Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
More Information
W32/Bajar-B is a mass mailing worm that emails itself to all entries in all Windows address books. It arrives in an email with the following characteristics:
Subject line: Nuevo programa para bajar musica gratis
Message body: con este programa vas a poder bajar cualquier tipo de musica las mejores canciones
The attached filename can be anything.
On execution W32/Bajar-B displays a message box containing the text "Instalando ZVmusic".
The worm checks the registry entry HKCU\Software\mp3_sent and if it is not set to "yea" then it makes it so and executes its mass mailing routine.
Finally W32/Bajar-B deletes:
C:\windows\rundll.exe
C:\windows\system\vshield.vxd
C:\autoexec.bat
C:\windows\regedit.exe
C:\windows\regedit.com
