I was using KaZaA about two weeks ago, than I realized I had the KaZaA worm [W32.Benjamin.worm]. After hours of trying to remove the annoying piece of crap, I found the solution. So I will now be posting up new worms and Removal instructions on this site.
The KaZaA worm - W32\Benjamin.worm Symptoms - Worm first makes up more than 2000 files in your temporary folder. This can take up to four or three gigs of space. Than it somehow sets kazaa to make it share files from there. These files are given popular media names, E.G=
Scary Movie 2.avi.exe
Doom 3.exe, ETC. To remove it however is pretty easy, but easier to get infected with.
Removal Instructions - First open up regedit [Start Menu -> Run -> regedit]. In the left panel, double click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
CurrentVersion>Run
In the right panel, locate and delete the registry entry:
System-Service = "%SysDir%\EXPLORER.SCR" [Were % is the directory]
Again in the left panel, double click the following: HKEY_LOCAL_MACHINE>Software>Microsoft
In the right panel, locate and delete the registry entry:
syscod = "%worm generated set of characters%" [e.g = 548641684984864168, numbers are random]
Restart your computer.
Open Windows Explorer. Right-click Start and click Explore.
Navigate to the Windows system directory, and delete the malware file and the dropped files:
On Windows 9x/ME/XP:
In the left panel, double click the following:
Windows>System
In the right panel, locate and delete the file:
EXPLORER.SCR
Again in the left panel, double click the following:
Windows>Temp
In the right panel, locate and delete the folder:
Sys32
On Windows NT/2000:
In the left panel, double click the following:
WINNT>System32
In the right panel, locate and delete the file:
EXPLORER.SCR
Again in the left panel, double click the following:
WINNT>Temp
In the right panel, locate and delete the folder:
Sys32
Now go over to TrendMicro And use the 'House Call' Online virus scanner [it's free] and scan 'My computer' [all files]. Now delete every virus it detects as benjamin.worm or anything close to it. After this your computer should be all set without the worm. Enjoy.
Thanks to Trend Micro for this handy info