Once again a virus targets the KaZaA network


The KaZaA network has been hit again by a nasty worm. Here`s the info on this latest bugger:

Kaspersky Labs reports the detection of the network worm Duload, which is spreading across the KaZaA file-exchange network. Presently Kaspersky Labs has already received several registered instances of infection in Italy.

The worm itself is a Windows (PE EXE) application written in Visual Basic. Currently two modifications of the Duload worm are known, each having a different file size:

Worm.P2P.Duload.a - 18432 bytes

Worm.P2P.Duload.b - 7680 bytes (Compressed with the UPX utility)

If the infected attachment is accidentally opened "Duload" copies itself to the Windows system directory under the name "SystemConfig.exe" and modifies the system registry so that this file automatically loads each time Windows is started.

Next, the Duload worm creates a folder in the Windows directory called "Media" and copies itself to this directory under 39 different names. Such as:

Pamela Anderson And Tommy Lee Home Video.exe

Alicia Silverstone Payboy Nude.exe

Kama Sutra Tetris.exe

Soldier Of Fortune 2 Mutiplayer Serial Hack.exe

The Sims Game Crack.exe

Warcraft 3 Battle.net Crack.exe

Hotmail Hacker.exe

Xbox Emulator.exe

Ps2 Emulator.exe

Duload" then once again modifies the system registry in order to make the "Media" folder accessible to all other KaZaA network users.

One modification of the worm (Worm.P2P.Duload.a) also downloads from an Internet site several Trojan programs designed to establish the unauthorized remote management of victim computers.

The defense against "Duload" has already been added to the Kaspersky Labs Anti-virus database.

More about this worm can be found here and you can find the whole list with the 39 names this worms uses here.

Source: Kaspersky

No posts to display