PDA

View Full Version : Worm/P2P.Spear.i Sperding thourgh KaZaA, eDonkey2000, and Morpheus etc.


ROCKAMANIAC
January 2nd, 2003, 01:54 PM
Yet another Worm in Fastrack and now on Edonkey aswell what can we say well i got the info from www.centralcommand.com
i didnt notice it on any other websites for example panda, norton, grisoft etc. just yet but heres the details !

Don't wait to be a victim of a computer virus attack, get Vexira Antivirus today.
Description:
------------
Worm/P2P.Spear.i is a Peer-2-Peer (P2P) worm that spreads through the use of many of the popular file sharing programs, including: KaZaA, eDonkey2000, and Morpheus.

If executed, the worm copies itself in the following directories:

- C:\Program Files\edonkey2000\incoming\Matrix2 ScreenSaver.exe
- C:\Program Files\edonkey2000\incoming\Die another Day Screener.exe
- C:\Program Files\edonkey2000\incoming\(c) by Mesut.exe
- C:\Program Files\Kazaa\My Shared Folder\Matrix2 ScreenSaver.exe
- C:\Program Files\Kazaa\My Shared Folder\Die another Day Screener.exe
- C:\Program Files\Kazaa\My Shared Folder\(c) by Mesut.exe
- C:\Program Files\morpheus\My Shared Folder\Matrix2 ScreenSaver.exe
- C:\Program Files\morpheus\My Shared Folder\Die another Day Screener.exe
- C:\Program Files\morpheus\My Shared Folder\(c) by Mesut.exe

Worm/P2P.Spear has been designed to spread only if it has one of the following names: Matrix2 ScreenSaver.exe, Die another Day Screener.exe or (c) by Mesut.exe. For example, if the file was renamed to file.exe, it would not copy itself to the locations specified above. Further more, it only copies itself if those locations already exist.

overdo
January 2nd, 2003, 02:17 PM
why do they bother? do the ppl who create these things think its funny? ah well thx for the info, perhaps this should be posted in the news section if its not already there?

ROCKAMANIAC
January 2nd, 2003, 02:37 PM
People who make these SUCK i agree ! and hey no problem i like helping people i guess lol

BlueLieu
January 2nd, 2003, 02:54 PM
With the improbability of this being traced to the originator, ever wonder if the RIAA people do this?

Totally illegal of course but possible.

ROCKAMANIAC
January 2nd, 2003, 03:00 PM
by the way does anyone know where to get Vexira Antivirus Retail i coudnt find it on kazaa. emule, shareaza and ares Any ideas

overdo
January 2nd, 2003, 04:55 PM
Originally posted by ROCKAMANIAC
by the way does anyone know where to get Vexira Antivirus Retail i coudnt find it on kazaa. emule, shareaza and ares Any ideas
Not allowed to post links here but pm me telling me what u want

@BlueLieu - lol wouldn't surpise me at all

EDIT:
http://www.avp.ch/avpve/worms/kazaa/spear.stm
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.yoohoo.c.html - note this worm is obviously not new and i'm now assuming that all major anti-virus programs remove this worm

{SH0CK}_v00d00_
February 1st, 2003, 11:30 AM
Worms, Trojans and Virii are rife on P2P as a whole, assuming u use a decent Antivirus package, u shouldnt really worry, i personally prefer pccillin and it has caught everything ive thrown at it so far.

If you are still totally worried about it, just dont use p2p :)