eSecurity Planet   Earthweb  
Images Events Jobs Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
   eSecurity subjects:
E-Security Planet Webcasts:
Keeping Your Data Secure from the Outside In

Beyond Basic Data Security

more Webcasts...


Search EarthWeb Network

internet.commerce
Be a Commerce Partner
GPS Devices
Promotional Pens
SMS Gateway
Send Text Messages
Hurricane Shutters
Promote Your Website
Imprinted Promotions
Remote Online Backup
Disney World Tickets
Desktop Computers
Promotional Golf
Compare Prices
Promotional Gifts
Compare Prices

esecurityplanet : Online Threats & Alerts: Virus Alert: New Worm Spreads Through KaZaA, IRC

Stay up to date with the latest storage technology news, advice, and information! Visit Internet.com/Storage.

  Rethinking the Datacenter
Sponsored by HP
Today's datacenters need to increase utilization, get control over power and cooling costs, and align with business objectives. Download this eBook to learn about the challenges facing the data center in a world where digital information is growing at a torrid pace and costs are being held in check. Learn more. »
 
  Putting the Green into IT
Sponsored by HP
Electricity use in data centers is skyrocketing, sending energy bills through the roof, creating environmental concerns and generating negative publicity. "Going Green" means looking to technologies like virtualization, energy-efficient chips and racks, and implementing policies that extend beyond the data center. Learn more. »
 
  Managing the Modern Network
Sponsored by HP
In a global economy where information crosses the globe in an instant, and where Web-based applications power business, it's more important than ever to ensure your network is safe from threats and optimized to deliver the data your business needs. »
 
  Evaluating Software as a Service for Your Business
Sponsored by Webroot
Is Software as a Service just hype, or is something really going on here? See if your company can benefit as SaaS tries to change the face of the enterprise. »
 
  Is Your Disaster Recovery Plan Good Enough?
Sponsored by HP
Preparing for a disaster is more often than not part of the storage planning process, and it is one of the most difficult tasks, since it includes local hardware and software, networking equipment, and a test plan. Learn how to get disaster recovery right. »
 

Related Articles
Virus Alert: Mass Mailing VBS Virus a Low Risk
Virus Alert: Trojan Has Malicious Capabilities
Virus Alert: Waterworks Worm Overwrites Files
Virus Alert: Backdoor CHCP Discovered
Virus Alert: Troj/Slanret Seeks Hidden System Privileges
eSecurity Glossary
biometrics
encryption
keylogger
malware
phishing
RFID
security
spyware
virus
worm
Search for more eSecurity terms ...
FREE Tech Newsletters

Virus Alert: New Worm Spreads Through KaZaA, IRC
February 11, 2003
By eSecurityPlanet Staff

Anti-virus developer Panda Software on Tuesday reported the appearance of Kazoa.C, alias Gool, a new worm/Trojan programmed in Delphi that spreads through the popular file sharing application KaZaA and through the chat program IRC.

Kazoa.C/Gool impacts Windows XP/2000 Pro/NT/Me/98/95. When installed on the affected computer, it changes entries in the Windows Registry in order to ensure that it is run every time Windows is started up. Kazoa.C/Gool also opens a port (usually 31337) and sends out the IP address of the affected computer via the Internet, leaving the computer vulnerable to remote attacks. An attacker would be able to carry out the following actions on the affected computer:

  • Send messages
  • Hide the Taskbar that appears on the desktop
  • Delete the CMOS
  • Provoke an error in the computer
  • Use up memory
  • Handle and send files
  • Capture screens and keystrokes
  • Obtain data on the operating system and characteristics of the machine.
  • Kazoa.C/Gool modifies the default shared file folder in the application KaZaA and creates a large number of files, which contain the worm's code, with names like Catherine Zeta Jones, Pamela Anderson, Sandra Bullock, Shakira or Pokemon.

