|
|||||||||||
|
RE: Increased Kuang2 activity
From: <davec(at)skooter.net>
Date: Mon Feb 10 2003 - 12:13:00 EST
backdoor-kuang2v (4074) High Risk Kuang2 Virus installs remote control functionality on infected systems
Description:
Platforms Affected:
Remedy:
To clean the local system, leave the IP address field in the program blank. The antivirus cleaning process copies the infected version of EXPLORER.EXE to EXPLORER.WK2, and removes the virus. The program places the cleaned version of the file back to EXPLORER.EXE, when you shut down and restart your computer. The antivirus process also scans the hard drive, looking for any other infected files. The readme file included in the distribution of the backdoor recommends running the antivirus scan twice to ensure that the backdoor is removed.
Consequences:
References:
TL Security Trojan Archive, "Kuang 2 The Virus" at http://www.multimania.com/ilikeit/kuang2v.htm Standards associated with this entry:
Reported:
"Logan F.D. Greenlee" <lgreenlee@ciretose.net> wrote ..
This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Mon Feb 10 15:10:50 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:58 EDT |
||||||||||
|
|||||||||||