All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
Virus Encyclopedia
Riskware
Alerts
Analysis
News
Glossary
Weblog

 
Archive

<< 2009  
Jan Feb Mar
Apr May Jun
Jul Aug Sep
Oct Nov  
Virus Alert Danger Levels
Virus Alert Danger Levels

Wonder what the current virus alert means for your computer? Find out more about our Virus Alerts Threat Levels.

Free Removal Tools
Free Removal Tools

The Kaspersky Lab website removal tools section provides free utilities for removing dangerous viruses during an epidemic.

Antivirus Database Updates
Antivirus Database Updates

Kaspersky Anti-Virus users can always find the latest virus definitions in the database updates on the Kaspersky website.

 

  Home / Viruses / Alerts

Net-Worm.Win32.Kido

new thread
return
01.13.09 17:12 GMT

 14.01.2009 14:36  |  mehrsat4u Post Reply   
  I Found this virus 3 days ago in my network, but i have problem that kaspersky show the following message when find this virus. "write access is denied" file: c:\windows\bkqamc.dll
Note : my virus name is:
Net-Worm.Win32.Kido.em
Patch MS08-067.mspx Microsoft
can u help me plz?

 17.01.2009 21:08  |  abanda741 Post Reply   
    help:??????

 26.02.2009 17:07  |  qh.sandip Post Reply   
    hi

 03.03.2009 10:04  |  ameycooldude Post Reply   
    USE KLWK soft 4rm kaspersky
using command prompt it gets executed n then removes viruses
to remove manually
connect ur hdd by using an ide/sata to usb cable to uninfected pc having kaspersky antivirus updated.....
set the settings high then scan the drives
DANGER:
Dont boot the uninfected pc using infected pc's HDD
connect it just like usb pen drive... .using converter
it costs around 250 in Mumbai & Goa

 14.03.2009 00:58  |  majed Post Reply   
    majed hhdjgs

 23.03.2009 22:01  |  abu_ahmed_6 Post Reply   
    hi thanks four rejeste me

 01.04.2009 16:39  |  akahn Post Reply   
    Typically, these dll's load into memory when the system boots (and/or a user logs on to O/S), and puts a lock on the file. You can do a couple of things:
1 - First try booting into Safe Mode w/command prompt. Then go to the file and delete it. Sometimes if it won't let you delete it, you can rename it "using "ren" command
2 - If that doesn't work, use the Windows install CD to boot into recovery console and then go the to the file and delete it.
3 - You can also remove the hard drive, and install it as a secondary drive on another PC, then browse to and delete the file.

 08.04.2009 17:15  |  behahaimy Post Reply   
    abc

 23.09.2009 17:07  |  bjk,bjl, Post Reply   
    Please, I want the key to Kaspersky Anti-Vairs 2010

 26.09.2009 14:38  |  jack34 Post Reply   
    I suggest you to install the NOD32 antivirus software and update this software daily on nod321 dot come website free of cost.
----------------------------
[url=http://www.getplastic.co.uk]credit card[/url]
[ccna test](http://www.ccnatest.com/)
URL="http://www.lowmortgageoffer.com"]home mortgage[/URL]
[http://www.ccnatest.com ccna certification test]
URL http://en.wikipedia.org/wiki/Main_Page
ccna test
[ccna exam|http://www.ccnaexams.com]

 14.01.2009 23:13  |  koclokk Post Reply   
  My KAV have detected Net-Worm.Win32.Kido.dq and the threats have been deleted. But this threats is always show up, over n over.
My KAV is ver 7.0x
Threats location in C:\windows\system32\x and on Temporary internet files folder.
Can you help me please....

 15.01.2009 06:39  |  manawa Post Reply   
  Hi every body we need a help removing Net-Worm.Win32.Kido.ih virus. because kaspersky detecting this virus variation but it won't clean or delete because there is no right access to that random DLL file.
we have tried to use that kido removing tool but that won't help. please help to us remove this virus from our pc's.
Thank you!

 20.01.2009 13:09  |  ngocnpp Post Reply   
    Hello
I've used the solution as bellow to solve this issue in our network:
You need to update the Critical patch of this vulnerability (MS08-067).
Kaspersky can't disinfected the worm without the administrator right permission. In this case, I guess that your network is working based on domain controller. You should scan your computer that use the Administrator right permission.
P/S: The Kido removing tool doesn't work for Kido.ih

 21.01.2009 07:58  |  manawa Post Reply   
      We have tried your solution but it won't work.
any ideas?
 
 22.01.2009 06:11  |  ngocnpp Post Reply   
        You mean Your computer still infected?
   
 01.04.2009 16:37  |  akahn Post Reply   
          Typically, these dll's load into memory when the system boots (and/or a user logs on to O/S), and puts a lock on the file. You can do a couple of things:
1 - First try booting into Safe Mode w/command prompt. Then go to the file and delete it. Sometimes if it won't let you delete it, you can rename it "using "ren" command
2 - If that doesn't work, use the Windows install CD to boot into recovery console and then go the to the file and delete it.
3 - You can also remove the hard drive, and install it as a secondary drive on another PC, then browse to and delete the file.

 26.02.2009 17:08  |  qh.sandip Post Reply   
    plz give me removal tool

 26.02.2009 18:28  |  luciano Post Reply   
      come eliminare questo virus?

 15.09.2009 13:06  |  ahtsham Post Reply   
    I am using antivirus kaspersky business space security. I scanned my computer it detects the virus Net-worm.win32.kido but can not delete, please tell me the solution to remove the virus.

 15.01.2009 07:34  |  sma_sma Post Reply   
  Hello,
Science last week we face the big issue. This virus detected but can't remove. also this virus create several services, dll and registry paths. please send us immediate solution ASAP...
Mainly we need a help to remove Net-Worm.Win32.Kido.ih virus
also we can give our good supports to you, if you need.
Thanks.

 20.01.2009 13:15  |  ngocnpp Post Reply   
    Just update the last Kaspersky virus database and enjoy it! KAV work great!

 17.01.2009 14:11  |  siva Post Reply   
  plz Analysis Net-Worm.Win32.Kido

 20.01.2009 07:48  |  mbahador Post Reply   
  Hello,
My KAV detect many attacks block from other computer in lan, for example "Win.NETAPI.buffer-overflow.exploit! Attacker's IP address: 192.168.5.53. Protocol/service: TCP on local port 445. Time: 2009/01/15 " please help me???

 20.01.2009 14:40  |  abelvarzim Post Reply   
  Updated Kaspersky, runed the removal tool klwk, and the microsoft pacht KB921883. Still i can´t erase the "Net-Worm.Win32.Kido.em" from my system.
Please help.

 20.01.2009 17:17  |  tasseb Post Reply   
    We've get the same infection, regarding Kido.ih version of Kido.
Kaspersky find it, delete it, every time it's detected... but the virus is able to propagate and come again.
The patched machines (Vulnerability MS08-067) are infected as well.
Kaspersky Lab says they were working on a removal tool for ih variant since one week yet, and no solution found that don't crash the system.
So we're just waiting from this tool now, and the virus propagate itself and infect all our machines...
PS: KB921883 patched MS06-040's vulnerability. This one has been replaced, updated by MS08-067 (KB958644)
 
 21.01.2009 21:40  |  Lucky670 Post Reply   
      Im still in clean cos the KB954644 was installed in my PC last October by Auto Update and Ive scanned and it all clean - no infection. I also checked registry as well.
I usual uncheck 3rd party cookie in Fx 3 also CookieSafe add-on that put "Block 3rd party cookie"
I also using CounterSpy V3 as well. Anyway keep scan every day to keep clean - there are new virus,etc.. to come up this year. People are stupid to create virus or worm to spread to make damage other people PC -- it has to stop.

 27.01.2009 10:06  |  manawa Post Reply   
  Hello,
Now the kidokiller tool is working for virus removal. but we have a problem with scheduled task. virus is generating scheduled task call at1, at2, at3,.......
But after we delete all those tasks after few time they'll generating again.
what is the reason to this?

 10.02.2009 04:43  |  janusarabia Post Reply   
    same with our network here in the office..what we did,we've stopped the TASK SCHEDULER SERVICE (CONTROL PANEL\ADMINISTRATIVE TOOLS\SERVICES) from the computer and change it to MANUALLY (RUN) instead of AUTOMATIC. NOTE: Don't DISABLE it (READ THE SERVICES INSTRUCTIONS THERE).

 09.02.2009 20:48  |  kartal Post Reply   
  hello

 11.02.2009 19:41  |  vladymyris Post Reply   
  Hi all!I red all your comments and I have some solutions that might help you.So,here they are:
1. Read the report from KAV and see the location of the virus,go there and try to delete it manually;
2. Install the vulnerability patch from Microsoft;
3. I saw on your comments that the virus removing tool doesn`t work.There are other Anti-Virus sites that have virus removing tool(srry i can`t give ya an example,I don`t remeber!),you can try those;
4. Try to run Windows in Safe mode and maybye you can delete the virus from there;
5.Use the Internet as little as you can because the person who created the virus can connect to the virus on your computer and the have total acces to your computer.Also,when you`re not using the computer or when you don`t need the Internet,REMOVE THE INTERNET CABLE FROM YOUR COMPUTER!AT LEAST THE PERSON WHO CRREATED THE VIRUS WON`T BE ABLE ANYMORE TO ENTER IN YOUR COMPUTER!;
6. If you still need to use the Internet try avoiding logging to any accounts(Yahoo!Messenger,Skype,YouTube,Online Games,etc.),because the virus may steal your passwords and the creater of the virus may enter in your accounts.
7. If you know how to change your IP adress,try it because if you use the Internet this would protect your computer at least for a few hours and the creater of the virus will need a little while to find your new IP.WARNING!MAKE THIS ON YOUR OWN RISK!IF YOU`LL CHANGE YOUR IP YOU MIGHT NOT BE ABLE TO CONNECT TO THE INTERNET ANYMORE!
8. If you KAV is not able to delete the virus you can try another Anti-Virus,see if it helps,if it is remove the virus,restart your PC and then,if you want,install KAV again;
9. You can also connectyour PC to other PC and try removing the virus from the PC you`re connected to your infected PC,BUT BE CAREFULL!ONCE YOU CONNECT THE CABLE TO THE INFECTED PC,THE VIRUS MAY TRANSFER TO THE CLEAN PC ALSO!BE CAREFULL!;
10. And in the end,if none of theese help,you should reinstall your Windows.
. Thesse are the...

 12.02.2009 11:42  |  lovesee_007 Post Reply   
  hy dud,
what is svchost.exe
it disable my audio device.if i dont restart my pc i can not hear any sound from my pc.
Help me plz.

 12.02.2009 20:45  |  vladymyris Post Reply   
    Hey mate,if you`re using Kaspersky 2009(srry i don`t know anything about other versions) you can look somewhere into the Anti-Virus menu and you`ll find ,,Trusted Applications" and there is written svchost.exe.i think it`s a system component or kinda process but i`m not shure.It sholud be at trusted.Well this is not good if it is disableing your sound....something is not OK in your PC.You should scan your machine.And after that if no virus is detected try to reinstall your Audio Device(you should find the CD from your computer with the audio device).If still is not working,if you want,you shold reinstall your Windows.Hope this helps!Bye!

 12.02.2009 21:58  |  vladymyris Post Reply   
      Hey again!Sorry,don`t reinstall your audio device!you don`t need to!I think you have the following virus:Net-Worm.Win32.Kido.fx because i saw something written about svchost.exe in the following link of this site: http://www.viruslist.com/en/viruses/encyclopedia?virusid=21782749
Read the HOLE topic and you`ll see there spreading methods,files that are infected or changed registry names,etc.You will also see there how to delete the virus.If you`re not using Kaspersky 2009,you shoul download the trial because it will detect if you have this virus.Read carefully that topic and delete your virus.It`s possibly to have another virus that is making trouble to your machine but i think 90% that is the virus I told ya.Check if it is or not.Good luck!Bye!REMEMBER:DON`T REINSTALL YOUR AUDIO DEVICE,SORRY I DIDN`T KNOW IT`S THIS VIRUS.

 24.02.2009 10:20  |  udham Post Reply   
    Hello dear
how remove svchost.exe

 12.02.2009 20:55  |  vladymyris Post Reply   
  Hey all again!Sorry but my first messege is incomplete,so I tell you the las part.
Well,if your computer is infected,try the solutions from my first messege and if you have any data that you wanna save you sholud first scan it and then put it on a stick or a CD to save it.My oppinion is that the virus is auto-copying and it may download malicious softweare in your machines,that`s why your Kaspersky is always detecting that virus.To be sure that your PC will be CLEAN,you first must delete all the viruses from your machines and any malicious softweare that may harm your PC`s.I never had this virus but see from your comments that it`s very dangeuros.I hope my solutions will help you in the battle with the virus.Good luck!A,and tell me please if one of my solutions worked,I`m very curious,pls!!Cya and bye!

 16.02.2009 00:05  |  kareem Post Reply   
  hi

 19.02.2009 18:52  |  jizaguirre Post Reply   
  No puedo descargar el KidoKiller v3.1 alguien ha podido ْltimamente?

 25.05.2009 06:49  |  yudias Post Reply   
    thanks

 22.02.2009 06:12  |  volvo Post Reply   
  How is method of killing for Net-Worm.Win32.Kido virus.

 03.03.2009 16:27  |  armandzkidoo98 Post Reply   
  guys theres that Net-Worm.Win32.Kido stuck in my computer and it cant be deleted
then after a few weeks the scan found these viruses
trojan program
trojan backdoor (something..)
and a virus named I love my peanut (lol..) that shows porn every time i open the internet explorer
need help man!

 30.03.2009 16:22  |  sameolg Post Reply   
    Download it here -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe . Save the file to your desktop.
Now, please make sure no other programs are running, close all other windows and pause Kaspersky (Choose the option "resume manually" if still active) until after the scanning and removal process has taken place.
Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.
You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.
Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt , please attach it to your next post. Also, please don't forget to resume the Kaspersky that you paused

 12.03.2009 23:37  |  jobinjoe Post Reply   
  Hi guys
My external hdd is affected with this virus called “Net-Worm.Win32.Kido.ix” and my Kaspersky- 7.0 AV Its updated till date, is Not able to disinfect nor it is deleting the virus, and it says that it can not be delete or disinfect and access to this file is blocked.
Is there is any way to delete this files.
Please Guide me to solve this problem.
THANKING YOU..
cheers
Joe

 17.03.2009 05:21  |  jony Post Reply   
    HI,
My external hdd is affected with this virus called “Net-Worm.Win32.Kido.ix” and my Kaspersky- 9.0 AV Its updated till date, is Not able to disinfect nor it is deleting the virus, and it says that it can not be delete or disinfect and access to this file is blocked. Is there is any way to delete this files. Please Guide me to solve this problem. THANKING YOU.. cheers Joe
 
 17.03.2009 11:08  |  Ed Post Reply   
      hello my laptop it is attached by this virus Net-Worm.Win32.Kido and it has change the theme display to window vista classic when i tried to change it back to window vista display it cannot and it has mute audio how to remove this virus help please!!!

