Just recently we at VillageNet have been infected with the kak e-mail
worm, this is more of a pain than a serious problem, however if you do
not stop this infecting your P.C., then the next worm of a similar
design could seriously damage your P.C. software.
We
suggest you print this page for future reference.

Diagnosis :
-
Carry out the following procedure to see if you have the virus
- In Outlook Express 5 click
on [Tools] - [Options] then the [Signature Tab]
- If the signature File at the
bottom points to a kak.htm then you have this worm.
- Check to see if a file c:\ae.kak file is there, this is another
file that shows you have the worm.
- If you do not have the worm,
still check out our prevention section

Cure:
- Shut down Microsoft Outlook
Express if it is open .
- Then you need to set your
explorer to show hidden files so - double click on the "My
Computer" icon on your desktop.
- Now click on [View] -
[Folder Options] then the [View Tab].
- Now click where it says
[Show all files] so that the circle next to Show is filled.
- Now click OK - This now
means you will see the hidden files on the system - they are usually
less coloured than non hidden files.
- DO NOT REMOVE any hidden files unless you know what you are
doing .
- Now in My Computer click
onto your c: drive, into your windows directory and delete the file
called kak.htm.
- Still in my computer click
in to [Start Menu\Programs\Startup] and remove the file called kak.hta.
- Now comes the bit you have
to be very careful with.
- Click on [Start] - [Run] and
type in "RegEdit" then click [OK]
- BE VERY CAREFUL, you are now in the registry editor, and a
mistake can stop your P.C. from starting.
- Click on the + next to
HKEY_LOCAL_MACHINE then
- Click on the + next to
Software then
- Click on the + next to
Microsoft then
- Click on the + next to
Windows then
- Click on the + next to
CurrentVersion then
- Click on [Run] not the +
this time, a list of entries will appear in the right column.
- an entry for cAgOu will be
listed with [ab] to the left
- Click on the word [cAgOu]
this will appear in dark blue.
- Now press the [Delete] key,
it will pop up a window which says "Are you sure you want to
delete this value" [ Yes] or [No]
- Click on [Yes].
- Now click on [Registry] at
the top of the screen then [Exit]
- Phew the dodgy bit is over.
- Now you need to stop the
pesky worm re-infecting on reboot
- For the last bit you need to
be a little careful firstly copy c:\autoexec.bat to c:\autoexec.kak
steps 26 to 36
- Double Click on the [My
Computer] icon on your main window.
- Now click on the [c:] drive
icon.
- Check to see if there is a
file called ae.kak in the directory, if not skip steps 29 - 36
*******************************************
- Left Click once on
the Autoexec.bat file, then Right Click on the Autoexec.bat file.
- Move the cursor down to
[rename], click on rename with the left hand mouse button.
- In the box type "autoexec.kak"
then press [Return]
- Warning - DO NOT REBOOT YOUR
MACHINE
- Left Click once on
the ae.kak file, then Right Click on the ae.kak file.
- Move the cursor down to
[rename], click on rename with the left hand mouse button.
- In the box type
"Autoexec.bat" then press [Return]
- Check that there is an
Autoexec.bat file in your c: drive if there is not you have spelt a
file incorrectly, DO NOT REBOOT until you have an Autoexec.bat file, or your
windows will not start.
*******************************************
- OK its now safe when you reboot
- Finally open up Outlook
Express, and click on [Tools] - [Options] then the [Signature Tab] and
change the [File] setting to remove the kak.htm entry Apply and shut
down Outlook.
- Now REBOOT your P.C.
and carry out the Diagnosis check again to see if
all is OK.
- If OK go to the prevention section before opening up Outlook Express
again.

Prevention:
- Firstly open [My Computer]
click once on c:\ae.kak then the right mouse button and choose
properties, and set to read-only.
- Carry out step 1 for
c:\autoexec.bat as well.
- Finally go to http://www.microsoft.com
and download the latest patch for Outlook Express that stops Active
Server Page Scripts running.
- Run the Microsoft patch
- You can now run Outlook
Express, and as you go through your in-box any files with this virus
will get a message saying that "an ActiveX control on this
page is unsafe".
- You can safely open the file
as the patch will fix the problem.
|