Feeds

BadTrans virus bites Windows users hard

Mass mailer outbreak

  • alert
  • submit to reddit

Top 5 reasons to deploy VMware with Tegile

Computer users turned on their PCs this morning to find their In-boxes flooded with copies of the latest mass mailing virus.

BadTrans.B is spreading rapidly after infecting a large number of home users in the UK over the weekend. BTOpenworld shut off an email system today, but not before infecting many customers with the virus.

MessageLabs, a managed services firm which scans for and blocks viruses in email for clients, has blocked 5,164 copies of the virus this morning. Its figures show btinternet.com, ntlworld.com and freeserve.co.uk as the most common sources of the virus.

BadTrans.B is a variant of a virus which first appeared in April. It usually arrives as an email with either the subject line Re: (name of file attachment) or Re: (the subject line of a previous message thread). The email contains a double attachment and a name made up of a series of elements which "alternate like a fruit machine", according to Mark Sumner, CTO of MessageLabs.

BadTrans.B uses a known exploit, related to the processing of certain unusual MIME types, in certain versions of Outlook Express 5 so as to launch an attachment automatically. The trick, which was also used by the authors of the Nimda worm, means simply previewing an infected email is enough to get infected. Users who double click on an infected attachment also risk infection.

BadTrans.B uses MAPI to spread and gets target addresses from unread messages in a user's email client. The worm also drops a file named kdll.dll, which is the password stealing Trojan PWS-AV , on an infected user's PC.

Users should update their antivirus protection to guard against the virus. In addition, corporate users should consider blocking emails with .pif or .scr attachments at the email gateway, a step that would block BadTrans.B before it reaches user's desktops. ®

External links

Good analysis of the virus outbreak by MessageLabs
Description of the BadTrans-B worm by Sophos
Incorrect MIME Header Can Cause IE to Execute E-mail Attachment (MS bulletin and links to a patch)

Related Stories

SirCam blitz is damp squib
Thousands of idiots still infected by SirCam
SirCam virus hogs connections with spam
Firms hit in Nimda mutant outbreak
Nimda worm tails off
Users haven't learned any lessons from the Love Bug
Rise in viruses within emails outpacing growth of email
There's a virus in my WinXP system, part two
BTopenworld sends Trojan to subscribers

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.