Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | October 2005 (3.98) |
| Protection available since | 30 August 2005 22:23:29 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Baitap-A is a worm for the Windows platform.
When first run W32/Baitap-A will display a Macromedia Shockwave file intended to be a distraction.
W32/Baitap-A will will send itself in a message sent to those in the infected users' buddy list in popular chat programs.
When first run W32/Baitap-A copies itself to:
<Windows>\spoolsv.exe
<System>\resys.exe
W32/Baitap-A will create the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SVCHOST
<WINDOWS>\SPOOLSV.EXE
W32/Baitap-A will change the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogin
Shell
explorer.exe <WINDOWS>\SPOOLSV.EXE
