NetPlus Communications     W32.Badtrans.13312@mm VIRUS

Due to an increase in the number of submissions, W32.Badtrans.13312@mm has been upgraded to a Category 4 threat. It is a MAPI worm that replies to all unread messages in your email message folders and drops a backdoor Trojan.

Also Known As: W32/Badtrans-A, W32/Badtrans@MM, BadTrans, IWorm_Badtrans, I-Worm.Badtrans, TROJ_BADTRANS.A

Category: Worm

Infection Length: 13312

Virus Definitions: April 11, 2001

Threat Assessment:

 
High Medium High
Wild:
High
Damage:
Medium
Distribution:
High

Wild:

Damage:

 

Technical description:

When the worm is executed, it drops the backdoor Trojan Hkk32.exe into the \Windows folder and executes it. It then copies itself into the \Windows folder as inetd.exe, adds a run= line to the Win.ini file, and displays the following message:



The next time that the computer is restarted, the worm waits for five minutes and then uses MAPI to find all unread email messages and reply to all of them. The worm attaches itself to the message using one of the following file names:
Pics.ZIP.scr
images.pif
README.TXT.pif
New_Napster_Site.DOC.scr
news_doc.scr
hamster.ZIP.scr
YOU_are_FAT!.TXT.pif
searchURL.scr
SETUP.pif
Card.pif
Me_nude.AVI.pif
Sorry_about_yesterday.DOC.pif
s3msong.MP3.pif
docs.scr
Humor.TXT.pif
fun.pif

 

Removal instructions:

Because W32.Badtrans.13312@mm affects different operating systems in different ways, how you remove this worm depends on your operating system. Follow the instructions in the order given.

To remove the worm:


To remove files that cannot be deleted by NAV:
Follow the instructions for your operating system only if NAV could not delete files that it detected as infected with W32.Badtrans.13312@mm.

To edit the registry:

To edit the Win.ini file:
If you are running Windows 95/98/Me, you must also do the following:

Write-up by:

Symantec AntiVirus Research Center (SARC)
http://www.symantec.com/avcenter