Badtrans.B Worm Spreading Fast

Badtrans.B Worm Spreading Fast

Written By
Dennis Fisher
Dennis Fisher
Dec 3, 2001
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A fast-spreading e-mail worm infected thousands of home users over the Thanksgiving holiday weekend and began spreading in enterprises as well early last week.

Known as Badtrans.B, the virus infects PCs through several methods, but the most troubling aspect of the new worm is its ability to install a keystroke logger and a backdoor Trojan.

Badtrans.B, a variant of the original Badtrans virus, arrives in the users in-box as an executable attachment with one of numerous names. The worm will execute if the infected message is viewed in the preview pane of older or unpatched versions of Outlook.

Once its resident on a PC, the worm replies to any unanswered messages in the users in-box and tries to send the IP address of the machine to an anonymous e-mail account.

The virus is not destructive, but it follows an all-too-familiar infection pattern that anti-virus companies say should be obsolete by now.

“Why make it easy for the virus writers? If companies had blocked files with double extensions from entering their organizations after the Love Bug in May last year, they would not have been affected by Badtrans, Sircam, Anna Kournikova, Apology and countless other e-mail-aware worms,” said Graham Cluley, senior technology consultant for Sophos plc., an anti-virus company based in Abingdon, England. “Furthermore, one of the ways this worm attacks is by exploiting a security hole in Microsoft Outlook. Its baffling to find that even though Microsoft secured that hole eight months ago, many users have still not applied the patch.”

Badtrans.B began spreading in Europe on Friday, Nov. 23, and hit home users in the United States over that weekend, anti-virus companies said. When corporate users returned to work the following Monday and opened their e-mail, the worm picked up momentum. By early last week, MessageLabs, of Gloucester, England, which tracks virus outbreaks, had stopped more than 9,300 copies of Badtrans.B.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.