Precisa de ajuda? Peça à comunidade ou contrate um perito.
Acesse a Avira Answers
Alias:W32/BadTrans@MM
Type:Worm 
Size:13,312 Bytes Version A, 29,02 
Origin: 
Date:11-27-2001 
Damage:Badtrans.B sends itself by email using MAPI (Messaging Application Program Interface). 
VDF Version:6.23.00.00 
Danger:Low 
Distribution:Low 

DistributionThere is no text in the subject or body of the email sent by the worm.
The attachment's name is formed out of the following three expression groups, randomly collected and enlisted:
first group:
FUN HUMOR DOCS S3MSONG RESUME IMAGES PICS CARD SETUP Sorry_about_yersterday ME_NUDE YOU_ARE_FAT! HAMSTER NEWS_DOC README SEARCHURL
second group:
.DOC. .MP3. .ZIP.
third group:
pif
scr

Technical DetailsWhen the attachment is opened, the worm copies itself in Windows System directory with the name KERNEL32.EXE and enters the following registry key: [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce]?Kernel32?=?\%WINDIR%\SYSTEM\KERNEL32.EXE

Then, the worm dropps the file KDLL.DLL in Windows directory, which activates a keyboard process protocol Trojan.
Descrição enviada por Crony Walker em terça-feira, 15 de junho de 2004

Voltar . . . .
https:// Esta janela é criptografada para sua segurança.