Bad Trans and BadTrans.B Trojan Virus Information and Help
BadTrans Trojan Virus and How Did I Get It?
Upon execution the virus displays the following message box:
How Do I Remove the Virus?
Because the virus modifies Win.ini, you'll want to follow these instructions to remove the line from there first.
Click on Start, Run
Now, run an up-to-date anti-virus program and scan your system for viruses. If you don't have an anti-virus program on your system, trying using Housecall, an online anti-virus program, but definitely purchase anti-virus software and keep it up-to-date.
You will probably find at least two files infected as BadTrans, these are KERN32.EXE and CP_23421.NLS. These should both be deleted. If your anti-virus software can't delete them, then write the path to the file down and Restart your computer in MS-DOS mode. Once in DOS mode, proceed to use the DEL command to the delete the files.
Once the files are deleted, restart Windows. This should get rid of the BadTrans virus, but be sure to update your software and run a thorough virus scan of your system to check for other viruses.
variant of BadTrans logs keystrokes, sends log file including cached
passwords, and sends email messages. It arrives with a randomly
selected double extension filename. It uses a known vulnerability in
Internet Explorer-based email software (Outlook or Outlook Express) to
automatically execute the file attachment. Infecting the computer just
by previewing the message.
The virus will find unread mail to which it will reply. The subject will be "Re:". changes the From address in the header, adding an underscore (_) in front of the email address. Thus, replying to the email will be ineffective unless the _ is removed. The name of the attachment will be one of the following:
In all cases, the worm will append two extensions. The first will be one of the following:
The second extension that is appended to the file name is one of the following:
log file and the cached passwords are sent to one of these addresses or
some others which are currently not operational:
SMTP information can be found on the computer, then it will be used for
the From: field. Otherwise, the From: field will be one of these:
BadTrans.B Removal Instructions
Follow these steps for removing the BadTrans.B variant in Windows 95/98
Remove the virus from the Registry first. Click on START, RUN, type
REGEDIT, and click OK
Because the files may be in use, you may need to restart the computer in SAFE MODE before deleting the files in Windows ME, Windows 2000, or Windows XP instead of restarting the computer in MS-DOS Mode.
Now, run a thorough virus scan of your system to check for any reinfection of the virus
|Recommended Software for PC Hell Visitors|
iolo System Mechanic®
Emsisoft Anti Malware