PPRuNe Forums

PPRuNe Forums (https://www.pprune.org/)
-   Computer/Internet Issues & Troubleshooting (https://www.pprune.org/computer-internet-issues-troubleshooting-46/)
-   -   Kazaa infected, P2P community watch out (https://www.pprune.org/computer-internet-issues-troubleshooting/54140-kazaa-infected-p2p-community-watch-out.html)

FL310 22nd May 2002 13:31

Kazaa infected, P2P community watch out
 
While we got a new sticky on this forum, here are some interesting news for the sharing communities...an intentionally created worm to protect copyrights.

The popular Peer-to-Peer net Kazaa has been infected with a virus. The worm is called w32.benjamin, also known as Benjamin or w32.fillhdd.a. The file hides as a very popular film, song or even title. Once the file is downloaded and started, (executed) the harddrive will be filled up with thousands of copies of the file.

Presently only Windows users are under threat. The file is classed as harmless as it does not redistribute by mail and does not destruct any data.
Following error message appears after activation:

Access error #03A:94574:
Invalid pointer operation
File possibly corrupted.

Benjamin copies itself as explorer.scr into the system area of Windows and changes following registry keys:

HKEY_LOCAL_MACHINE/Software/Microsoft
Windows/CurrentVersion/Run
"System-Service"=
"C:\WINDOWS\SYSTEM\EXPLORER.SCR"

HKEY_LOCAL_MACHINE/Software/Microsoft
"syscod"="00090D64D4700E36"

This forces explorer.scr to load each time the PC is booted. Benjamin also creates a new directory called sys32. Further, the worm changes the Kazaa user data and enables the new directory to be visible to all Kazaa users and copies itself into this directory, always with different file size.

Most, but not all, antivirus progies haveupdated, or are in the process to, their virus signatures, but.....

What_does_this_button_do? 22nd May 2002 20:23

Confirmed by those clever people, here.


All times are GMT. The time now is 10:49.


Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.