• Starting today August 7th, 2024, in order to post in the Married Couples, Courting Couples, or Singles forums, you will not be allowed to post if you have your Marital status designated as private. Announcements will be made in the respective forums as well but please note that if yours is currently listed as Private, you will need to submit a ticket in the Support Area to have yours changed.

  • CF has always been a site that welcomes people from different backgrounds and beliefs to participate in discussion and even debate. That is the nature of its ministry. In view of recent events emotions are running very high. We need to remind people of some basic principles in debating on this site. We need to be civil when we express differences in opinion. No personal attacks. Avoid you, your statements. Don't characterize an entire political party with comparisons to Fascism or Communism or other extreme movements that committed atrocities. CF is not the place for broad brush or blanket statements about groups and political parties. Put the broad brushes and blankets away when you come to CF, better yet, put them in the incinerator. Debate had no place for them. We need to remember that people that commit acts of violence represent themselves or a small extreme faction.
  • We hope the site problems here are now solved, however, if you still have any issues, please start a ticket in Contact Us

  • The rule regarding AI content has been updated. The rule now rules as follows:

    Be sure to credit AI when copying and pasting AI sources. Link to the site of the AI search, just like linking to an article.

8 Viruses

Isair50

Unknown
Aug 24, 2003
51
1
37
Unknown
Visit site
✟176.00
Faith
Catholic
Marital Status
Single
I have trouble with about 8 viruses on my computer, my anit virus software: Norton Anti Virus cannot remove them. THe Viruses are: W32.Kwbot.C.Worm, W32.Randex.F, W32.Kwbot.F.Worm, Backdoor.Sdbot.F, another W32 Randex.F, Backdoor.Trojan, BAckdoor.Optix, Backdoor.Sdbot, and another W32 Randex.F, does anyone know a way to rid of these viruses?
 

doofus125

Goodbye
Aug 31, 2003
2,902
97
✟3,627.00
Faith
Agnostic
Marital Status
Single
Isair50 said:
I have trouble with about 8 viruses on my computer, my anit virus software: Norton Anti Virus cannot remove them. THe Viruses are: W32.Kwbot.C.Worm, W32.Randex.F, W32.Kwbot.F.Worm, Backdoor.Sdbot.F, another W32 Randex.F, Backdoor.Trojan, BAckdoor.Optix, Backdoor.Sdbot, and another W32 Randex.F, does anyone know a way to rid of these viruses?

You are in big trouble if norton can't get rid of them.....What version of windows and norton are u running and are the virus definitions up to date?

There are tools through the symantec site but the forum won't allow me to post the site so put a .com after that name :) I'm not sure if any of them will work for you or not....
 
Upvote 0

Inspired

only hurts when I breathe
Oct 8, 2002
4,991
197
49
Visit site
✟6,494.00
Faith
Christian
Marital Status
Single
Isair50 said:
I have trouble with about 8 viruses on my computer, my anit virus software: Norton Anti Virus cannot remove them. THe Viruses are: W32.Kwbot.C.Worm, W32.Randex.F, W32.Kwbot.F.Worm, Backdoor.Sdbot.F, another W32 Randex.F, Backdoor.Trojan, BAckdoor.Optix, Backdoor.Sdbot, and another W32 Randex.F, does anyone know a way to rid of these viruses?

Ok first one W32.Kwbot.C.Worm

Ok, before you do this, you need to create a backup of your harddrive, just in case.

here's what you need to do to remove it:

  1. Click Start, and then click Run. (The Run dialog box appears.)
  2. Type regedit

    Then click OK. (The Registry Editor opens.)
  3. Navigate to each of the keys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
    CurrentVersion\RunServices
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

    NOTE: All of these keys may not be found on all the systems.
  4. From each key, in the right pane, delete the values if you find them:

    SystemSAS system32.exe
    CMD cmd32.exe
  5. Navigate to and delete the key:

    HKEY_Local_Machine\Software\Krypton,
  6. Navigate to the key:

    HKEY_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

    NOTE: This key does not exist on all the systems. If you do not find it, proceed to step i.
  7. In the right pane, double-click: Shell
  8. Change the text in the Value data box so that it reads only:

    Explorer.exe
  9. Navigate to each of the keys:

    HKEY_Current_User\Software\Kazaa\LocalContent
    HKEY_Current_User\Software\iMesh\Client\LocalContent
  10. In the right pane, delete any values that refer to the C:\%Windir%\UserTemp or C:\%Windir%\User32 folders. For example:

    Dir? 012345:C:\%Windir%\UserTemp

    NOTE: "?" in this value represents a number that the worm has chosen.
  11. Exit the Registry Editor.
I would recommend rebooting after each edit.

Next, W32.Randex.F

  1. Click Start, and then click Run. (The Run dialog box appears.)
  2. Type regedit

    Then click OK. (The Registry Editor opens.)
  3. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  4. In the right pane, delete the value:

    "MicrosoftNetwork Daemon for Win32" = NETD32.EXE
  5. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
    RunServices
  6. In the right pane, delete the value:

    "MicrosoftNetwork Daemon for Win32" = NETD32.EXE
  7. Exit the Registry Editor.
W32.Kwbot.F.Worm

  1. Click Start, and then click Run. (The Run dialog box appears.)
  2. Type regedit

    Then click OK. (The Registry Editor opens.)
  3. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
  4. In the right pane, delete the value:

    "Shell"="Explorer.exe %system%\System32.exe"
  5. Navigate to these registry keys:

    HKEY_CURRENT_USER\Software\Kazaa\LocalContent
    HKEY_CURRENT_USER\Software\iMesh\Client\LocalContent
  6. In the right pane, delete the values:

    "Dir? 012345:"="%Windir%\sCache32"
    "DisableSharing"="0"
  7. Exit the Registry Editor.
Backdoor.Sdbot.F



  1. Click Start, and then click Run. (The Run dialog box appears.)
  2. Type regedit, and then click OK. (The Registry Editor opens.)
  3. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  4. In the right pane, delete the value:

    RDLL RunDll16.exe
  5. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
    RunServices

    NOTE: This key is not found on all the systems.
  6. In the right pane, delete the value:

    RDLL RunDll16.exe
  7. Exit the Registry Editor.


W32.Randex.F



Click Start, and then click Run. (The Run dialog box appears.)
  1. Type regedit

    Then click OK. (The Registry Editor opens.)
  2. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  3. In the right pane, delete the value:

    "MicrosoftNetwork Daemon for Win32" = NETD32.EXE
  4. Navigate to the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
    RunServices
  5. In the right pane, delete the value:

    "MicrosoftNetwork Daemon for Win32" = NETD32.EXE
  6. Exit the Registry Editor.

After you do all of this, unistall Kazaa, or whatever other file sharing programs you have, get norton, and keep it updated.;)
 
Upvote 0
Direct your browser to the following.

housecall.trendmico.com/housecall/start corp.as

It will do a free web-based virus scan on you PC that is both current and recommended by Microsoft :)mad: ).

I had the same virus in 91 files and it found them all. Here are some steps you need to take in order remove the references from your registry.


Removing Autostart Entries from the Registry

Removing autostart entries from the registry prevents the malware from executing during startup.
  1. Open Registry Editor. To do this, click Start>Run, type REGEDIT, then press Enter.
  2. In the left panel, double-click the following:
    HKEY_CURRENT_USER>Software>Microsoft>Windows>
    CurrentVersion>Runonce
  3. In the right panel, locate and delete the entry or entries:
    SystemSAS = "system32.exe"
    CMD = "cmd32.exe"
  4. In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
    CurrentVersion>Run
  5. In the right panel, locate and delete the entry or entries:
    SystemSAS = "system32.exe"
    CMD = "cmd32.exe"
  6. In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
    CurrentVersion>RunServices
  7. In the right panel, locate and delete the entry or entries:
    SystemSAS = "system32.exe"
    CMD = "cmd32.exe"
  8. In the left panel, double-click the following:
    HKEY_USERS>.DEFAULT>Software>Microsoft>Windows>
    CurrentVersion>Runonce
  9. In the right panel, locate and delete the entry or entries:
    SystemSAS = "system32.exe"
    CMD = "cmd32.exe"

Removing Malware Registry Key
  1. In Registry Editor, in the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>Software>Krypton
  2. Still in the left panel, delete the subkey:
    Krypton
  3. Close Registry Editor
 
Upvote 0