
    · Click on the Start Scan Button.
    · Wait for the process to complete.

    Command line disinfector
    BADTRSFX.EXE is a self-extracting archive containing BADTRCLI, a Resolve command line disinfector for use on Windows networks.

    After removing the worm you should install the Microsoft patch MS01-027 or, on single computers, update with all relevant security patches from Windows update.

     Softpedia guarantees that Resolve for W32/Badtrans 1.04 is 100% CLEAN, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    trojan protection | trojan remover | antivirus protection | W32/Badtrans-A | W32/Badtrans-B | trojan



    HTML code for linking to this page:


    Go to top

    Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM