|
-
July 8th, 2002, 01:03 PM
#1
Member
New Kazzaa Virus
There is a new Kazzaa virus out there.
W32/KWBot-A
Alias
W32.Kwbot.Worm, Worm.Win32.SdBot, W32/Moocow-A
Is it a worm wich uses the kazzaa network.
It copies itself as"explorer32.exe" in the windows systemfolder and creates 2 new
registry entries for running on system startup.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Explorer Update Build 1142 = explorer32
and
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Windows Explorer Update Build 1142 = explorer32
The worm infected the following files in the kazzaa network (examples only):
Star Wars Episode 2 - Attack of the Clones VCD CD1.exe
Spiderman The Movie - The Game.exe
Grand Theft Auto 3 CD1 ISO.exe
ZoneAlarm Firewall Pro.exe
Windows XP Professional iso.exe
Unreal Tournament cracked (works on all servers).exe
University Study Guide (cheat sheet).exe
Quicken Pro 2002 iso.exe
Perl Ultimate Study Guide.exe
Office XP Corporate Ed. iso.exe
Norton Utilities 2002.exe
Microsoft Visual C++ 7.0 iso.exe
MCSE Ultimate Study Guide.exe
Max Payne full iso.exe
Macromedia Flash 5.exe
Kazaa Advertisement Ad remover.exe
DSL Anonymizer.exe
DoS Attacker.exe
DivX Codec 6.0 beta (codec only).exe
Credit Card number generator VERIFIER (cc cc#).exe
cows gone wild.exe
100 XXX Passwords (verified 3-24-02).exe
Its possible that he attacker can control your infected system
with commands over IRC.
I hope my translation is not too bad, I got these informations
from the German Website of Sophos Antivir.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|