Toon posts:

W32.Kwbot.C.Worm

Pagina: 1
Acties:
  • 292 views sinds 30-01-2008
  • Reageer

Verwijderd

Topicstarter
Allereerst wee ik niet als dit topc in de goede forum is geplaatst.Just in case dat niet het geval is...mijn excuses daarvoor.. :-)

But now to the point....
Misschien maakt de titel al duidelijk waarover dit gaat...maar toch nog een kleine uitleg.
Ik heb mijn pc pas opnieuw geformateerd en gereinstalled...
Mijn grootste fout was dat ik niet van begins af aan een virusscanner geinstalled had waardoor ik op dit moment met deze (irritante) wrm in mijn pc zit.Schijnbaar heeft het ook mijn CMD32.exe bestand geinfecteerd waardoor ik nu dus constant een waarschuwing krijg dat da bestand beschadigd is.Ik krijg hem er NIET uit..kan hem ook niet in quarantaine zetten..(handig dat CMD32.exe) Ik heb het vermoeden dat ik het via Kazaa heb opgelopen..las zonet iets over een TANKED virus of zo op de Norton site...

Mijn vraag is...heeft iemand een manier voor mij hoe ik dit op kan lossen?Zou er echt blij mee zijn...:-)

Bij voorbaat mijn dank.. :-)

  • [ash]
  • Registratie: Februari 2002
  • Laatst online: 23-08 12:03

[ash]

Cookies :9

verwijderen ??

De command-line onder windows NT/2000/XP is namelijk 'cmd.exe'

Verwijderd

Ik had ook dat virus en norton heeft het verwijderd, het irritante is nu dat ik telkens bij het opstrarten een melding krijg, "blablabla cmd.exe is niet aangetroffen."

  • [ash]
  • Registratie: Februari 2002
  • Laatst online: 23-08 12:03

[ash]

Cookies :9

Verwijderd schreef op 07 maart 2003 @ 15:05:
Ik had ook dat virus en norton heeft het verwijderd, het irritante is nu dat ik telkens bij het opstrarten een melding krijg, "blablabla cmd.exe is niet aangetroffen."
ff in je registry onder de key in 'LOCAL_MACHINE -> Software -> Microsoft -> Windows -> Current Version-> Run' kijken en daar de verwijzing naar dit bestand te verwijderen.

Verwijderd

das een goeie nog niet over na gedacht, ook geen tijd voor gehad :)

Verwijderd

No additional information available at this time. Symantec Security Response will update this write-up if/when more information is available.


Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.
Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.


These instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


1. Update the virus definitions.
2. Run a full system scan and delete all the files detected as W32.Kwbot.D.Worm.
3. Delete all the registry values added by the worm.

For specific details on each of these procedures, read the following instructions.

1. Updating the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
Running LiveUpdate, which is the easiest way to obtain the virus definitions. These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the Virus Definitions (LiveUpdate), in the "Protection" section, at the top of this writeup.
Downloading the definitions using the Intelligent Updater. The Intelligent Updater virus definitions are posted on U.S. business days (Monday through Friday). You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater), in the "Protection" section, at the top of this writeup.

The Intelligent Updater virus definitions are available here. For detailed instructions on how to download and install the Intelligent Updater virus definitions from the Symantec Security Response Web site, click here.

2. Scanning for and deleting the infected files
a. Start your Symantec antivirus program and make sure that it is configured to scan all the files.
For Norton AntiVirus consumer products: Read the document, "How to configure Norton AntiVirus to scan all files."
For Symantec AntiVirus Enterprise products: Read the document, "How to verify that a Symantec Corporate antivirus product is set to scan All Files."
b. Run a full system scan.
c. If any files are detected as infected with W32.Kwbot.D.Worm, click Delete.

3. Deleting the value from the registry

CAUTION: Symantec strongly recommends that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

a. Click Start, and then click Run. (The Run dialog box appears.)
b. Type regedit

Then click OK. (The Registry Editor opens.)

c. Navigate to each of the following keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

d. For each key, in the right pane, delete the value: winsys

e. Exit the Registry Editor.


Ofwel: http://securityresponse.s...ata/w32.kwbot.d.worm.html


whoops beetje lang gewacht met replyen |:(

[ Voor 2% gewijzigd door Verwijderd op 07-03-2003 15:13 . Reden: traag ]


Verwijderd

ja dat had ik je ook wel kunnen vertellen ;)

Verwijderd

Topicstarter
heeey kijk eens aan..thanks iedereen...en mocht mijn pc daarna zo verrot zijn...I'll sue all your freakin' asses.. :P haha

Nogmaals Thanks :)

Verwijderd

ja best, bel me advocaat maar

Verwijderd

Volgens mij werkt ie voor M$ :+

  • Arno
  • Registratie: Juli 2000
  • Laatst online: 07-09 14:01

Arno

PF5A

Verwijderd schreef op 07 March 2003 @ 15:24:
Volgens mij werkt ie voor M$ :+
Is dat nu weer nodig :? :/

[ Voor 3% gewijzigd door Arno op 07-03-2003 15:25 ]

"Supercars are made to mess around with G-forces, hypercars are made to mess around with G-strings"
Jeremy Clarkson


Verwijderd

Traag schreef op 07 March 2003 @ 15:25:
[...]
Is dat nu weer nodig :? :/
Heej als je het niet uit kan staan negeer het dan gewoon
No hard feelings hoor

Verwijderd

Verwijderd schreef op 07 maart 2003 @ 15:24:
Volgens mij werkt ie voor M$ :+
nee mis

  • F_J_K
  • Registratie: Juni 2001
  • Niet online

F_J_K

Moderator CSA/PB/AI

Front verplichte underscores

Verwijderd schreef op 07 maart 2003 @ 15:27:
Heej als je het niet uit kan staan negeer het dan gewoon
No hard feelings hoor

Heej als je het niet uit kan staan, gebruik je gewoon geen MS producten. M$ is een simpele flame en nergens voor nodig. Lees ook het SA policy er over even door en bedenk wat die reactie voor zin heeft gehad in dit topic: het gaat er ene beetje offtopic door ;)

Het was trouwens niet eens grappig :+

Maar goed. Laten we hier verder enkel ontopic reacties geven aub, discussieren over het gebruik van M$ kan per e-mail :)

'Multiple exclamation marks,' he went on, shaking his head, 'are a sure sign of a diseased mind' (Terry Pratchett, Eric)


Verwijderd

Topicstarter
okay..ik heb de benodigde CMD cmd32.exe besanden verwijderd...en de aanwijzingne opgevolgd totdat ik bij het punt kom dat ik ZELF in de registry moet gaan zoeken naar Kazaa en daar een paar keys moet verwijderen of zo.
kazaa staat NIET vermeld in mijn registry.... :? ik hb verder dus niets meer gedaan...de pc opnieuw opgestart en daarna handmatig wezen virusscannen.
De virusscanner kwam uiteindelijk nog 1 geinfecteerde file tegen en die verwjderde hij.
Alles goed opgelost....

zou je denken...

Ik ga vervolgens de ONLINE-SCAN van Symantec doen...en als ie daarme klaar is..dan geeft ie 91 (!!!!!) geinfecteerde bestanden aan...
Eeeeeh...wie kan mij daarmee helpen???

Zie hieronder een voorbeeld...

Afbeeldingslocatie: http://rockymalvia2.homestead.com/files/infected.jpg

  • Atmosphere
  • Registratie: April 2000
  • Laatst online: 03-12-2025
Je hebt een aantal restore-points waar het virus ook in is opgenomen.
Je zou deze kunnen verwijderen, aangezien ik er niet van uitga dat je terug wil springen naar een geinfecteerd systeem.

-x(Al is de wereld is nog zo klein. Atmosphere vind hem wel fijn)x-; Sys; t-net


Verwijderd

Topicstarter
Aaaaha..okay...en hoe zou k die dan kunnen verwijderen? Hoe komt het dan eignelijk dat de virusscanner op de schijf ze NIET vindt maar de online versie wel..??

  • ThaHandy
  • Registratie: Juli 2001
  • Laatst online: 05-09 12:13

ThaHandy

Discovery Channel

scannen in dosmode? (fat32)

code:
1
2
3
4
5
NAVDX and Long Filenames (LFNs)
-------------------------------
NAVDX, the command-line scanner used for startup scans
and emergency recovery, does not properly display long 
filenames in a DOS box.

een proberen waard?

  • leuk_he
  • Registratie: Augustus 2000
  • Laatst online: 29-08 20:52

leuk_he

1. Controleer de kabel!

Atmosphere schreef op 07 maart 2003 @ 17:01:
Je hebt een aantal restore-points waar het virus ook in is opgenomen.
Je zou deze kunnen verwijderen, aangezien ik er niet van uitga dat je terug wil springen naar een geinfecteerd systeem.
System restore dus uitschakelen. (zit ergens onder de properties van my_computer, of gebruik de help van windows.). Het verbaast me dat symantec dat er niet bijzet.

Need more data. We want your specs. Ik ben ook maar dom. anders: forum, ff reggen, ff topic maken
En als je een oplossing hebt gevonden laat het ook ujb ff in dit topic horen.

Pagina: 1