All the latest UK technology news, reviews and analysis

Badtrans is back, but don't panic

by Chris Lee

26 Nov 2001

Be the first to comment

  • Tweet this

A new variant of the damaging Badtrans internet worm has emerged over the weekend, prompting security experts to remind IT managers to update antivirus software and warn staff to look out for suspicious attachments.

Security specialist McAfee said that the 'B' variant of the W32/Badtrans@MM worm, or Badtrans.b, is a mass-mailing internet worm, like the Melissa and Lovebug viruses before it, that attempts to send itself using Microsoft Outlook by replying to unread emails.

Badtrans first surfaced in April. When executed, it drops a remote access Trojan, or RAT, into the user's Windows directory, which attempts to mail the victim's internet protocol (IP) address to the author.

David Emm, product marketing manager for McAfee, which has been tracking the new-variant virus for about a month, said that the subject and body text may vary, but will come with an attachment that is 13,312 bytes in length and will take a number of forms including the following:

S3MSONG.DOC.scr
Pics.DOC.scr
HUMOR.MP3.scr
Sorry_about_yesterday.MP3.pif
README.MP3.scr
ME_NUDE.MP3.scr
fun.MP3.pif
NEWS_DOC.DOC.scr
docs.DOC.pif
images.DOC.pif
HAMSTER.DOC.pif
SEARCHURL.MP3.pif

"At the moment we're not saying the situation is serious, we're just warning people that it's out there," said Emm.

"Home users are particularly affected, but as ever it's just a question of reminding people to update their antivirus software and beware of mysterious attachments or messages from people they don't recognise."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

1%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Global Project/Programme Manager-with recruitment deployment experienc

My London client is looking for an experienced Programme...

PHP Developers (All Levels)

My leading client is looking for a number of excellent...

Group Services Manager - Telecoms

My client, a leading international name in Manufacturing...

Automated PHP Developer

My client is looking for an Automated Engineer/Developer...

To send to more than one email address, simply separate each address with a comma.