Cannot remove virus

Hi

I am new to Avast.I am running free version at the moment alongside free Zone Alarm firewall.Previously used Panda.

Avast keeps finding W32:kuang2 worm/torjan.It has found it in C:\systemvolume_restore & C:\pagefile.sys.

I run XP SP2.Have 2 x hard drives F & C(F is main drive,C is for my data storage).

Any ideas please as to what it is and how to remove it?

Thanks

Di :slight_smile:

The detection in pagefile.sys is a false positive.

avast! usual doesn’t scan this file, but may do so if scanning from another partition.

Do a forum search for more info because this topic has come up many times before.

You could add this ?:\PAGEFILE.SYS to the avast! Program Settings, Exclusions, as this detection seems to be on an on-demand scan.
Is that correct for when it is detected ?

The ’ ? ’ is a single character so if you happen to have the page file split over other drives the single entry will cater for both.

The only really effective way to clean infected _restore points is to disable system restore (for all drives) and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore.

Windows XP System Restore Guide

W32:kuang2 could be present in other files of your computer.
I suggest:

  1. Disable System Restore and reenable it after step 3.
  2. Clean your temporary files.
  3. Schedule a boot time scanning with avast with archive scanning turned on.
  4. Use SUPERantispyware and/or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
  5. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
  6. Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.
  7. Immunize your system with SpywareBlaster or Windows Advanced Care.
  8. Check if you have insecure applications with Secunia Software Inspector.