Guest guest Posted April 26, 2000 Report Share Posted April 26, 2000 The following warning applies only to users of Microsoft Outlook Express version 5. Today my computer became infected with a virus called " kak.worm " , which is spread via Email. Only computers using Outlook Express, running on Windows 95 or 98, are susceptible to this virus. The kak.worm virus arrives in a normal Email which apparently has no attachment. Once the user receives an infected Email message, and opens the infected message or views the message in the message pane, the worm modifies the system so that the next time the machine is started, the standard Email signature of the user is replaced with an HTML file infected by the virus. After that, EVERY EMAIL SENT by the infected computer contains a copy of the virus, which has replaced the user’s signature. The kak worm activates on the first day of each month if the infected machine is restarted after 5 PM. It displays a message, then tries to shut down Windows, but no permanent damage is done. If you are running Outlook Express version 5 on Windows 95 or 98, I recommend that you do the following things: Check your Email signature by clicking “Tools” then “Options”, then click the “Signatures” tab. Look down at the bottom of the window. If the “File” option button is selected, and “KAK.HTA” appears in the “file” box, your machine is probably infected. If you see the “KAK.HTA”, DELETE IT FROM THE “FILE” BOX. This will prevent your system from spreading the virus. Run your virus detection program against EVERY FILE TYPE on your system. Do not just run it against “*.exe” program files. If you do not have a virus detector – get one. The link at the bottom of this Email is to F-Secure’s web site, which describes the kak virus. F-Secure sells a virus detector. Network associate’s “McAfee Shield” is another option. Run a search of your entire C: drive for filename “kak*.* by opening the “Exploring” file manager program, clicking on the C: drive, and pressing the F3 button. You will likely find “kak.hta”. It will probably be in your “Temporary Internet Files” folder. Delete the kak file. Shut down and restart your system. Repeat the above 4 steps. As a security precaution, I have changed my eGroups subscription mode to “No mail / Web only”. I have resubscribed using my Yahoo Email address instead of my home address, in the hope of minimizing future problems. Sorry for the hassle. The F-Secure link is below. http://www.datafellows.com/news/2000/20000330.html Jim Clary __________________________________________________ Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.