General discussion


Worm.Win32.SdBoter.g, W32.Kwbot.Worm

Win32 worm

W32/KWBot-G is a worm which exploits the users of peer-to-peer networks.
When first executed the worm will copy itself to the Windows system folder as svchost64.exe. It will then create the following registry entry so that the copy is run each time Windows is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Run DLL = svchost64.exe


Discussion is locked
Reply to: W32/KWBot-G
PLEASE NOTE: Do not post advertisements, offensive materials, profanity, or personal attacks. Please remember to be considerate of other members. If you are new to the CNET Forums, please read our CNET Forums FAQ. All submitted content is subject to our Terms of Use.
Reporting: W32/KWBot-G
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.

CNET Forums