Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

WORM_KWBOT.E

Feb 4, 2004 4:09AM PST

Virus type: Worm

Destructive: No

Aliases: W32.Kwbot.Worm

Description:


This worm drops copies of itself in the Windows system folder. It also drops several malicious files detected as the following:


BKDR_SDBOT.GEN
WORM_LOVGATE.F
It modifies the Windows registry so that it runs at every system startup and also to register some of its dropped files as service processes.

Using a list of user names and passwords, this worm attempts to gain access to machines connected in the network. Once it has successfully logged on to a system, this malware drops a copy of itself using the file name NETSERVICES.EXE.

It runs on Windows ME, NT, 2000 and XP.

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_KWBOT.E

Discussion is locked