Notices
Non Scooby Related Anything Non-Scooby related

Nasty virus I cam across today...

Thread Tools
 
Search this Thread
 
Old Jun 8, 2001 | 10:03 PM
  #1  
DazV's Avatar
DazV
Thread Starter
Scooby Regular
 
Joined: Jun 2000
Posts: 3,783
Likes: 0
Post

Called BadTrans

Infects via an email attachment which can be any one of the following:
Card.pif
docs.scr
fun.pif
hamster.ZIP.scr
Humor.TXT.pif
images.pif
New_Napster_Site.DOC.scr
news_doc.scr
Me_nude.AVI.pif
Pics.ZIP.scr
README.TXT.pif
s3msong.MP3.pif
searchURL.scr
SETUP.pif
Sorry_about_yesterday.DOC.pif
YOU_are_FAT!.TXT.pif

Once triggered it splits intself into 3 parts.

One called INETD.EXE is triggered by the win.ini. (located in windows folder)

One called KERN32.exe which is a trojan. (located in windowssystem folder)

Last one is the worst, called HKSDLL.DLL - its a keylogger which is capable of recording keypresses (like credit card info) into a file. The file is then transmitted back to the author.

Nasty or what ?
More info at
Reply
Old Jun 10, 2001 | 12:02 PM
  #2  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Post

Clever little b'stard isn't it. Hope everyone here practices safe hex.

If anyone here needs Antivirus advice feel free to ask.

Jack Clark
McAfee/Dr Solomon's

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>Originally posted by DazV:
<B>
Card.pif
docs.scr
fun.pif
hamster.ZIP.scr
Humor.TXT.pif
images.pif
New_Napster_Site.DOC.scr
news_doc.scr
Me_nude.AVI.pif
Pics.ZIP.scr
README.TXT.pif
s3msong.MP3.pif
searchURL.scr
SETUP.pif
Sorry_about_yesterday.DOC.pif
YOU_are_FAT!.TXT.pif[/quote]

Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
Nov 4, 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
Dec 28, 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
Nov 18, 2015 07:03 AM
Ganz1983
Subaru
5
Oct 2, 2015 09:22 AM




All times are GMT +1. The time now is 11:44 PM.