Internet Security Source provides daily updates on Internet Threats, Viruses, Worms, Trojans, Spyware and Adware. Subscribe to our newsletter and receive daily updates on threats on the internet.
Kazaap
Friday, June 27 2008
Symantec Security Response
http://www.symantec.com/business/security_response/index.jspKazaap
Updated: December 4, 2006 6:05:14 AM
Type: Misleading Application
Risk Impact: Medium
Systems Affected: Windows 98, Windows 95, Windows XP, Windows NT, Windows Server 2003, Windows 2000
SUMMARY
Behavior
Kazaap is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats.Protection
- Initial Rapid Release version December 1, 2006
- Latest Rapid Release version May 13, 2008 revision 038
- Initial Daily Certified version December 1, 2006
- Latest Daily Certified version May 13, 2008 revision 048
- Initial Weekly Certified release date December 6, 2006
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
TECHNICAL DETAILS
Kazaap is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats.When Kazaap is executed it creates and populates the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kazaap Adware & Spyware Remover
HKEY_LOCAL_MACHINE\SOFTWARE\FoxIE
HKEY_LOCAL_MACHINE\SOFTWARE\Kazaap
HKEY_CURRENT_USER\Software\Kazaap
It then creates the following files:
%UserProfile%\Desktop\Kazaap.lnk
%UserProfile%\Local Settings\Temp\~DF4350.tmp
%UserProfile%\Start Menu\Programs\Kazaap\Kazaap.lnk
%UserProfile%\Start Menu\Programs\Kazaap\Secure Update.lnk
%UserProfile%\Start Menu\Programs\Kazaap\Uninstall Kazaap.lnk
%ProgramFiles%\Kazaap\DB\pests.dtx
%ProgramFiles%\Kazaap\Kazaap.exe
%ProgramFiles%\Kazaap\Resources\Updates\index.dat
%ProgramFiles%\Kazaap\uninst.exe
%ProgramFiles%\Kazaap\update.exe
It then may populate the following directories with files downloaded by the application updater:
%ProgramFiles%\Kazaap\Resources
%ProgramFiles%\Kazaap\Resources\Updates
ContrWare
Virus-Kill
DoctorAdwarePro
WinSpy
WinFixer

