Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please read the instructions for removing worms.
You should disable sharing on C:\Windows\Sys32 (right-click this folder in Explorer, select Sharing, then disable sharing).
Uninstall KaZaA, then clean the registry. At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export Range' panel, click 'All', then save your registry as Backup.
Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the key:
HKU\[code number]\Software\KaZaa
and delete it if it exists.
If you wish to use KaZaA, reinstall it.
More Information
W32/Kingdom-A is a worm which attempts to spread over KaZaA Peer-to-Peer (P2P) file sharing networks.
Upon execution, the worm drops itself to C:\Windows\Sys32 as kingdom-hearts.exe and modifies the following registry entries
HKCU\Software\KaZaa\LocalContent\DisableSharing
HKCU\Software\KaZaa\LocalContent\Energy
The above changes enable P2P file sharing under KaZaA and make C:\Windows\Sys32 a shareable folder.

