GIRLS' STATE TRACK AND FIELD UPDATES

Q-C Online support pages
Technical support article

About the "Bad Transmission" or "BadTrans" Worm



Also Known As: W32/Badtrans-A, W32/Badtrans@MM, BadTrans, IWorm_Badtrans, I-Worm.Badtrans, TROJ_BADTRANS.A

W32.Badtrans.@mm is the latest virus spreading through the Internet over E-mail using Outlook and Outlook Express. It is a MAPI worm that replies to all unread mails in your e-mail message folders, whether they are new or old. When it comes to you, the recipient, it will be from someone you know, most likely it will be a reply to a message you sent to them. The original verion had text of: "Take a look to the attachment". The latest version of this virus comes with no message body at all, only the attachment. Common file names for the attachments are listed below.

When the older verions of worm is executed, it drops the backdoor Trojan Hkk32.exe in the \Windows folder, and then executes it. It then copies itself into the Windows folder as inetd.exe, adds a run= line to the Win.ini, and displays the following message:



The next time that the computer is rebooted, the worm will wait for 5 minutes, then it will use MAPI to find all unread email messages and reply to all of them. The worm also drops a file kern32.exe, which is a password-stealing Trojan, Troj/Keylog-C, into the Windows system directory and changes the registry key
\HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\kernel32=kern32.exe
Both virus variations make it so that the Trojan runs at Windows startup. When the Trojan runs, it attempts to send user-confidential information such as passwords, operating system details and keyboard keys pressed to an attacker. The worm will attach itself to the e-mail, using several different file names. Most appear as if the file has multiple extensions, such as:

Pics.ZIP.scr
images.pif
README.TXT.pif
New_Napster_Site.DOC.scr
news_doc.scr
hamster.ZIP.scr
YOU_are_FAT!.TXT.pif
searchURL.scr
SETUP.pif
Card.pif
Me_nude.AVI.pif
Sorry_about_yesterday.DOC.pif
s3msong.MP3.pif
docs.scr
Humor.TXT.pif
fun.pif

To remove this or any other virus, update your anti-virus software immediately and run a thorough scan of your machine. Your best defense against a virus is to always remember to never download any strange attachment, especially if you do not know who it is coming from. If you do not know what a specific attachment is, reply to the person who sent it to you and ask, do not download. Your second line of defense should be having, and running, an up to date Anti-Virus application. For more information on virus updates and anti-virus software, visit our Virus Information section.

Local events heading








  Today is Saturday, May 18, the 138th day of 2013. There are 227 days left in the year.
1863 -- 150 years ago: A large variety of children's wagons and gigs have arrived in thecity and are being sold at war prices.
1888 -- 125 years ago: All Rock Island retail houses, with the exception of a clothingstore and a jewelry store, have agreed to early closing hours during the summer months.The store will be closed at 8 p.m.
1913 -- 100 years ago: Baseball enthusiasts in Rock Island are attempting to raise$20,000 to keep the Island City Park open, despite the fact that the city has no franchise inorganized baseball this year.
1938 -- 75 years ago: The organization of a third rural young people's unit will beundertaken tomorrow night at the Milan Presbyterian Church, with Mrs. Mildred K.Wellman, home advisor, and Robert Smith, county farm adviser in charge.
1963 -- 50 years ago: Deere & Co. will begin a "big switch" on its telephone systemMonday morning. The extension numbers of all 1,600 telephones on the firm's EastMoline and Moline exchanges will be changed Monday morning.
1988 -- 25 years ago: East Moline's June Jamboree VI -- Nostalgia Days, will seemlike a '60s revival with the appearance of stars like Bobby Vee, Freddie Cannon, PeterNoone, Turtles, The Grass Roots and Lou Christie. This year's festival has beenexpanded to five days, June 22-26, at the Northeast Park complex.




(More History)