This is a peer-to-peer worm that spreads via KaZaa. The only purpose of the worm is to spread. It does not contain a damaging payload. When run, it copies itself to the %WinDir%\System32 directory as DirectXset.exe and creates a registry run key to load itself at startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "DirectX64" =C:\WINDOWS\System32\DirectXset.exe
The HKEY_CURRENT_USER\Software\KAZAA\LocalContent registry key is queried to locate the last "Dir" that is shared. The worm then creates a new shared directory, such as Dir4 = 012345:C:\WINDOWS\System32\Setup32\. 26 copies of the worm are saved to this directory using the following filenames:
Audio Catalyst 2.1.exe
Borland Delphi 7 Crack.exe
CladDVD XP 2 by fosi.exe
GFI Languard V4 Beta.exe
How to use Languard.exe
Mc Affee anti Virus Scan Patch.exe
Medal of Honor by TNT Keygenerator.exe
Movie Jack 2.exe
MS Windows Keygenerator all Versions_XP_2k_ME_98_95 .exe
Nero 5.5.9.14 Full + All Plugins Updates + Serial Keygen.exe
Norton AntiVirus 2003 Crack by Reality.exe
Office XP Keygenerator.exe
Partition Magic 7.exe
PowerDVD 5 - Keygenerator.exe
ProgDVB 3.29.exe
Quake all Versions Keygenerator.exe
Sim City 4 Download FULL.exe
SimCity 4 No CD Crack.exe
Ultra edit 32 new version + serial.exe
Unreal 2003 cd Crack 4 Ver 2166.exe
Unreal 2003.exe
Unreal Tournament 2003 internet Keygenerator-NEW.exe
Winamp 4 Beta.exe
Windows Longhorn Alpha Security Patch.exe
WinDVD Platinum all languages.exe
Zone Alarm Security Patch - 2003.exe
A file, readthisworld.txt, is also saved to this directory, containing the text Steph.With nice brown eyes .. 4 ever.