需要修復電腦?
聘請專家
Alias:W32/BadTrans@MM
Type:Worm 
Size:13,312 Bytes Version A, 29,02 
Origin: 
Date:11-27-2001 
Damage:Badtrans.B sends itself by email using MAPI (Messaging Application Program Interface). 
VDF Version:6.23.00.00 
Danger:Low 
Distribution:Low 

DistributionThere is no text in the subject or body of the email sent by the worm.
The attachment's name is formed out of the following three expression groups, randomly collected and enlisted:
first group:
FUN HUMOR DOCS S3MSONG RESUME IMAGES PICS CARD SETUP Sorry_about_yersterday ME_NUDE YOU_ARE_FAT! HAMSTER NEWS_DOC README SEARCHURL
second group:
.DOC. .MP3. .ZIP.
third group:
pif
scr

Technical DetailsWhen the attachment is opened, the worm copies itself in Windows System directory with the name KERNEL32.EXE and enters the following registry key: [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce]?Kernel32?=?\%WINDIR%\SYSTEM\KERNEL32.EXE

Then, the worm dropps the file KDLL.DLL in Windows directory, which activates a keyboard process protocol Trojan.
說明撰寫者 Crony Walker 開啟 2004年6月15日星期二

返回 . . . .
https:// 為了你的安全,此視窗已加密。