 17.03.2009 12:39  |  kavaro7 Post Reply   
  After cleaning Kido virus from the pc's we are now facing another issues with task scheduled.
kido virus generating lots of task scheduled like at1,at2,at3,..........
after we clear all those tasks in another few more hours these task generated again

 20.03.2009 19:50  |  KEYUR279 Post Reply   
  Please Sent New Thread News

 27.03.2009 14:47  |  lujiang188 Post Reply   
  I have tried for about 5 times on my U-disks,but to my disappointment ,Ifound that the virust Net-worm.win32.Kido.ih can't be removed drastically by Kaspersky.

 30.03.2009 16:20  |  sameolg Post Reply   
    here is the solution:
Download it here -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe . Save the file to your desktop.
Now, please make sure no other programs are running, close all other windows and pause Kaspersky (Choose the option "resume manually" if still active) until after the scanning and removal process has taken place.
Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.
You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.
Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt , please attach it to your next post. Also, please don't forget to resume the Kaspersky that you paused

 28.03.2009 15:30  |  mohammadfadda Post Reply   
  I have viruses in my computer ,what i do ?

 01.04.2009 05:47  |  cg@soscanhelp.com Post Reply   
    The .dll in question set to read only in the security tab of the file properties.
Boot the computer into safe mode.. locate the .dll in question.. goto the security tab after right clicking the file and choosing properties. (the security tab only shows up in safe mode.) Give everyone full controll ... click ok ... then delete it. reboot your computer and run a full system scan.
If the dll is not removed it will reinfect your computer upon every reboot. This is how I removed this virus when the kido killer / Kaspersky would not.
 
 04.04.2009 18:29  |  rainmaker Post Reply   
      hello,
I have one question:
how come the KAV or KIS do not prevent the Kido worm from being installed??? I thought KIS/KAV has some kind of prevention techniques so all threats are stopped before they instal into a system.

 11.04.2009 09:22  |  nakiel Post Reply   
  I have noticed that none so far has made the connection between the conficker virus and Adolf Eugen Fick; the man who invented contact lenses...

 13.04.2009 05:25  |  77seeker Post Reply   
  I have a problem with virus Net-Worm.Win32.Kido.ih in my flasdisk, I have erased in flashdisk and my flasdisk have format until three. but every my flasdisk plug to my notebook the virus came again.
please help me!

 18.04.2009 18:48  |  dhaya Post Reply   
  i want know about the virus & how to solve the virus manually thank u

 02.05.2009 13:41  |  eghlima Post Reply   
  hi help me help mi . plese send a new anti viruse . helpe mi

 02.05.2009 13:43  |  eghlima Post Reply   
  سلام لطفا براي من يك انتي ويروس قوي ارسال كنيد سيستم من واقعا ويروس بدي داره 09169327268 - 0098

 02.05.2009 13:44  |  eghlima Post Reply   
  سلام لطفا براي من يك انتي ويروس قوي ارسال كنيد سيستم من واقعا ويروس بدي داره 09169327268 - 0098 eghlima57@yahoo.com

 09.05.2009 07:50  |  hop Post Reply   
  I have one virus attached me via USB. It's name is boyedt.com. KAS cannot find it when it plugin USB to computer although i have updated my database yet. I realise it by Winrar. So show me how to treat it. I don't allow me to update my KAS. I still visit website normally.

 16.05.2009 04:15  |  albanaalbna@yahoo.com Post Reply   
  albanaalbna@yahoo.com

 23.05.2009 18:46  |  fannysony Post Reply   
  my computer has just been infected by this kind of virus Net-Worm.win32.kido.jq ! i don't know where to find the solution for this new kind of kido virus! plzz help me! i used kaspersky to scan many times. at the fisrt time, the virus was found on the computer. but when i tried to delete or neutralize it, the program informed : "not found virus net-worm.win32.kido.jq" .. don't know how to deal with this...

 23.05.2009 21:15  |  mhbubul Post Reply   
  deleted: Trojan program Backdoor.Win32.Agobot.pnu File: E:\System Volume Information\_restore{3733F190-21FD-4340-9DC3-4ED6185E5960}\RP14\A0000295.exe///iss2_en.exe///av/autodown.exe
deleted: virus Worm.Win32.VB.zx File: D:\USB.exe

 23.05.2009 21:16  |  mhbubul Post Reply   
  create a folder name like 526d5717206736f34ca096
and write access denied if i want to delete folder.

 28.05.2009 06:23  |  fabio Post Reply   
  I've a kas business 6 and yesterday many machines was infected with kido, but the kas catch as Win32 - GEN and don't remove, but If I use Kas 7 its detect correcty, as kido and remove. Why this happen?
I can identify manually as conficker.C.
Thanks in advance.

 31.05.2009 10:06  |  JohnnyMilwaukee Post Reply   
  what is wrong...I should be able to go where I please,,,Always I am told I am in Extreme danger, and I know there is malware and god knows what else inside...what am I paying for...can't you lock on and purge the little Stalinist functionaries? Or give me thread tracing technology, direct and indirect/like Black Ice...once upon a time...at least we could get the IPs,thd sss= DNS,the MAC Number, and were the computer or zombie is. No offense intended, but, I rejected the study of hardware and software by no later than 1976. If you like it,please do it. Rid us of these toads. Flood their drives, burn their cards and flood them with replicating files. I want you to go to war with them. You probably know a substantial percentage of their communities. Why do we wait? Please, do the Nikita,except,pound a virtual shoe on their pointed little pimply heads. I try to write, my files are wipes.Every time I got on line, my settings are changed. Yes, I know Evgeny Zamiatin wrote the real 1984. In 1920, or was it 1922. Whatever the case, nearly a century has gone by, and things have only gotten worse. Strike a blow for the poets. Rid me of this vermin, that I might rest and think. Don't set it so either it barely works,or worse, that I have to learn all of what you are the specialists in. Please....

 21.06.2009 15:54  |  beckysandiford Post Reply   
  Hi,
I am having a problem on my laptop with the virus:
net-worm.win32.kido.jq
I am trying to clean it with Kaspersky but it is saying write access is denied, and i don't know how to gain access. I am computer administrator as there is no one else using this laptop, i don't know how to get rid of it, as the virus software is not doing anything,
Regards,
becky.

 23.06.2009 11:44  |  ecitnet Post Reply   
  hello

 28.08.2009 09:28  |  tmn413 Post Reply   
  I have a nasty virus that is slowly crippling me. I have tried downloading several spyware and malware removal tools an each time I run them, the software runs for a very short time and then gets terminated. When I select the application to run again a WINDOWS message comes back and says something to the effect that the file cannot be accessed. I believe that this virus has also disabled my Restore feature and locked me out of administrator. I recently went to the Microsoft website to download all of the latest security patches and updates and thre of them were unable to load. MS also has a spyware cleaning software (I believe it is called Defender) and that was stopped after it was downloaded and in the middle of running. The last straw was the free scanning software that MS offers to tell you what viruses and spyware you have ... I downloaded and ran that and the virus has now rendered me windows explorer application unaccessible. (I am on another computer). I even tried loading some of the programs like Spybot in safe mode and that did not help .... the virus rendered that application unaccessible while in safemode. Can anyone please help before I go nuts???

 29.08.2009 21:21  |  az-eagle Post Reply   
    I am doing a study on this Net-Worm.Win32.Kido. I need to gain some more information on this if possible. Can anyone direct me a another site that is able to tell me the estimated cost of damage this worm has caused?

 01.09.2009 10:42  |  kyizin Post Reply   
  How to work Net-worm.win32.kido?

 23.09.2009 17:07  |  bjk,bjl, Post Reply   
  Please, I want the key to Kaspersky Anti-Vairs 2010

 

Copyright © 1996 - 2009
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com