AntiBadtrans
AntiBadtrans Ranking & Summary
AntiBadtrans description
After execution the worm will copies itself in Windows %System% directory under the kernel32.exe name, and it will drop the kdll.dll at the same location. To ensure that it will be executed at restart it adds the following registry key: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\Kernel32 with value kernel32.exe Then it will delete itself from the location where it was executed, and it will gather computer information (like User name, computer name, RAS information, passwords, so on) and sends it to the following e-mail address: uckyjw@hotmail.com
The Worm has two methods of getting e-mail addresses: It search them in *ht* and *.asp files in Internet Cache directory or it gets them with MAPI functions from e-mails received by the infected user. It will not send itself twice to the same address because it keeps the already used e-mail addresses in %SYSTEM%\PROTOCOL.DLL.
Manual removal: not recomended Automatic removal: Run BitDefender and let it delete the infected files it founds. Please download the Badtrans free removal tool, AntiBadtrans.B.exe, to automatically remove this virus.
AntiBadtrans Screenshot
AntiBadtrans Keywords
Bookmark AntiBadtrans
AntiBadtrans Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com