-
W32/KWBot-A Virus
hmm when I read the thread that monoton made about the kazaa's virus W32/KWBot-A I read all the softwares that were infected of this virus:
Examples of filenames used are :
Star Wars Episode 2 - Attack of the Clones VCD CD1.exe
Spiderman The Movie - The Game.exe
Grand Theft Auto 3 CD1 ISO.exe
ZoneAlarm Firewall Pro.exe
Windows XP Professional iso.exe
Unreal Tournament cracked (works on all servers).exe
University Study Guide (cheat sheet).exe
Quicken Pro 2002 iso.exe
Perl Ultimate Study Guide.exe
Office XP Corporate Ed. iso.exe
Norton Utilities 2002.exe
Microsoft Visual C++ 7.0 iso.exe
MCSE Ultimate Study Guide.exe
Max Payne full iso.exe
Macromedia Flash 5.exe
Kazaa Advertisement Ad remover.exe
DSL Anonymizer.exe
DoS Attacker.exe
DivX Codec 6.0 beta (codec only).exe
Credit Card number generator VERIFIER (cc cc#).exe
cows gone wild.exe
100 XXX Passwords (verified 3-24-02).exe
Grrrrrrrr!!!!!!!!!! When I saw ZoneAlarm Firewall Pro.exe I got :fpissed: very pissed because I download that program from Kazaa!! I know i know it was stupid but i needed a Firewall PRONTO!
I already deleted the Firewall but I know that wont help and I know the virus is still in my PC.
So if any of you guys would help me how to DELETE this virus It would be alot of HELP!!!!
Thanks!
-
Just run an updated virus scanner. It should detect the virus if you have it on your system. Also, if you needed a firewall, you probably should have just downloaded the freeware version of ZoneAlarm... that way you're ensured that it's clean and you don't pirate software... no one likes a software pirate.
AJ
-
Thanks for the Tip avdven! But you think just doing a virus scan in my computer would work and delete the virus just like that?
-
as of around noon today, the only av i found that had a def for it was sophos, norton didn't even mention it. if things have changed please tell me.
"cows gone mad" thats friggen hysterical, i can see them all standing there shaking their utters at the camera. NOOOOO!
-
LilDraganon > Yeah, if you have updated virus defs. and run a full scan, it'll find it and clean it. If it can't clean the files, just quarantine them for later removal.
Tedob1 > The virus was discovered on June 18, 2002, and the definitions from Symantec released the next day (the 19th) can detect and clean infected files. See more info here: http://securityresponse.symantec.com...wbot.worm.html
AJ
-
Yeah I made a scan of the virus and it founded I told it to delete it it said it delete it but i did another scan and it was still there!!! Is like is unremovable :(
-
HeyLilDraganon:
Here is a write-up from Trend Micro that might interest you:
KWBOT
Good luck.
-
Pretty clever of them to disguise it as an Update Build...all the more reason for people to keep track of the legitimate updates that they've downloaded, including the build numbers as well as the time and date of the update. (plus the source of the 'build')
The deletion through the registry may be the best immediate solution, however....then, when the programmers at the AV companies post a patch, run that to get rid of all of the scraps...
Ouroboros
-
Thanks bucket for the website :) but I tried what it said but it wouldn't work but thanks for trying to help me I appreciate that!
If anybody else knows how to remove this virus please help!
-
Thanks avdven, don't know how i missed that. I first heard of it yesterday in a post here.
/me smacks himself a couple of times in the face trying to wake up
-
you should go into your regestry and try deleting all files related to it if you try this then tell me how it works out
-
HeyLildarganon:
Did you ever try getting the evil one out of memory and then run the virus scan?
Just a thought.
:killcompu