kazaa at it again

zapper

Inactive User
Joined
Aug 23, 2001
Messages
1,095
Reaction score
0
Location
england
i see on kazaa there at it again putting wrong files took all day to get celine dion;s new album shxxt is it the record company;s that do this ?
 
i know m8,i d/loaded the new hulk film the other night,luckily quite a few had the file so it took about 6 hrs to d/load,when i checked it the next day it was a porn film..:mad: ,what a waste of time........zooropa
 
i know as well i downloaded what i thought was a film but it turned out to be a 3 hour swedish porno what a bitch
and i had to watch it all just in case the film i wanted was tagged on the end
lol
 
same here m8 lmao,i had to watch over 3 hours....:eek: and then again just incase i had missed the film i wanted :rolleyes:
 
i tried to d/l 'swedish l**bians meet debbie who 'did' dallas' took 7 weeks to d/l and d'ya know what ? ....

it was the ferkin Hulk !!!
 
just think of the poor bestard that thought he had downloaded the hulk
 
i use a handy prog called avi previewer that enables you to watch files before they are done and its a free download

h**p://www.avipreview.com/index.htm

just replace the stars
 
While we are on the subject about kazaa their is 90 fake files which is part of a virus doing the rounds here is some info for you good folk to help keep you safe

a virus called tanked is on kazaa which copies 90 virus fake files on your system from a temp dir
i noticed this as it has a list of files with most of the fake virus names ... like gutar cords 5.5... you wont be able to see these files as they wont be in your shared files dir ,they will be in a temp dir....
what to do !!!
get yourself a uptodate virus scanner


infofile
http://securityresponse.symantec.com/avcenter/venc/data/w32.kwbot.c.worm.html

please help others on the kazaa network by doing a search for Guitar Chords Library its only the 5.5 version (there is no such file out there)

--------------------------------------------------------------------------------
This is aworm virus spreading via the Kazaa file sharing network.
The worm has a powerful backdoor routine which connects to an IRC channel and listens to commands from its "master".

The worm itself is a Windows PE EXE file about 100Kb of length written in Microsoft Visual C++, the worm is compressed by UPX file compression utility and then encrypted with "Krypton" Win EXE files encryptor.

When infected file starts, the installation routine gets control.

Installation
While installing the worm copies itself to Windows system directory with different names (see below) and registers that file in two system registry auto-run keys.
The worm copy names are:

"Tanked.11": "system32.exe"
"Tanked.13": "winsys.exe"
"Tanked.14": "cmd32.exe"

The registry keys are:
"Tanked.11":

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SystemSAS = system32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
SystemSAS = system32.exe

"Tanked.13":
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
WinSys = winsys.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
WinSys = winsys.exe

"Tanked.14":
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CMD = cmd32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
CMD = cmd32.exe

Spreading
The worm copies itself to Kazaa directory with following names:
'Battlefield1942_bloodpatch.exe'
'Unreal2_bloodpatch.exe'
'UT2003_bloodpatch.exe'
'AquaNox2 Crack.exe'
'NBA2003_crack.exe'
'FIFA2003 crack.exe'
'C&C Generals_crack.exe'
'UT2003_keygen.exe'
'UT2003_no cd (crack).exe'
'Age of Empires 2 crack.exe'
'Anno 1503_crack.exe'
'C&C Renegade_crack.exe'
'Diablo 2 Crack.exe'
'Gothic 2 licence.exe'
'GTA 3 Crack.exe'
'GTA 3 patch (no cd).exe'
'Hitman_2_no_cd_crack.exe'
'Mafia_crack.exe'
'Neverwinter_Nights_licence.exe'
'NHL 2003 crack.exe'
'WarCraft_3_crack.exe'
'Splinter_Cell_Crack.exe'
'Battlefield1942_keygen.exe'
'Winamp 3.8.exe'
'MediaPlayer Update.exe'
'UT2003_patch.exe'
'ACDSee 5.5.exe'
'DivX Video Bundle 6.5.exe'
'Global DiVX Player 3.0.exe'
'QuickTime_Pro_Crack.exe'
'KaZaA Lite (New).exe'
'iMesh 3.7b (beta).exe'
'iMesh 3.6.exe'
'KaZaA Hack 2.5.0.exe'
'DirectDVD 5.0.exe'
'Flash MX crack (trial).exe'
'Ad-aware 6.5.exe'
'WinZip 9.0b.exe'
'SmartFTP 2.0.0.exe'
'ICQ Lite (new).exe'
'ICQ Pro 2003b (new beta).exe'
'ICQ Pro 2003a.exe'
'AOL Instant Messenger.exe'
'Download Accelerator Plus 6.1.exe'
'Trillian 0.85 (free).exe'
'MSN Messenger 5.2.exe'
'Network Cable e ADSL Speed 2.0.5.exe'
'mIRC 6.40.exe'
'GetRight 5.0a.exe'
'Pop-Up Stopper 3.5.exe'
'Yahoo Messenger 6.0.exe'
'KaZaA Speedup 3.6.exe'
'Nero Burning ROM crack.exe'
'WindowBlinds 4.0.exe'
'Animated Screen 7.0b.exe'
'Living Waterfalls 1.3.exe'
'Matrix Screensaver 1.5.exe'
'Popup Defender 6.5.exe'
'Space Invaders 1978.exe'
'SmartRipper v2.7.exe'
'TweakAll 3.8.exe'
'DVD Copy Plus v5.0.exe'
'Serials 2003 v.8.0 Full.exe'
'Zelda Classic 2.00.exe'
'Need 4 Speed crack.exe'
'Links 2003 Golf game (crack).exe'
'Netfast 1.8.exe'
'Guitar Chords Library 5.5.exe'
'DVD Region-Free 2.3.exe'
'Cool Edit Pro v2.55.exe'
'Coffee Cup Free HTML 7.0b.exe'
'Clone CD 5.0.0.3.exe'
'Clone CD 5.0.0.3 (crack).exe'
'Nimo CodecPack (new) 8.0.exe'
'Business Card Designer Plus 7.9.exe'
'Steinberg_WaveLab_5_crack.exe'
'Hot Babes XXX Screen Saver.exe'
'FreeRAM XP Pro 1.9.exe'
'IrfanView 4.5.exe'
'Audiograbber 2.05.exe'
'WinOnCD 4 PE_crack.exe'
'Final Fantasy VII XP Patch 1.5.exe'
'BabeFest 2003 ScreenSaver 1.5.exe'
'PalTalk 5.01b.exe'
'DirectX Buster (all versions).exe'
'DirectX InfoTool.exe'
'Unreal2_crack.exe'
'FlashGet 1.5.exe'
'Babylon 3.50b reg_crack.exe'
'mp3Trim PRO 2.5.exe'

Other
The worm has "copyright" text strings:
"Tanked.11":

T~Drone.11
t69 [sd]v0.5b TankEd.11
[sd]v0.5b TankEd.11 by [sd]

"Tanked.13":
T~Drone.13
t69 [sd]v0.5b TankEd.13
[sd]v0.5b TankEd.13 by [sd]

"Tanked.14":
T~Drone.14
t69 [sd]v0.5b TankEd.14
[sd]v0.5b TankEd.14 by [sd]

hope this some help to you all....baz
 
and to add to that m8ys.......watch out for this one too W32.HLLP.Handy

W32.HLLP.Handy is a virus that prepends itself to the files in the KaZaA download folder and the Internet Explorer default download folder. It is written in the Borland Delphi programming language and is compressed with UPX.

Also Known As: W32/HLLP.Hantaner [McAfee], Win32.HLLP.Hantaner [KAV], PE_HANTANER.A [Trend], Win32.HLLP.Handy [CA], W32/Hantaner-A [Sophos]
Type: Virus
Infection Length: 24,064 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected: Macintosh, OS/2, UNIX, Linux

Just letting u guys know,

Gary
 
yea gaz ive intecepted that one but found it a pussy since i have updated my norton (as i was downloading a file it had the HLLP hataner virus on it and it was disinfected before i got the chance to cancle the download)

it seems kazaa is a good network for software & viruses (me thinks its music companys tryin to kill kazaa from the inside!!!) due to the files being designed exclusively for the kazaa network, there is a lot of fake films too with just a blank screen (johnny english for one!!!)
good job i use avi previewer to check it as it downloads and if i find its not what it says on the tin ,its deleted (unless its swedish sheep pr0n LOL) ... baz
 
The hub will always be the best as everything on theres always what it says it is :)
 
Is it true that new downloads of the kazaa exe file they request a credit card??
 
Never asked me for credit card details when I downloaded Kazaa the other day. Mind you there are variations of Kazaa that you can purchase e.g lite and gold. I'm looking for access to Kazaa without the annoying "save" feature that keeps chucking adverts at you. I tried removing it using Norton cleansweep but had problems after that. Anyone any ideas?

Rob.
 
Back
Top