The W32.Kwbot.C.Worm attempts to spread itself through the KaZaA and
iMesh file-sharing networks. The worm also has a backdoor Trojan capability
that allows a hacker to gain control of the compromised computer.
When W32.Kwbot.C.Worm runs, it does the following:
Copies itself as one of the following:
%System%System32.exe
%System%Cmd32.exe
The attribute of this copy is set to Hidden.
Removal Instructions:
Update the virus definitions.
Restart the computer in Safe Mode.
Run a full system scan and delete all the files detected as
W32.Kwbot.C.Worm.
Delete the values that the worm added to the registry.
http://securityresponse.symantec.com/avcenter/venc/data/w32.kwbot.c.worm.html