Page 2 of 2 FirstFirst 12
Results 11 to 17 of 17

Thread: Win32:Kuang2 virus

  1. #11
    Yes........well......perhaps I shouldn't point the finger so quickly......


    Where the hell did you get the client!? I looked everywhere for that sucker...Maybe I'm not as l33t as I thought!

  2. #12
    Junior Member
    Join Date
    Nov 2001
    Posts
    8
    Originally posted here by Conf1rm3d_K1ll
    Yes........well......perhaps I shouldn't point the finger so quickly......


    Where the hell did you get the client!? I looked everywhere for that sucker...Maybe I'm not as l33t as I thought!
    http://www.dark-e.com/archive/trojan...tv/index.shtml

    And this did not work. I still have the virus. Deleting restore points did not work either. I'm going to give this client a shot again...

  3. #13
    Junior Member
    Join Date
    Nov 2001
    Posts
    8
    Crap! I cannot seem to get rid of this thing!

    "File "C:\System Volume Information\_restore{957C0F68-3CE5-4475-886D-C7F4756C4224}\RP29\A0003390.dll" is infected by "Win32:Kuang2" virus."

    I cannot find that driver and I created a new restore point, and deleted all other restore points. The little Kuang2 client does not find it either. Maybe the client is for a different version of this virus. Please help! I want to make formatting a last resort.

  4. #14
    Senior Member
    Join Date
    Feb 2002
    Posts
    253
    Here is the Trend Micro writeup on the W95.kuang2.cli virus:

    http://www.antivirus.com/vinfo/virus...VName=PE_WEIRD

    Hope that I have been some help.

  5. #15
    Senior Member bAgZ's Avatar
    Join Date
    Jul 2001
    Posts
    206
    Wasn't that the virus from Neuromancer

  6. #16
    Senior Member
    Join Date
    Nov 2001
    Posts
    276
    - Fasten Your Seatbelts! Kuang2 theVirus is invisible in registry or ctrl+alt+del task list. When somebody start in on clean system it will first infect some of the system files [Trojanslair Note: Uses Wininit.ini to rename Kernel32.dll] so the virus will be active every next time when target reboots. After that virus is active and it start to infect all Windows PE EXE files on all fixed disks. Virus don't change time & date of infected file. It infect also files with ReadOnly attribute. Infected file grow in size by aprox 11 KB. Has a build in Cleaner ! Who do I here saying smallest Trojan/Backdoor ? Client has Upload, Download, Spawn Possiblities. Coded by Weird
    Here´s the wankers homepage

    Couldn´t find any constructive info, sorry..
    Dear Santa, I liked the mp3 player I got but next christmas I want a SA-7 surface to air missile

  7. #17
    Junior Member
    Join Date
    Nov 2001
    Posts
    8

    Cool

    Well its great to be back all fresh and clean after a format. Now it's time to learn everything about internet security that I can, so you guys will be seeing me a lot more ofter!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •