true, benjamin spreads through kazaa specifically, whereas other viruses can use kazaa as a medium for spreading benjamin uses kazaa as its main way of spreading.. so if you use kazaa, and especially if you have downloaded a file that has the words full downloader in the name. you most likely have benjamin, or one of the porn dialer viruses. these "full downloader" files are very common on kazaa and even morpheus, and most if not all of them are virii....
here is info on benjamin too
W32/Benjamin.worm Corporate User : Low-Profiled
Home User : Low-Profiled
Internet Worm Information
Discovery Date: 05/16/2002
Type: Internet Worm
Release Date: 4204
Minimum Engine: 4.1.50
Description Added: 05/20/2002
Description Modified: 05/22/2002 11:30 AM (PT)
Internet Worm Characteristics:
This threat is considered a Low-Profiled risk as it is not wide-spread and has gotten media attention.
When this worm is run, it copies itself to %WINDIR%\SYSTEM\EXPLORER.SCR, where %WINDIR% is the directory Windows is installed in. Then it adds the registry key:
To spread, the worm requires that the Kazaa software is installed on the machine. It creates a directory called %WINDIR%\TEMP\SYS32, and changes the Kazaa settings so that remote users can download from this directory. Then it copies itself to that directory under many different names which other users may search for. The size of these files can vary since the worm pads them with garbage bytes. This method of spreading is comparable to the VBS/GWV worm.
Presence of EXPLORER.SCR and registry key pointing to it.
Presence of %WINDIR%\TEMP\SYS32 and many files inside.
Method Of Infection
Since this worm offers itself over the Kazaa network under names that users may find tempting, users who are not infected may download and run the worm from infected machines, and thus spread the worm themselves.
Use current engine and DAT files for detection and removal.
Additional Windows ME/XP removal considerations
Win32/Kazaa.Benjamin worm (ESET)
if you do what I suggested it is not my fault...