The Badtrans has Worm and Trojan characteristics. It spreads via email attachments, with the "From" address either the actual address of the sender or a randomly selected address from:
Rita Tulliani [firstname.lastname@example.org],
Kelly Andersen [Gravity49@aol.com],
Joanna [joanna @mail.utexas.edu],
JESSICA BENAVIDES [email@example.com],
Monika Prado [firstname.lastname@example.org],
Mary L. Adams [email@example.com],
The email "Subject: [EMPTY]" or "Subject: Re: (followed by a valid subject)"
The "Attachment Name:" is one of the following:
FOR WINDOWS 95/98/ME
- Boot up your computer with a clean DOS Boot Diskette from drive A
- Place your V-Buster diskette in Drive A and type "Vbuster" [ENTER]
- Use V-Buster to scan your computer. Delete all occurances of the worm
- When the scan is complete, exit to Dos. At the A prompt, type "C:" [ENTER]
- Copy back any files that you have previously deleted
- Boot up Windows
- Click on "Start", "Run" and type "Cmd". Click on "OK"
- Press "Ctrl-Alt-Del" Click on "Processes"
- Find "Explorer.exe" Click on "End Process"
- Find "kernel32.exe" Click on "End Process"
- Put the V-Buster diskette in your Drive A
- Click on "Start", "Run" and type "A:VBUSTER.EXE". Click on "OK"
- Use V-Buster to scan your computer. Delete all occurances of the virus
- Click on "Start", "Run" and type "C:\WINDOWS\EXPLORER.EXE". Click on "OK"
- Recopy any files that you have previously deleted