Was this page useful? For further information about BubbleBoy, see the description: https://www.F-Secure.com/v-descs/bubb-boy.shtml Removal Automatic action Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect The above steps should disable the worm. Now click on [View] - [Folder Options] then the [View Tab].

Clear deleted items folder. 10. HKEY_CURRENT_USER\Identities\Software\Microsoft\Outlook Express\5.0\signatures\Default Signature This default signature points to the KAK.HTM file loaded into the Windows directory. Users may also want to disable 'Active Scripting' in the 'Restricted Sites' zone and set E-Mail to run in the 'Restricted Sites' zone. If neither Outlook Express nor MS Internet Explorer 5.0 are installed, the worm is not able to infect the machine. https://www.f-secure.com/v-descs/kak.shtml

Once the user receives an infected e-mail message and opens or views the message in the preview pane, the worm creates a file "kak.hta" to the Windows Startup directory. Delete infected files from Quarantine.

H_KEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run/cAgOu You can also delete the references to KAK in autoexec.bat (you find it by going to windows/system and double clicking on sysedit.exe). Removal of this Internet worm consists of several steps: * close email client(s)* install the MS patch mentioned above* remove KAK.HTA and/or KAK.HTM* turn off "preview pane"(optional)* delete the default email What makes this worm unique is its ability to infect a system by someone simply reading or previewing an email message. F-Secure Anti-Virus detects the worm.

In theory, it is now safe to use Outlook Express 5 for reading and sending Email -- but don't... Sixth, edit AUTOEXEC.BAT and delete the two lines involved in creating and deleting kak.hta in the Windows Startup folder. En cas de réutilisation des textes de cette page, voyez comment citer les auteurs et mentionner la licence. If AE.KAK exists in the root of C: and no changes have been made to AUTOEXEC.BAT since Kak infested the machine, you can delete (or rename) AUTOEXEC.BAT then rename AE.KAK to

Install the Microsoft patch. Check the Windows Startup folder and delete any file there named kak.hta.

The key it adds to the registry is: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cAg0u The .hta file that the virus creates and executes in the future is saved to Windows System directory. The Kak worm reveals its presence on a system on the 1st of any month after 6:00 PM, when it displays "Kagou-anti-Kro$oft says not today!", and then shuts down windows. Methods of Infection Opening email messages which are composed in HTML format and which contain the script will install the Internet worm on supported systems as mentioned above. For Home For Business For Partners Labs Home News News From the Labs Incidents Calendar Tools & Beta Tools & Beta Flashback Removal Database Updates Rescue CD Router Checker iOS Check

Delete all files detected as kakworm, kakworm.dr, etc. Now REBOOT your P.C. Learn More About About Company News Investors Careers Offices Labs Labs Labs blog Latest threats Remove threats Submit a sample Beta programs Support Support Knowledge base Software updates Community Support Tools The signature is set to include the file "C:\WINDOWS\kak.htm" and is set as the default signature such that the worm is spread on all outgoing email if the signature is included.

Email messages written in HTML format will be coded with the Internet worm on infected systems due to the default signature modification on infected systems. Click on the "Windows Setup" tab and double click on "Accessories". For more details on this vulnerability and to obtain a patch from Microsoft, see this link:Microsoft Security Bulletin To obtain a patch from Microsoft, see this link:https://www.microsoft.com/msdownload/iebuild/scriptlet/en/scriptlet.htm For current security bulletins After all this, you will almost surely have one or more messages carrying the Kak code in your Email folders.

