Softpedia
 

WINDOWS CATEGORIES:



GLOBAL PAGES >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>

WEEK'S BEST

  • DAEMON Tools Pro (...
  • FlashFXP [ DISCOUN...
  • PowerISO 4.9
  • WebcamMax [DISCOUN...
  • Zemana AntiLogger ...
  • System Mechanic Pr...
  • Glary Utilities Pr...
  • All My Movies [DIS...
  • Ad-Aware Internet ...
  • Atlantis Word Proc...
  • Home > Windows > Antivirus > Removal Tools
     Report malware

    Win32.Badtrans.B@mm Detection & Clean 1.0.0.1

    download button

    Downloads: 346  Tell us about an update
    User Rating:
    Rated by:
    NOT RATED
    0 user(s)
    Developer:

    License / Price:

    Size / OS:

    Last Updated:

    Category:

    Freeware / $0
    240 KB / Windows All

    C: \ Antivirus \ Removal Tools

     Read user reviews (0)  Send to friend   Follow (0 users)

    Win32.Badtrans.B@mm Detection & Clean description

    A removal tool for the Badtrans virus

    Win32.Badtrans.B@mm Detection & Clean is a small utility that can help you get rid of the malware infection.

    The virus comes in the following format:

    From: e-mail address of the infected sender or one of the following e-mail addresses:

    "Anna" aizzo@home.com
    "JUDY" JUJUB271@AOL.COM
    "Rita Tulliani" powerpuff@videotron.ca
    "Tina" tina0828@yahoo.com
    "Kelly Andersen" Gravity49@aol.com
    " Andy" andy@hweb-media.com
    "Linda" lgonzal@hotmail.com
    "Mon S" spiderroll@hotmail.com
    "Joanna" joanna@mail.utexas.edu
    "JESSICA BENAVIDES" jessica@aol.com
    "Administrator" administrator@border.net
    "Admin" admin@gte.net
    "Support" support@cyberramp.net
    "Monika Prado" monika@telia.com
    "Mary L. Adams" mary@c-com.net

    Subject: Empty or having the following content:

    RE:
    RE: [original subject]

    Body: Empty

    Attachment: The name of the attachement is formed using one of the following words:

    fun
    Humor
    docs
    info
    Sorry_about_yesterday
    Me_nude Card
    SETUP
    stuff
    YOU_are_FAT!
    HAMSTER
    news_doc
    New_Napster_Site
    README
    images
    Pics

    The extension of the attachment could be a combination of .MP3., .DOC., .ZIP., with .scr., .pif. or just .scr or .pif.

    The worm is using the IFRAME vulnerability and it will be executed on computers with Outlook Express just by preview. Computers with security patch will be infected only by executing the attachment.

    After execution the worm copies itself in Windows %System% directory under the kernel32.exe name, and it will drop the kdll.dll at the same location.

    To ensure that it will be executed at restart it adds the following registry key:

    [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\Kernel32]

    with value kernel32.exe.

    Then it will delete itself from the location where it was executed, and it will gather computer information (like User name, computer name, RAS information, passwords, so on) and sends it to the following e-mail address: uckyjw@hotmail.com

    The Worm has two methods of getting e-mail addresses:
    It search them in *ht* and *.asp files in Internet Cache directory or it gets them with MAPI functions from e-mails received by the infected user.

    It will not send itself twice to the same address because it keeps the already used e-mail addresses in %SYSTEM%\PROTOCOL.DLL.

     Softpedia guarantees that Win32.Badtrans.B@mm Detection & Clean 1.0.0.1 is 100% CLEAN, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    Badtrans.B@mm cleaner | Badtrans remover | Badtrans worm | Badtrans.B@mm | Badtrans | worm



    HTML code for linking to this page:


    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM