1. Home
  2. Computing & Technology
  3. Antivirus Software

A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | Encyclopedia Home
Also see: Hoax Encyclopedia | Repair Center | News Briefs | Glossary | Infected Attachments | Prevention Center

Related Links

Battle for File-Shares
BitDefender's Description

K0wbot
Aliases: Backdoor.K0wbot, kwbot, W32.Kwbot.Worm

Type: Peer-to-Peer file sharing virus
Systems Affected: Windows systems using the KaZaA network.
Payload: Creates file share on affected users' drives; contains remote access capabilities
ITW: Yes
Origin:

Description: According to BitDefender, K0wbot creates a copy of itself, named EXPLORER32.EXE, in the C:\Windows\System subfolder. K0wbot modifies the registry, adding the value 'EXPLORER32.EXE' to the following registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

This allows the worm to load upon Windows startup. The K0wbot worm also enables sharing of KaZaA files (assuming it has been disabled) and copies itself to the KaZaA shared folder using names of various software, movie, and music titles.

Though the original K0wbot does not have a malicious payload, the worm does include the ability to self-update and provides remote access via the IRC network.

About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >