Thursday, December 6, 2007

Encounter with Kibaki(The Virus)

I have dealt with several viruses but Kibaki virus was different from them.
Intelligent virus? It seemed to be learning: I delete one file to kill the virus after some time it replaces the file i deleted. From then on it replaces it instantly. I try to rename works the first time but I forgot to do something and I have triggered something else. The renamed file is replaced. Then on every time I rename the file it is replaced instantly. Seemed like some form of intelligence to me. Keeps truck of every file belonging to the virus.
Being made by africans, instead of being angry at it I smile wow! a virus that can give headaches to antivirus makers and its from Africa! So africans can do wonders.
I never used to like Visual Basic programming though I used it in my degree project. But this virus made me love VB(not to create viruses but do do wonders with it).
Anyway, I came up with a script that kills the virus and removes the registry values set by the virus and all one needs to do is scan and remove the remaining files with an antivirus like nod32.
You can download the script here. And you need to download the antivirus(nod32) too to remove the virus completely(need to do a full scan).