Results 1 to 4 of 4

Thread: How does Worm/Kibuv.B infect the system?

  1. #1
    Join Date
    Nov 2009
    Posts
    824

    How does Worm/Kibuv.B infect the system?

    My operating system is Windows XP Service Pack 2 and I have currently got the scare of this Worm/Kibuv.B virus on my system. I do not have much knowledge about how these infections spread. I have learnt about a few and now since Worm/Kibuv.B has entered my own system, I want to know how Worm/Kibuv.B actually infects the system? What level of threat does it posses and what are its eradicating techniques? Please reply because my system is on a hunt by an infection I do not know how remove.

  2. #2
    Join Date
    Feb 2008
    Posts
    2,635

    Re: How does Worm/Kibuv.B infect the system?

    I know how Worm/Kibuv.B infects the system. It starts on the FTP server with the port number 7955. It will enter any username and password, which will be accepted. Even if the request for the file is not made, the copy/duplicate of this worm is send.
    The following mechanisms are used by Worm/Kibuv.B to spread or multiply into the system:
    1. RPC DCOM Buffer Overflow
    2. Backdoors created by Weird and Beagle
    3. IIS 5.0 WebDav vulnerability
    4. Sasser FTP server overflow
    5. Messenger Service Buffer Overrun
    6. UPnP Buffer Overflow
    7. LSASS vulnerability

  3. #3
    Join Date
    May 2008
    Posts
    2,945

    Re: How does Worm/Kibuv.B infect the system?

    You need not worry about how this Worm/Kibuv.B infects the system because it has a very low damage level. But, since it is a worm it distributes easily, that means it has a high distribution level. So, if you wont remove this worm from your system, it will use all your resources and make your system very slow amd then formatting will be the only solution left.
    Just follow the simple steps to get rid of this worm:
    • Since you are using Windows XP, first you need to disable the system restore option.
    • Then, the virus definitions need to be updated. It is recommended to NORTON, if possible in such cases.
    • The computer need to be restarted in a VGA or SAFE MODE.
    • Now, enable a full system scan and remove all the infections with the name Worm/Kibuv.B
    • Lastly, all the changes made to the registry by the worm need to be reversed.

  4. #4
    Join Date
    Jan 2006
    Posts
    3,792

    Re: How does Worm/Kibuv.B infect the system?

    The technique how Worm/Kibuv.B infects the system is that port number 420 is installed by a backdoor so that it can receive remote commands. This worm gets into the IRC server and looks for an opportunity to attack like any command or such. A link is also send to the entrants that are new to the IRC channel.
    A scan in safe mode will eradicate it easily.

Similar Threads

  1. How to protect system from ramnit worm
    By KDoyle in forum AntiVirus Software
    Replies: 6
    Last Post: 07-02-2012, 12:55 AM
  2. How to remove Nachia worm from system
    By Aadeshh in forum Networking & Security
    Replies: 4
    Last Post: 25-02-2010, 02:02 AM
  3. How to protect system from Witty worm
    By WinDoWLoCuS in forum Networking & Security
    Replies: 4
    Last Post: 21-02-2010, 04:52 AM
  4. System infected with W32/MoFei.worm
    By Pratyush in forum Networking & Security
    Replies: 5
    Last Post: 12-01-2010, 06:18 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,168,567.59069 seconds with 17 queries