Kak: A "No-Click" Email Worm
This resource have been adapted from http://www.ukans.edu/~acs/virus/kak.shtml
Is Kak On My Computer?
Check for Kak infection on your computer by scanning with an up-to-date virus scanner. Or do this:
- Go to the Start button, then Find and click on Files or Folders.
- Enter
kak.htm
in the Named window. - Click on the Find Now button.
- If it finds
kak.htm
on your computer, go to the Removing Kak instructions.
Preventing Kak Infections
I. Patch the hole that Kak exploits:
- Download this Microsoft patch. Enter this URL in Internet Explorer's Address window: ftp://ftp.microsoft.com/peropsys/IE/IE-Public/fixes/usa/Eyedog-fix/x86/q240308.exe
- When Internet Explorer asks: "What would you like to do with this file?" choose "Run this program from its current location."
All this patch does is force Outlook 2000 or Outlook Express to give you fair warning when they encounter something like Kak. This is the warning:
"Some software (ActiveX controls) on this page might be unsafe. It is recommended that you not run it. Do you want to allow it to run?"
Academic Computing Services highly recommends you answer "No" to that question whenever you see it.
II. Close the door that unsafe scripts (such as Kak) might enter:
- Start Internet Explorer.
- Go to the Tools menu and click on Internet Options.
- Click on the Security tab.
- Click once on the Internet icon (to highlight it).
- Click on the Custom Level button-bar (lower part of dialog box).
- Under Download Signed ActiveX Controls ... select Enable
- Under Download Unsigned ActiveX Controls ... select Disable
- Under Initialize And Script ActiveX Controls Marked As Unsafe ... select Disable.
- Click OK.
- Click OK (again), then shut down Internet Explorer.
III. How to keep from inadvertently spreading this class of email worms to your correspondents in the future--optional
(Outlook Express users only)- Start Outlook Express.
- Go to the Tools menu and click on Options.
- Click on the Send tab.
- Where it says Mail Sending Format (near bottom), select Plain Text.
- Click OK
- Shut down Outlook Express.
(Outlook 2000 users only)
- Start Outlook 2000.
- Go to the Tools menu and click on Options.
- Click on the Mail Format tab.
- In the window to the right of Send In This Message Format (top), make sure it says Microsoft Outlook Rich Text. (NOT HTML).
- Click OK
- Shut down Outlook 2000.
Removing Kak
If you are certain your computer is infected with Kak (Check to make sure Kak is on your computer), follow these instructions to remove it.
I. Remove Kak files
- Go to the Start button, then Find, and click on Files or Folders.
- Enter
kak.htm
in the Named window. - Click on the Find Now button.
- Click once (to highlight)
kak.htm
and hit the DEL key. - Click the cursor back in the Named window
- Enter
*.hta
- Find the file
xxxxxxxx.hta
, where thexxxxxxxx
is eight random letters and numbers as the first name of this file and its second name (extension) is.hta
. - Click once (to highlight) and hit the DEL key.
II. Patch the hole that Kak exploits.
III. Shut Down, Then Restart Your Computer.
IV. Delete Default Signature (Outlook Express users only)
- Start Outlook Express.
- Go to the Tools menu and click on Options.
- Click on the Signatures tab.
- In the Signatures window (middle) click once (to highlight) on Signature #1
- Click on the Remove button. Likewise, remove any other Signatures.
- Click on the Apply button (bottom right).
- Click OK
- Shut down Outlook Express.
V. Clean Up Harmless Kak Residue ----- Optional
- Go to the Start button, then Find, and click on Files or Folders.
- Enter
Autoexec.bat
in the Named window. - Click on the Find Now button.
- Click once (to highlight) on
Autoexec.bat
in the bottom (found) window --- choose the firstautoexec.bat
if there is more than one. - Go to the File menu (top left), click on Rename, and type
Autoexec.Old
. - Go to the Start button again, then Find, and click on Files or Folders.
- Enter
AE.KAK
in the Named window. - Click on the Find Now button.
- Click once (to highlight) on
AE.KAK
in the bottom (found) window - Go to the File menu (top left), click on Rename, and type
Autoexec.Bat
0 responses:
Post a Comment
Thanking you for your comment(s). Hope you will visit this blog again!