ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Another worm crawls around Kazaa

Graeme Wearden ZDNet.co.uk

Published: 22 Aug 2002 17:03 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Users of file-swapping service Kazaa have been warned about a new worm that could put their computers under the remote control of hackers.

Antivirus firm Kaspersky Labs said on Thursday that it had detected the worm, called Duload, spreading across the Kazaa network. This is at least the third worm to hit the Kazaa network, following KWBot last month and May's Benjamin worm.

Duload is a Windows attachment written in visual basic, Kaspersky said. Like KWBot and Benjamin, Duload spreads by modifying the infected computer's system registry and then disguising multiple copies of itself as files that other Kazaa users might like to download.

The first time that Duload is run, it copies itself to the Windows system directory under the name "Systemconfig.exe", and edits the system registry so that it is automatically run whenever Windows is loaded.

Duload then creates a folder called Media, and makes 39 copies of itself. It uses names such as Free Porn.exe, Win An Xbox.exe, Soldier Of Fortune 2 Mutiplayer Serial Hack.exe and Britney Spears Dance Beat.exe.

By then making the Media folder accessible to other Kazaa users, Duload sets up the conditions necessary for it to spread across the Kazaa network.

Two versions of Duload have been detected -- Worm.P2P.Duload.a and Worm.P2P.Duload.b. Kaspersky said it has recorded instances of the worm in Italy.

Kaspersky has also warned that Duload.a, when activated, also downloads several Trojan programs that could compromise the victim's computer, laying it open to unauthorised remote management.

A computer infected by a Trojan can be employed by a malicious hacker to take part in a Denial of Service attack.

Kaspersky has added a defence against Duload to its Antivirus database, which can be downloaded from the company's Web site.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
41 out of 95 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Backup Engineer

Generation of off-site copies 4. About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve ...

Warwick - SAP System Support Analyst - Level D-00048892

Perform system & client copies. Accenture's Warwick Delivery Centre manages IT services located at Accenture, client and third party locations. Our ...

Technical Application Management - SQL Queries

ITIL Foundation, Windows 2000 / 2003 (analysing event logs, editing registry, reviewing logs, performance monitoring, use of Terminal Services) & a ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment