White Papers White Papers

W32/Badtrans-B (Sophos)

Overview Date: Tue, 27 Nov 2001 13:14:17 (GMT)

Name: W32/Badtrans-B

Type: Win32 worm

At the time of publication of our initial alert (Sat, 24 Nov 2001 16:00:35 (GMT), Sophos had received just one report of this worm from the wild. Within a few days, Sophos has received many reports of this worm from the wild. Sophos has received a significant number of reports of users receiving an email-aware worm called W32/Badtrans-B.

Description: W32/Badtrans-B is a worm which uses MAPI to spread. The worm arrives in an email message with no message text. The attachment filename is randomly generated from three parts. The first part is taken from the list:

FUN
HUMOR
DOCS
S3MSONG
Sorry_about_yesterday
ME_NUDE
CARD
SETUP
SEARCHURL
YOU_ARE_FAT!
HAMSTER NEWS_DOC
New_Napster_Site
README
IMAGES
PICS

The second from the list:

.DOC.
.MP3.
.ZIP.

and the last from:

pif
scr

If the attached file is run, it copies itself into the Windows system directory with the filename KERNEL32.EXE and changes the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce so that the worm runs the next time Windows is started. The worm also drops a file named kdll.dll, which is the password stealing Trojan Troj/PWS-AV.

Further White Paper Details
PublisherSophos File FormatHTML
Date PublishedNovember 2001 Downloads2
FormatWhite Papers   
Topics
    N/A
  • Featured White Papers
Thin clients switch on digitally excluded

Thin clients switch on digitally excluded

Case study: Digital inclusion project tackles social exclusion in Liverpool more

Renault goes multilingual

Renault goes multilingual

Case study: Translation tech turns docs into 23 languages… more


Quick Sitemap Links: