Need help? Ask the community or hire an expert.
Go to Avira Answers
Alias:W32/BadTrans@MM
Type:Worm 
Size:13,312 Bytes Version A, 29,02 
Origin: 
Date:11-27-2001 
Damage:Badtrans.B sends itself by email using MAPI (Messaging Application Program Interface). 
VDF Version:6.23.00.00 
Danger:Low 
Distribution:Low 

DistributionThere is no text in the subject or body of the email sent by the worm.
The attachment's name is formed out of the following three expression groups, randomly collected and enlisted:
first group:
FUN HUMOR DOCS S3MSONG RESUME IMAGES PICS CARD SETUP Sorry_about_yersterday ME_NUDE YOU_ARE_FAT! HAMSTER NEWS_DOC README SEARCHURL
second group:
.DOC. .MP3. .ZIP.
third group:
pif
scr

Technical DetailsWhen the attachment is opened, the worm copies itself in Windows System directory with the name KERNEL32.EXE and enters the following registry key: [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce]“Kernel32“=“\%WINDIR%\SYSTEM\KERNEL32.EXE

Then, the worm dropps the file KDLL.DLL in Windows directory, which activates a keyboard process protocol Trojan.
설명 삽입자 Crony Walker   2004년 6월 15일 화요일

뒤로 . . . .
https:// 이 창은 보안을 위해 암호화되었습니다.