Antivirus and Security Software from Sophos

Sophos blogs

W32/Kingdom-A

Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Please read the instructions for removing worms.

You should disable sharing on C:\Windows\Sys32 (right-click this folder in Explorer, select Sharing, then disable sharing).

Uninstall KaZaA, then clean the registry. At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export Range' panel, click 'All', then save your registry as Backup.

Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the key:

HKU\[code number]\Software\KaZaa

and delete it if it exists.

If you wish to use KaZaA, reinstall it.

More Information

W32/Kingdom-A is a worm which attempts to spread over KaZaA Peer-to-Peer (P2P) file sharing networks.

Upon execution, the worm drops itself to C:\Windows\Sys32 as kingdom-hearts.exe and modifies the following registry entries

HKCU\Software\KaZaa\LocalContent\DisableSharing

HKCU\Software\KaZaa\LocalContent\Energy

The above changes enable P2P file sharing under KaZaA and make C:\Windows\Sys32 a shareable folder.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer