|
Subscribe
to Virus Alert |
Win32/Badtrans.B Worm
Badtrans.B is a mass mailing email worm.
This a variant of Badtrans.A
worm. This worm will infect Windows systems. Badtrans.B spreads through
MS-Outlook or Outlook Express. The email generated by the worm could have the subject as a response to an earlier mail sent from the system, with the Re: prefix. Sometimes, it is also know to have just Re: in the subject. The infected mail carries an attachment, which is in a compressed format with any one of the following names: Sorry_about_yesterday.DOC.pif When the infected attachment is executed, it checks if the process KERNEL32.EXE, is running. If the Worm finds this process running, it terminates the process and copies itself to the WINDOWS\SYSTEM directory as KERNEL32.EXE. It then goes on to collect RAS information of the system and stores it as a file, CP_25389.NLS, in an encrypted format. It copies a trojan file called KDLL.DLL, which collects passwords and details of the programs running. A registry key is created; HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\kernel32 Email addresses from .HTM, .HTML and .ASP files are collected as well and Badtrans emails itself to those addresses.
The worm is also known as W32.Badtrans.B, IWorm_Badtrans, TROJ_BADTRANS.B.
You can also use the CleanBT.EXE program that is made specially to detect and remove the Win32/Badtrans.B worm. |
Proland Software is the developer of Protector Plus range of antivirus software packages. Protector Plus is available for Windows Vista, Windows 95/98/Me, Windows XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS and NetWare servers.
![]() |
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware. Protector Plus antivirus software can detect and remove Win32/Badtrans.B worm
reliably.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.
|
You can download the 30 day evaluation
copy of the
antivirus software free of cost for these platforms:
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Copyright ©
2007 Proland Sofrware. All rights reserved.