|
|
||||||||||||||
|
|
|
BadTrans@mm Name: W32/Badtrans.B@mm
Description:
W32/Badtrans.B@mm is a mass-mailing worm that infects Win32 systems. This worm arrives as an email attachment using one of several different filenames as well as two separate extensions; for example, YOU_ARE_FAT!.MP3.scr.
It also drops a keystroke recorder file named KDLL.DLL. CSAV will detect this as "is a security risk or a "backdoor" program". Detection: Command AntiVirus version 4.58.3 or higher with definition files dated 11/26/2001 will detect and delete the virus. Removal Instructions: To get rid of W32/Badtrans.B@mm, follow these steps: CAUTION: During the disinfection process, do not run any applications other than the ones described in the following instructions. For example, do not open any e-mail clients that might spread the virus again.
Command AntiVirus scans your computer for viruses. Let it delete any leftovers from the virus, for example the body of the virus and the KDLL.DLL. Name: W95/Badtrans.A@mm
Description:
W95/Badtrans.A@mm is a mass-mailing internet worm with a remote access trojan component. When executed, the worm makes a copy of itself named "inetd.exe" and puts it into the Windows directory. It also drops the trojan file, named "kern32.exe", and a keylogger DLL, named "hksdll.dll", into the Windows System directory. When this process is complete, an "Install Error" box with the message "File data corrupt: probably due to bad transmission or bad disk access" will be displayed. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
|
||||||||||||||||||||||||||||||||||||||||||||