Norton found this one yesterday when I downloaded my email. It is #2 on the threat list behind Sircam. It sends messages to your unread mail.
W32.Badtrans.13312@mm
Discovered on: April 11, 2001
Last Updated on: June 21, 2001 at 07:40:49 AM PDT
Due to an increase in the number of submissions, W32.Badtrans.13312@mm has been upgraded to a Category 4 threat. It is a MAPI worm that replies to all unread messages in your email message folders and drops a backdoor Trojan.
Also Known As: W32/Badtrans-A, W32/Badtrans@MM, BadTrans, IWorm_Badtrans, I-Worm.Badtrans, TROJ_BADTRANS.A
Category: Worm
Payload:
Large scale e-mailing: It replies to all unread messages in the message folders within the default MAPI email program.
Compromises security settings: It drops a backdoor Trojan.
Technical description:
When the worm is executed, it drops the backdoor Trojan Hkk32.exe into the \Windows folder and executes it. It then copies itself into the \Windows folder as inetd.exe, adds a run= line to the Win.ini file, and displays the following message: File data corrupt:
Probably due to bad data transmission or bad disk access.
The next time that the computer is restarted, the worm waits for five minutes and then uses MAPI to find all unread email messages and reply to all of them. The worm attaches itself to the message using one of the following file names:
Pics.ZIP.scr
images.pif
README.TXT.pif
New_Napster_Site.DOC.scr
news_doc.scr
hamster.ZIP.scr
YOU_are_FAT!.TXT.pif
searchURL.scr
SETUP.pif
Card.pif
Me_nude.AVI.pif
Sorry_about_yesterday.DOC.pif
s3msong.MP3.pif
docs.scr
Humor.TXT.pif
fun.pif