| Badtrans worm with keystroke logging functionality (BadtransWorm) |
|---|
| Vuln ID: | 7607 | |
|---|---|---|
| Risk Level: | High |
BadtransWorm |
| Platforms: | Microsoft Windows 95, Microsoft Windows NT: 4.0, Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Me, Microsoft Windows XP, Microsoft Windows 2003 Server | |
| Description: | Badtrans is a mass-emailer worm that includes some enhanced functionality to record an infected user's keystrokes. Badtrans is not intentionally destructive to files or data, but it may cause network traffic difficulties. The Badtrans worm employs three main components:
The author of the Badtrans worm used a modified version of the "Hooker" keystroke logging software, which was designed to gather security-sensitive information on the host by looking for passwords, gathering IP addresses, and capturing keystrokes. The Badtrans worm sends such information to one of several email addresses. |
|
| Remedy: | To remove the BadTrans worm from your system: CAUTION: Use Registry Editor at your own risk. Any change made with Registry Editor may cause severe and irreparable damage and may require you to reinstall your operating system. Internet Security Systems cannot guarantee that problems caused by the use of Registry Editor can be solved.
|
|
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Symantec Security Response McAfee Virus Information Library Microsoft Security Bulletin MS01-020 ISS X-Force |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |