W32/Badtrans.A@mm

Download VIRUSfighter NOW
W32/Badtrans.A@mm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 11/24/2001 • Type: Worm
• Virus characteristics first published: 11/24/2001 • Spreading mechanism: Email
• Virus characteristics latest update: 12/17/2003 • Overall risk: Low
• Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
Email characteristics:
  • Subject: (reply to unread emails)
  • Body: > Take a look to the attachment.
  • Attachment: (several - see details below)
When the worm is run, it will show the messagebox below:

Messagebox


It will also copy itself to the Windows directory under the name of INETD.EXE, and add an entry to WIN.INI to run this file on startup. When the machine is booted next time, the worm will attempt to use MAPI services to mail itself as a reply to all unread messages in the Outlook folders.

The attachment names will be selected at random between one of the following:

fun.pif
Humor.TXT.pif
docs.scr
s3msong.MP3.pif
Sorry_about_yesterday.DOC.pif
Me_nude.AVI.pif
Card.pif
SETUP.pif
searchURL.scr
YOU_are_FAT!.TXT.pif
hamster.ZIP.scr
news_doc.scr
New_Napster_Site.DOC.scr
README.TXT.pif
images.pif
Pics.ZIP.scr

# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter