ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Online business Toolkit

Worm crawls into Kazaa network

Matt Loney ZDNet.co.uk

Published: 20 May 2002 11:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Kazaa file-swapping network has been hit by a virus, according to security experts.

The Kazaa network is one of the most popular file-exchange networks, with more than 81 million copies of its client downloaded to date, according Sharman Networks, the company that developed the service.

Security software firm Kaspersky Labs said the worm, called "Worm.Kazaa.Benjamin", is the first malicious program to spread through the Kazaa file exchange network, although Gnutella was hit by a proof-of-concept worm in February.

The Benjamin worm was reported to Kaspersky Labs on Saturday. "In terms of data destruction it is not very dangerous," said Kaspersky spokesman Denis Zenkin. "It does not erase any information, but eats up space on your hard disk and it jams the data transmission channels. It becomes harder for the Kazaa network users to communicate because lots of infected data is being placed in their hard drives, and if you look for a game you are likely to be offered a copy of the virus instead."

Benjamin spreads by creating a directory that is accessible to other users of the Kazaa network. It makes numerous -- possibly thousands -- copies of itself in this directory, using many different names from a list contained in the body of the worm. When a network user conducts a search for a file under a name corresponding with one the worm's pseudonyms, the unsuspecting user is given the chance to download it from the infected computer.

When it is downloaded, Benjamin displays a false error report, warning the user that the file is possible corrupted, but then goes on copy itself into the system directory and creates two keys in the system registry.

As well as eating up free disk space, said Kaspersky, Benjamin opens a Web page, called benjamin.xww.de to display banner ads. On Monday morning the Benjamin.xww.de Web site had a message saying: "Domain closed due to massive abuse."

Benjamin is written in Borland Delphi and is approximately 216KB in size - it is compressed by the AsPack utility. The size of a file can vary greatly as the worm ends each file with random data -- called "dust" -- for masking. But, said Zenkin, is can be removed relatively easily by deleting the infected files. Antivirus software vendors such as Kaspersky Labs have already updated their products to detect it, he added.

Sharman Networks could not immediately be reached for comment.


See the MP3 News Section for the latest on everything from MP3 players to Napster and the other music swapping services.

Have your say instantly, and see what others have said. Go to the Napster Debate.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
40 out of 93 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment