Email this page Print this page Give us your feedback
Panda Security » Enterprises » Security Information » Encyclopedia: virus, worms, adware ...

Encyclopedia

Badtrans

 
Threat LevelModerate threatDamageHighDistributionNot widespread
Common name:Badtrans
Technical name:W32/Badtrans
Threat level:Low
Alias:Badtrans.A, I-Worm.BadTrans, Badtrans@MM, W32/Badtrans@MM
Type:Worm
Effects:  

It sends itself from an affected computer to all the senders of the e-mail messages marked as unread. It displays a false error message on screen when the infected file is run.

Affected platforms:

Windows XP/2000/NT/ME/98/95

Detection updated on:Nov. 13, 2002
StatisticsNo
Yes, using TruPrevent Technologies
Repair utility: Panda QuickRemover
Family:Badtrans

Brief Description 

    

Badtrans is a worm that reaches computers in a file with a PIF or SCR extension attached to an e-mail message, which appears to be a reply to a previously sent e-mail message. When the recipient opens the message and runs the attached file, the computer will be affected.

The danger of Badtrans lies in the following:

  • It activates whenever the computer is started up.
  • It has a high capacity to spread by camouflaging itself.

When Badtrans affects a computer, it replies to all the e-mail messages marked as unread. By doing this, it tricks the recipients into believing that they have received a reply to a message that they have sent.

The file that carries Badtrans avoids arousing suspicion by displaying a message that tricks the user into thinking that it is corrupt:

File data corrupt: probably due to bad data transmission or bad disk access.

Visible Symptoms 

    

A clear indication that you have received Badtrans is a reply to a previously sent message that includes an attachment with a PIF or SCR extension.

When the infected file is run, Badtrans displays an error message that informs the user that the file is corrupt. It displays this message in order to go unnoticed, as the file is not corrupt and carries out its infection.

Last updated:  13/11/2002 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ News]


© Panda Security 2009 | Privacy policy | Legal notice
Web Map | Contact Panda Security | Panda Security for Business