DESCRIPTION:
The Badtrans has Worm and Trojan characteristics. It spreads via email attachments, with the "From" address either the actual address of the sender or a randomly selected address from:
Anna [aizzo@home.com],
JUDY [JUJUB271@AOL.COM],
Rita Tulliani [powerpuff@videotron.ca],
Kelly Andersen [Gravity49@aol.com],
Andy [andy@hweb-media.com],
Linda [lgonzal@hotmail.com],
MonS [spiderroll@hotmail.com],
Joanna [joanna @mail.utexas.edu],
JESSICA BENAVIDES [jessica@aol.com],
Administrator [administrator@border.ner],
Admin [admin@gte.net],
Support [support@cyberramp.net],
Monika Prado [monika@telia.com],
Mary L. Adams [mary@c-com.net],
Anna [lindaizzon@home.com],
JUDY [JUJUB@AOL.COM],
Tina [tina08@yahoo.com]
The email "Subject: [EMPTY]" or "Subject: Re: (followed by a valid subject)"
The "Attachment Name:" is one of the following:
Card/CARD,
fun/FUN,
HAMSTER,
Humor/HUMOR,
images/IMAGES,
info,
me_nude/ME_NUDE,
New_napster_site,
news_doc,
Pics/PICS,
S3MSONG,
SEARCHURL,
SETUP,
Sorry_about_yesterday,
studd,
YOU_are_FAT
REMOVAL INSTRUCTIONS:
FOR WINDOWS 95/98/ME
- Boot up your computer with a clean DOS Boot Diskette from drive A
- Place your V-Buster diskette in Drive A and type "Vbuster" [ENTER]
- Use V-Buster to scan your computer. Delete all occurances of the worm
- When the scan is complete, exit to Dos. At the A prompt, type "C:" [ENTER]
- Copy back any files that you have previously deleted
WINDOWS NT/2000/XP
- Boot up Windows
- Click on "Start", "Run" and type "Cmd". Click on "OK"
- Press "Ctrl-Alt-Del" Click on "Processes"
- Find "Explorer.exe" Click on "End Process"
- Find "kernel32.exe" Click on "End Process"
- Put the V-Buster diskette in your Drive A
- Click on "Start", "Run" and type "A:VBUSTER.EXE". Click on "OK"
- Use V-Buster to scan your computer. Delete all occurances of the virus
- Click on "Start", "Run" and type "C:\WINDOWS\EXPLORER.EXE". Click on "OK"
- Recopy any files that you have previously deleted