    This worm tries to trick users into running these files by suggesting that they contain erotic photos, cracks for hacking operating systems etc. These files always have a double extension, but the real extension is .exe. If a computer is not configured to show all file extensions, these icons will be displayed as inoffensive jpg or .txt files. When the executable file is run (by double-clicking on the icon), Kazoa.C/Gool displays a screen.

    If this malicious code detects the presence of certain antivirus and security programs, it terminates them. Find out if your computer is infected by checking whether the following files are in the Windows system directory:

    EXPLORER.EXE
    Explorer.VBS
    RealWayToHack.exe

    Panda Software is giving this virus a very low threat rating. For technical details, visit this page.

    JS/Seeker-C Trojan Attempts to Disrupt IE

    JS/Seeker-C is a malicious script that attempts to modify Internet Explorer settings, such as the Start Page and Search setting, according to Sophos.

    It appears the script has been designed to do this to redirect traffic to Web sites (typically, but not limited to pornographic sites). The Trojan writes to registry values under:

    HKCU\Software\Microsoft\Internet Explorer.

    JS/Seeker-C does not forward itself to other users, but has to be deliberately installed on a Web site or forwarded via email from a malicious user.

    For removal instructions, visit this Sophos page.

    W32.Yalat.Worm Spreads via MAPI

    W32.Yalat.Worm attempts to spread by using MAPI and by copying itself to shared folders. It also attempts to stop the processes of some antivirus programs. However, the worm does not work as intended due to bugs in the code. For technical details, visit this Symantec page.

    W32.HLLW.Maax Worm Chooses File-Sharing Programs, E-mail to Spread

    Symantec is also reporting the appearance of the W32.HLLW.Maax worm, which uses several file-sharing programs and Microsoft Outlook to spread.

    The file-sharing programs include KaZaA, Morpheus, Edonkey, Grokster, Limewire and Bearware. The e-mail would have a subject chosen from a predetermined list and an attachment with a filename of Tca.exe.

    This worm attempts to terminate the processes of antivirus and security- related programs. It is written in Microsoft Visual Basic version 6 and is packed with UPX. Read the technical details here.

    Compiled by Esther Shein.

     

    Tools:
    Add www.esecurityplanet.com to your favorites
    Add www.esecurityplanet.com to your browser search box
    IE 7 | Firefox 2.0 | Firefox 1.5.x
    Receive news via our XML/RSS feed

    Online Threats & Alerts Archives

    eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
    What's The Future Of IT? Find Out By Reading "IT in 2018" Now. Free Registration Required.
    Whitepaper: Enterprise Information Integration--Deployment Best Practices for Low-Cost Implementation
    Trend Micro InterScan Trial – Block Spam and Viruses Today
    HP eBook: Using Business Service Management (BSM) to Manage Your Business Applications



    JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
    Microsoft Article: 7.0, Microsoft's Lucky Version?
    Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
    Avaya Article: How to Feed Data into the Avaya Event Processor
    Microsoft Article: Install What You Need with Windows Server 2008
    HP eBook: Putting the Green into IT
    Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
    Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
    Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
    Avaya Article: Setting Up a SIP A/S Development Environment
    IBM Article: How Cool Is Your Data Center?
    Microsoft Article: Managing Virtual Machines with Microsoft System Center
    HP eBook: Storage Networking , Part 1
    Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    Intel Video: Are Multi-core Processors Here to Stay?
    On-Demand Webcast: Five Virtualization Trends to Watch
    HP Video: Page Cost Calculator
    Intel Video: APIs for Parallel Programming
    HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
    Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Sun Download: Solaris 8 Migration Assistant
    Sybase Download: SQL Anywhere Developer Edition
    Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
    Red Gate Download: SQL Compare Pro 6
    Iron Speed Designer Application Generator
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
    eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
    IBM Article: Collaborating in the High-Performance Workplace
    HP Demo: StorageWorks EVA4400
    Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
    Microsoft How-to Article: Get Going with Silverlight and Windows Live
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES