Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically

Short description
Win32/Zaka.N is a worm that spreads via P2P networks.
Installation
When executed the worm copies itself in the following locations:
  • %windir%sendtoKilme.exe
  • %windir%all usersstart menuprogramsstartupKilll.e
This causes the worm to be executed on every system start.
Spreading
The worm copies itself into the root folders of the following drives C: - Z: using the following name:
  • Killme.exe
Spreading via P2P networks
Win32/Zaka.N is a worm that spreads via P2P networks.

The worm searches for shared folders of the following programs:
  • Kazaa
It tries to place a copy of itself into the folders.

The following filenames are used:
  • Kaboomall Openthisone.exe
  • Kazaaa Kaboon_new_version_en.exe
  • My_Sister_Naked!!!.exe
  • Naked_teen_new!.exe
  • ry_teen_girl_new.exe
Other information
The worm may display the following message:
  • Error?????????????
The worm may set the following Registry entries:
  • [HKEY_LOCAL_MACHINESoftwareMicrosoftWindows
    CurrentVersionRun]
    "%filename%" = "%filepath%"
A string with variable content is used instead of %filename%, %filepath% .