Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Win32:Kuang2 virus

  1. #1
    Junior Member
    Join Date
    Nov 2001
    Posts
    8

    Win32:Kuang2 virus

    Please Help! I cannot get rid of this virus. Here is what my antivirus software says:

    Wednesday, March 20, 2002 2:59:09 AM

    File "C:\System Volume Information\_restore{957C0F68-3CE5-4475-886D-C7F4756C4224}\RP29\A0003390.dll" is infected by "Win32:Kuang2" virus.

    I search for that driver and find nothing. Searched the web for info on this virus and find little to nothing. I think it's a trojan but I cannot find it to delete it. Help is appreciated.

  2. #2
    What anti virus software are you using? What OS are you running?



    It appears that Kuang2 is just a simple trojan so therefore it comes in two parts. The client comes with the "anti virus".....Get your hands on the client part of the program and your done!


    Here's a little cut and paste from ISS X-Force Database-

    To clean the local system, leave the IP address field in the program blank. The antivirus cleaning process copies the infected version of EXPLORER.EXE to EXPLORER.WK2, and removes the virus. The program places the cleaned version of the file back to EXPLORER.EXE, when you shut down and restart your computer. The antivirus process also scans the hard drive, looking for any other infected files. The readme file included in the distribution of the backdoor recommends running the antivirus scan twice to ensure that the backdoor is removed.


    Hope that helps.............



  3. #3
    Junior Member
    Join Date
    Nov 2001
    Posts
    8
    Originally posted here by Conf1rm3d_K1ll
    What anti virus software are you using? What OS are you running?
    Running Avast antivirus on Windows XP pro. I use Sygate personal firewall pro as well.

  4. #4
    I've had a very quick look around for somewhere to download the program with no success. Perhaps someone else can be of more help?


    Give The Cleaner a try......You can download it here...

  5. #5
    Senior Member
    Join Date
    Dec 2001
    Posts
    304
    You could go the above routes to fix this problem but what i would do (maybe alittle easier)
    would be to go to www.tweakxp.com and find out how to delete your restore points.

    "C:\System Volume Information\_restore{957C0F68-3CE5-4475-886D-C7F4756C4224}\RP29\A0003390.dll

    Sounds like a system restore point to me.
    Violence breeds violence
    we need a world court
    not a republican with his hands covered in oil and military hardware lecturing us on world security!

  6. #6
    Junior Member
    Join Date
    Nov 2001
    Posts
    8
    I did find the client side of this virus and will run the scan command. That should do it. Thanks a lot for all of the help!

  7. #7
    Senior Member
    Join Date
    Dec 2001
    Posts
    304
    here is the exact link to the solution http://www.tweakxp.com/tweakxp/display.asp?id=330

    Another thing may be to make a restore point for today and then go threw your other restore points and then for each one that you restore to then run the virus protection again. When you get to the correct restore point it should find the virus is a different directory and then you can delete the virus using your anti-virus and then go back to the restore point that you made for today and run your scan again...should come up viri free

    again this is the long and painfull way.. I would just delete all the restore points...Also just to be safe as soon as i deleted them i would make another one quick
    Violence breeds violence
    we need a world court
    not a republican with his hands covered in oil and military hardware lecturing us on world security!

  8. #8
    Me thinks someone has been playing with trojans and got them self all infected.......

  9. #9
    Senior Member cwk9's Avatar
    Join Date
    Feb 2002
    Posts
    1,207
    Did a little searching and came up with this from the Symantec web site. Note this is about Kuang not kuang2 so i'm not sure if this helps.

    Kuang
    Aliases: None Area of Infection: .COM Files No additional information. This threat is detected by the latest Virus Definitions. All computer users should employ safe computing...
    http://securityresponse.symantec.com...dyn/16953.html <-- link to virus info
    Its not software piracy. I’m just making multiple off site backups.

  10. #10
    Junior Member
    Join Date
    Nov 2001
    Posts
    8
    Originally posted here by Conf1rm3d_K1ll
    Me thinks someone has been playing with trojans and got them self all infected.......
    Again I do appreciate all the help. But I have yet to realize the purpose of playing with trojans and sending people virii. I never thought something like that was fun or cool and can't figure out why some do.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •