Content

W32/Traxg-B

Type
Virus
SubType
Generic Worm
Discovery Date
10/14/2004
Length
57,344 bytes
Minimum DAT
4314 (01/14/2004)
Updated DAT
4314 (01/14/2004)
Minimum Engine
5.1.00
Description Added
10/15/2004
Description Modified
10/15/2004 3:12 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

Proactive Detection
This worm is detected as W32/Generic.a@MM with the 4314 DATs or greater. As such it poses little risk to users running McAfee AV protection.

The worm bears the following characteristics:

  • written in MSVB
  • mails itself using Microsoft Outlook
  • copies itself multiple times to folders and drives on the local machine using enticing filenames
  • drops C:\FOLDER.HTT containing a script to run a copy of the worm
  • hooks system startup via the addition of a Registry key
  • modifies Registry keys to alter the settings of Windows Explorer

Symptoms

As discussed above. This virus has been proactively detected since 4314 DATs and so poses little risk to users running McAfee AV.

Method of Infection

As discussed above. This virus has been proactively detected since 4314 DATs and so poses little risk to users running McAfee AV.

Removal

All Users:
Use specified engine and DAT files for detection and removal.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Aliases

  • W32/Traxg-B (Sophos)

Characteristics

Characteristics -

Proactive Detection
This worm is detected as W32/Generic.a@MM with the 4314 DATs or greater. As such it poses little risk to users running McAfee AV protection.

The worm bears the following characteristics:

  • written in MSVB
  • mails itself using Microsoft Outlook
  • copies itself multiple times to folders and drives on the local machine using enticing filenames
  • drops C:\FOLDER.HTT containing a script to run a copy of the worm
  • hooks system startup via the addition of a Registry key
  • modifies Registry keys to alter the settings of Windows Explorer

Symptoms

Symptoms -

As discussed above. This virus has been proactively detected since 4314 DATs and so poses little risk to users running McAfee AV.

Method of Infection

Method of Infection -

As discussed above. This virus has been proactively detected since 4314 DATs and so poses little risk to users running McAfee AV.

Removal -

Removal -

All Users:
Use specified engine and DAT files for detection and removal.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A