Not-so BadTrans virus fails to spread

By Robert Lemos, ZDNet News
16 April 2001 12:45 PM
Tags: worm, virus, email virus, message, infect, micro
A virus that monitors a PC's network connections and sends itself in response to any incoming email has apparently failed to spread, despite, or because of, warnings issued by several major antivirus software makers.

"We initially gave it a medium rating, but we expect to downgrade that today," Susan Orbuch, spokeswoman for antivirus company Trend Micro, said Friday.

Though several of Trend Micro's customers reported receiving emailed copies of the virus, only three companies were actually infected, Orbuch said.

The mass-mailing worm, known as W32/BadTrans, appears attached to an email message either as a screensaver (.scr) or Windows shortcut (.pif) file, with any one of a variety of names, including Card, docs, hamster, humour and 12 others.

If opened, the worm first displays a dialog box titled, "WinZip Self-eXtractor," which reads, "File data corrupt: probably due to a bad data transmission or bad disk access." Then the worm will install a backdoor program, compromising the computer's security, and mail the victim's IP address to the virus writer.

The worm also replies to all incoming email messages, attaching itself to the outgoing message. The new message will have the same subject line and message body as the original email, and the sender will be the victim's username.

While it has some of the makings of a successful mass-mailer, BadTrans has effectively fizzled out, said Vincent Gullotto, director of Network Associates' antivirus emergency response team.

On Thursday the company received only 10 reports of the worm, he said. "There is a possibility that it was a bit more prevalent in the UK and Europe," he said. "But we consider it to be a low threat."

Symantec's Web site rated the virus as a 3 out of 5, with less than 50 infections to date.

The failure of the virus to spread may not mean that people are getting smarter in the use of email.

According to Trend Micro's research team, the virus had several technical problems.

"Not every version of the virus is working," said Trend Micro's Orbuch.

In addition, an attempt by the virus writer to make the worm not respond to emails from other infected computers was flawed. Two or more infected computers in a company result in a spam war of messages bouncing back and forth, which makes the worm extremely visible, Orbuch said.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Get extensions going in Firefox, redux
    Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
  • Array How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • More blogs »

Tags

Back to top

Featured