Click to See Complete Forum and Search --> : kazaa officially a virus....


NooNoo
May 20th, 2002, 12:28 PM
Had a guest in the chatroom with this...lot of people gonna be swearing real soon!

<a href="http://support.centralcommand.com/cgi-bin/command.cfg/php/enduser/std_adp.php?p_refno=020520-000004" target="_blank">http://support.centralcommand.com/cgi-bin/command.cfg/php/enduser/std_adp.php?p_refno=020520-000004</a>

Brief description:

Worm/Kazaa.Benj that uses the file exchange P2P network Kazaa to
spread itself. It is written in Borland Delphi and is
approximately 216 kb in size The size of a file can vary since
the worm adds random data to itself to avoid detection.

The worm then copies itself in the \windows\%system% directory
under the filename "EXPLORER.scr".

Additionally, a set of random *.scr and *.exe files are created
in the /windows/Temp/sys32 folder.

So that it gets run each time a user restart their computer the
following registry key gets added:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
System-Service"="C:\\WINDOWS\\SYSTEM\\EXPLORER.SCR

The following key also gets created:

HKEY_LOCAL_MACHINE\Software\Microsoft
"syscod"="00090D64D4700E36"

Once EXLPORER.scr is ran, it will create a large number of *.exe
and *.scr files with names assocaited with movie titles, song
titles, or T.V. shows (ie. Age of Empires ScreenSaver,
BlackHawkDown, NASCAR Heat-installer). A user searching for a
file in the Kazaa network finds it in the list of accessible
files on already infected machine. Kazaa newtork users then
download the worm and execute it. The worms payload is to open
the (benjamin.xww.de) website.

DANIMAL
May 20th, 2002, 02:46 PM
Thanks for the heads up!

MacGyver
May 20th, 2002, 03:46 PM
I wondered how long it would be before somebody would unleash something like this.

Poseidon
May 20th, 2002, 04:37 PM
Thanks for the info.

It was only a matter of time.

gtiseb
May 21st, 2002, 07:43 AM
this is actually not that bad. Only because it's a test. Virus writers are jsut testing the baility with a little dinky worm that's easily detectable and eraseble. I'm worried about the REAL attack that will come when they make one that self replicates, hides, erases and kills the computer.

Then you'll see all our paychecks rise!

Stalemate
May 21st, 2002, 10:30 AM
I guess it's another step towards the "superworm" trojan virus that will make a lot of people cry someday. :rolleyes:

Thanks for the notice, NooNoo.