P2P-Zone

P2P-Zone (http://www.p2p-zone.com/underground/index.php)
-   Peer to Peer (http://www.p2p-zone.com/underground/forumdisplay.php?f=5)
-   -   Worm spreads through KaZaA network, again (http://www.p2p-zone.com/underground/showthread.php?t=12851)

zombywoof 23-08-02 10:23 AM

Worm spreads through KaZaA network, again
 
For those of you who use kazaa. I don't use it myself, but here is some info for those who do.


Virus watchers have discovered the latest in a line of viruses targeted at file sharing networks.

The Duload worm is spreading across the KaZaA file-exchange network, antivirus firm Kaspersky Labs warns today based on reports of infections from Italian internet users.

Duload appears as a Windows executable written in Visual Basic either 18432 bytes or, in its compressed form, 7680 bytes in size.

If the infected file is accidentally opened "Duload" copies itself to the Windows system directory under the name "SystemConfig.exe" and modifies the system registry so that this file automatically loads each time Windows is started.

Next, the Duload worm creates a folder in the Windows directory called "Media" and copies itself to this directory under 39 different names, explained in more detail in Kasperky's advisory.

Duload then once again modifies the system registry in order to make the Media folder accessible to all other KaZaA network users, with the aim of furthering its spread.

One modification of the worm also downloads from the Net several Trojan programs designed to establish the unauthorised remote management of victim computers.

Antivirus vendors are in the process of updating their tools to detect the worm. As always, the main advice remains to be vigilant about the possibility of downloading and running executable code from file sharing Web sites.

File sharing services are increasingly becoming a target for virus writers. In June, KaZaA users became exposed to a virus called Backdoor.K0wbot.1.3.B, which followed the infection of the network by Benjamin worms only a month earlier. ®

article: http://www.theregus.com/content/55/26080.html

JackSpratts 23-08-02 12:00 PM

thanks oscar. :tu:

- js.

kento 23-08-02 12:43 PM

i steel think that newsgroups and or irc is the way-to-go but kazaa is nice too...however this is like the third virus in what? 3 months? do these viruses just propagate automatically or do they have to be executed?

the article on the antivirus website didn't say.

thanks,

-kento ;)

MagicMorpheus 23-08-02 01:41 PM

Most viruses (or trojans) have to be executed but I'm not sure about this one.:)

Merijn 24-08-02 06:24 AM

All trojans/worms/viruses for Kazaa have (and probably will) use the same approach to spreading:
- you download the worm thinking it's something else
- you are stupid enough to execute it
- the worm copies itself to several dozen filenames that seem attractive to stupid Kazaa users
- the worm makes the folder it copied itself to available to the Kazaa network by writing it to the Registry where Kazaa looks for folders to share
- rinse and repeat

So if you have a virusscanner that's up-to-date: don't worry.

kento 24-08-02 07:37 AM

Quote:

Originally posted by Merijn
All trojans/worms/viruses for Kazaa have (and probably will) use the same approach to spreading:
- you download the worm thinking it's something else
- you are stupid enough to execute it
- the worm copies itself to several dozen filenames that seem attractive to stupid Kazaa users
- the worm makes the folder it copied itself to available to the Kazaa network by writing it to the Registry where Kazaa looks for folders to share
- rinse and repeat

So if you have a virusscanner that's up-to-date: don't worry.

Thanks for the clarification, Merijn...and hello to MagicMorpheus! :)

MagicMorpheus 24-08-02 09:54 AM

What's up, Kento!:)

pod 26-08-02 10:05 AM

Duload not to be confused with the perfectly legitimate DUMeter.

colinmacc 27-08-02 08:54 AM

classic!
 
Quote:

Originally posted by Merijn

- you are stupid enough to execute it

You've hit the nail on the head here.

This is the critical step. This is where all viruses would cease to exist if people could avoid doing this!!

Merijn 28-08-02 04:12 PM

Re: classic!
 
Quote:

Originally posted by colinmacc
This is the critical step. This is where all viruses would cease to exist if people could avoid doing this!!
Well, not all ofcourse. Some rely on the Microsoft security model (what? where?) to spread. ;)


All times are GMT -6. The time now is 03:45 PM.

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© www.p2p-zone.com - Napsterites - 2000 - 2024 (Contact grm1@iinet.net.au for all admin enquiries)