Home Malware Programs Worms Worm.Benjamin.a

Worm.Benjamin.a

Posted: July 15, 2007

Threat Metric

Threat Level: 9/10
Infected PCs: 49
First Seen: July 24, 2009
Last Seen: January 20, 2022
OS(es) Affected: Windows

Benjamin.a is a worm that propagates via the KazaA file sharing network. Once it is executed, Worm.Benjamin.a will modify your default KazaA shared directory to point to its location. Then Worm.Benjamin.a will copy itself randomly creating names from a list that it carries, based on movie names, album names, and software product names. In addition, Worm.Benjamin.a may also show fake error messages that will warn about "invalid pointer operations".

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



777.exe File name: 777.exe
Size: 643.02 KB (643021 bytes)
MD5: f157f33adbb0d808d97ddc9308695d9d
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
7.exe File name: 7.exe
Size: 616.79 KB (616794 bytes)
MD5: c46f2100f5a6934f3c50710b9a5d76f1
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
69.exe File name: 69.exe
Size: 620.29 KB (620294 bytes)
MD5: 285806ff077d73301fa59086d968fc0a
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
4.exe File name: 4.exe
Size: 631.22 KB (631224 bytes)
MD5: d55bdb9430a4c9d6958de34064f30365
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
8.exe File name: 8.exe
Size: 620.16 KB (620165 bytes)
MD5: 00a4ab8c946de9d4e42d29ef2126f27a
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
5.exe File name: 5.exe
Size: 637.56 KB (637561 bytes)
MD5: 7da215d9dc7ea90e7e419b9dd5afb8bb
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
21.exe File name: 21.exe
Size: 609.53 KB (609533 bytes)
MD5: 6efc54ce3d06b40c6360fea5d3573b92
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
2.exe File name: 2.exe
Size: 629.01 KB (629018 bytes)
MD5: 20137d24078bafd2a0ec416b1bd2d883
Detection count: 82
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
2002.exe File name: 2002.exe
Size: 609.12 KB (609129 bytes)
MD5: 7bf4ad69eb9975659233f367f3e7769b
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1999.exe File name: 1999.exe
Size: 654.66 KB (654662 bytes)
MD5: 5536f0fc08fa017433d64c5805ae07f4
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1503 A.D. - The New World-installer.exe File name: 1503 A.D. - The New World-installer.exe
Size: 611.64 KB (611642 bytes)
MD5: a630b5bd38ec5e40a4e66225faf2abce
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
$1.exe File name: $1.exe
Size: 630.94 KB (630940 bytes)
MD5: 6967a3f21f94eee28547747c3a113c3d
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
13 Geister-divx-full-downloader.exe File name: 13 Geister-divx-full-downloader.exe
Size: 650.21 KB (650218 bytes)
MD5: 4b2606ae31da0de5e090b2d29acf6980
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
$2.exe File name: $2.exe
Size: 627.97 KB (627975 bytes)
MD5: c1f471ec8dec92de3ff5b627ab5959d3
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
0.exe File name: 0.exe
Size: 616.02 KB (616024 bytes)
MD5: 25030684a1d0d1c9a819f3fe23ffa3a0
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
$30 FOR FREE.exe File name: $30 FOR FREE.exe
Size: 606.64 KB (606640 bytes)
MD5: ca8d227c8f24e0b19388dad92b713183
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
100000.exe File name: 100000.exe
Size: 615.63 KB (615639 bytes)
MD5: 305cbc18dbf8ddf1b7279774605530ea
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
10000.exe File name: 10000.exe
Size: 648.01 KB (648011 bytes)
MD5: fd2dbe0c60e1b463738b8f3a72c90197
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1000000.exe File name: 1000000.exe
Size: 608.09 KB (608091 bytes)
MD5: 96481d9c42cc43690eb46e40ca3bba4a
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
$$FREE$$.exe File name: $$FREE$$.exe
Size: 655.82 KB (655824 bytes)
MD5: 5a18c3c1484a2e3972bb6e1d4aa0a440
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
$30.exe File name: $30.exe
Size: 626.49 KB (626494 bytes)
MD5: e177f81892ada520c9d48d510f711672
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
E:\VirusShare_00000\VirusShare_3a6f312d0ef225d89b271c3e7604cdc6 File name: VirusShare_3a6f312d0ef225d89b271c3e7604cdc6
Size: 606.52 KB (606520 bytes)
MD5: 3a6f312d0ef225d89b271c3e7604cdc6
Detection count: 7
Path: E:\VirusShare_00000\VirusShare_3a6f312d0ef225d89b271c3e7604cdc6
Group: Malware file
Last Updated: January 20, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

Run keysSystem-Service

Additional Information

The following directories were created:
%WINDIR%\Temp\sys32
Loading...