Microsoft KB Archive/310403

= How to Remove the W32.Badtrans.13312@mm Worm Virus from Your Computer =

Article ID: 310403

Article Last Modified on 1/31/2007

-

APPLIES TO


 * Microsoft Outlook Express 5.01 Service Pack 1
 * Microsoft Outlook Express 5.0
 * Microsoft Outlook Express 5.5 Service Pack 1
 * Microsoft Outlook Express 5.01 Service Pack 1
 * Microsoft Outlook Express 5.01 Service Pack 2
 * Microsoft Outlook Express 5.0
 * Microsoft Outlook Express 5.5 Service Pack 1
 * Microsoft Outlook Express 5.01 Service Pack 1
 * Microsoft Outlook Express 5.01 Service Pack 2
 * Microsoft Outlook Express 5.0
 * Microsoft Outlook Express 5.5 Service Pack 1
 * Microsoft Outlook Express 5.01 Service Pack 1
 * Microsoft Outlook Express 5.01 Service Pack 2
 * Microsoft Outlook Express 5.5 Service Pack 1
 * Microsoft Outlook Express 5.01 Service Pack 2

-



This article was previously published under Q310403



IMPORTANT: This article contains information about modifying the registry. Before you modify the registry, make sure to back it up and make sure that you understand how to restore the registry if a problem occurs. For information about how to back up, restore, and edit the registry, click the following article number to view the article in the Microsoft Knowledge Base:

256986 Description of the Microsoft Windows Registry



SUMMARY
This article describes the damage that occurs if your computer becomes infected with the W32.Badtrans.13312@mm worm virus. The article also has instructions for removing the virus from a computer that runs Microsoft Windows 2000, Microsoft Windows Millennium Edition (Me), Microsoft Windows NT 4.0, Microsoft Windows 98, or Microsoft Windows 95.



MORE INFORMATION
The W32.Badtrans.13312@mm worm virus is also known as W32/Badtrans-A, W32/Badtrans@MM, BadTrans, IWorm_Badtrans, I-Worm.Badtrans, and TROJ_BADTRANS.A.

How the Virus Affects a Computer
After your computer becomes infected with the W32.Badtrans.13312@mm worm virus, you receive a dialog box that says, &quot;File data corrupt: probably due to bad data transmission or bad disk access.&quot; If you click OK, when you next start your computer, Outlook Express waits five minutes and then automatically replies to all of the unread messages that are in the Inbox.

The virus uses one of the following names to attach itself to each of the replies:
 * Pics.ZIP.scr
 * images.pif
 * README.txt.pif
 * New_Napster_Site.doc.scr
 * News_doc.scr
 * Hamster.ZIP.scr
 * YOU_are_FAT!.txt.pif
 * searchURL.scr
 * SETUP.pif
 * Card.pif
 * Me_nude.avi.pif
 * Sorry_about_yesterday.doc.pif
 * s3msong.MP3.pif
 * docs.scr
 * Humor.txt.pif
 * fun.pif

When the W32.Badtrans.13312@mm worm virus runs, it places the &quot;Trojan horse&quot; file Hkk32.exe in the Windows folder and then runs the Hkk32.exe file. The virus then copies itself into the Windows folder as Inetd.exe, adds a run= line to the Win.ini file, and displays the dialog box message about &quot;File data corrupt.&quot;

How to Remove the W32.Badtrans.13312@mm Worm Virus
To resolve this behavior, remove the worm virus. You must delete all of the files that are detected as W32.Badtrans.13312@mm, undo the changes that the virus makes to the registry, and then, if you are running Microsoft Windows 95, Microsoft Windows 98, or Microsoft Windows Millennium Edition (Me), remove the virus entry from the run= line of the Win.ini file.

Delete All W32.Badtrans.13312@mm Files

 * 1) Click Start, click Find, and then click Files or Folders. (In Microsoft Windows 2000, click Start, click Search, and then click Files or Folders.)
 * 2) Type W32.Badtrans.13312@mm, and then click Find Now (or in Windows 2000, click Search).
 * 3) In the results window, delete all files that are named W32.Badtrans.13312@mm.
 * 4) Quit the search tool.
 * 5) Do one of the following:
 * 6) * If you are running Windows 95, Windows 98, or Windows Me, skip the rest of this set of steps and go to the next set of steps, &quot;Edit the Registry.&quot;
 * 7) * If you are running Microsoft Windows NT 4.0 or Windows 2000, continue with this set of steps.
 * 8) Press CTRL+ALT+DELETE, click Task Manager, and then click Processes.
 * 9) Click Image Name twice, to sort the processes alphabetically.
 * 10) Scroll through the list and look for the Inetd.exe file. If you find this file, click the file, and then click End Process.
 * 11) Scroll through the list and look for the Kern32.exe file. If you find this file, click the file, and then click End Process.
 * 12) Quit Task Manager.
 * 13) Right-click the My Computer icon on the Windows desktop, and then click Explore.
 * 14) Do one of the following:
 * 15) * If you are running Windows NT, click View, and then click Options.
 * 16) * If you are running Windows 2000, click Tools, and then click Folder Options.
 * 17) Click View.
 * 18) Do one of the following:
 * 19) * If you are running Windows NT, click Show all files, click to clear the Hide file extensions for known file types check box, and then click OK.
 * 20) * If you are running Windows 2000, click Show hidden files and folders, and then click to clear the Hide file extensions for known file types check box.
 * 21) In the left pane of Windows Explorer, right-click drive C, and then click Find (in Windows NT) or Search (in Windows 2000).
 * 22) In the Named box (in Windows NT) or in the Search for Files and Folders box (in Windows 2000), type (or copy and paste) the following file names: inetd.exe kern32.exe hkk32.exe hksdll.dll kdll.dll
 * 23) Click Find Now (in Windows NT) or Search Now (in Windows 2000).
 * 24) When the search is complete, write down the names and locations of the files that are listed.
 * 25) On the Edit menu, click Select All.
 * 26) Hold down SHIFT, press DELETE, and then continue to hold down SHIFT until you are prompted to confirm the deletion. Click Yes. (Holding down SHIFT while you press DELETE bypasses the Recycle Bin.)
 * 27) Quit Windows Explorer.

Delete the Virus Value from the Registry
WARNING: If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.

 Start Registry Editor (Regedt32.exe). Locate the Kernel32 KERN32.EXE value under the following key in the registry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

 On the Edit menu, click Delete, and then click OK. Do one of the following:  If you are running Windows 95, Windows 98, or Windows Me, skip the rest of this set of steps and go to the next set of steps, &quot;Edit the Win.ini File.&quot; If you are running Windows NT or Windows 2000, continue with this set of steps.</li></ul> </li> Locate the run \Inetd.exe value under the following key in the registry:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

</li> On the Edit menu, click Delete, and then click OK.</li> Quit Registry Editor.</li></ol>

Remove a Line from the Win.ini File
If you are running Windows 95, Windows 98, or Windows Me, you must also remove a line from the Win.ini file: <ol> Click Start, and then click Run.</li> Type edit c:\windows\win.ini, and then click OK. (If Windows is installed in some other location, make the appropriate substitution in the path.)</li> In the [windows] section, locate the run= line. It looks similar to this:

run=c:\windows\inetd.exe

</li> Remove all of the text that is to the right of the equal sign (=), so that the line now reads run=.</li> Save your changes.</li></ol>

How to Protect Your Computer from Viruses
To help protect your computer from computer viruses, obtain current antivirus software. Microsoft does not provide software to detect or remove computer viruses.

For additional information about antivirus software manufacturers, click the article number below to view the article in the Microsoft Knowledge Base:

49500 List of Antivirus Software Vendors

Keywords: kbinfo KB310403

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.