Do I have the BadTrans worm?

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Tipacanoe

Thread Starter
Joined
Feb 7, 2001
Messages
852
:confused:

When I d/l e-mails this am, I found 3 files with attachments, 2 senders unknown and 1 known and the same sender. When I went to check for the details on the attachments, I was presented in each case with a screen saying: You have chosen to d/l a file from this location

EA4DMGBP9p from

What would you like to do with this file?
- open
- save

I decided not to open and went about business on other e-mails.

When I returned to the unopened e-mails, as soon as I clicked on the first one, I was presented with an AVG warning screen warning of the badtrans virus. I closed the screen and deleted that file.

I consulted Norton's instructions, shut down, started in safe mode, b/u registry, and looked for kernel32.exe in RunOnce. That file was not there, only an icon saying default.

I opened in Windows and looked at remaining attachments. They have extensions like docs.doc.pif.

I scanned with AVG in both safe mode and not. No virus files were reported.

What should I be doing now? Thanks very much indeed.
 
Joined
Oct 14, 2001
Messages
2,218
Hi... Did the attachment jump up w/ out you trying to open it?

Was your AVG Virus scanner updated?

If not go scan at housecalls... its free & very efficient.
You can get there by clicking Here!


Savvy :)
also see this post!
 

Tipacanoe

Thread Starter
Joined
Feb 7, 2001
Messages
852
Thanks for quick reply.

Yes. I think I just opened the e-mail. I may have clicked on the paper clip - I guess I must have - to get the "You have chosen ..." screen.

As I said, I have scanned twice with AVG updated as of 11/24. It did not id any virus files.

Do you still think I need to go to housecalls too?
 

Tipacanoe

Thread Starter
Joined
Feb 7, 2001
Messages
852
I had forgotten that when I delete it just goes to a delete folder. When I just remembered I went there again. As soon as I clicked on the e-mail, I got the AVG warning again. It asked if I wanted to enable access. I replied no and deleted the file from delete.

Thoughts? Thanks.
 
Joined
Oct 14, 2001
Messages
2,218
No... its a self installing virus & opens itsself even in the preview pane of your e-mail... AVG must have quarantined it. I also was hit w/ it last night. Same thing & circumstances.

It did steal my passwords in my e-mail settings. Had to redo them in accounts.

Savvy :)

Go to AVG quarantine & delete it & yes I went to houscalls too... better safe than sorry
 
Joined
Oct 14, 2001
Messages
2,218
For what its worth I got hit with it last night too.
Same identical way & follwed thru just like you.

Savvy :)
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top