Spyware & Virus Directory
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
Wscript.Kakworm Removal Tool
Updated: August 24, 2005 03:28:32 PM GDT
Type: Removal Information
SUMMARY
NOTE: There are two versions of this worm:
Wscript.KakWorm and
Wscript.KakWorm.B. The tool referenced on this page is only for the Wscript.KakWorm.
Please go
here for the Wscript.KakWorm.B removal tool.
How to obtain and use the Wscript.KakWorm removal tool
To use the tool, we recommend you download the
Fixkak.exe file to your Windows desktop or to a folder on your hard disk. After the file finishes downloading, follow these steps:
- Close all programs.
- Double-click Fixkak.exe to run it. A removal tool dialog box will appear.
- Click Remove. One of the following three messages will appear after you click Remove:
- "Your computer is not infected." (Your system is safe, and you do not need to do anything.)
- "Your computer has been successfully restored." (The worm has been removed, and your system is now free of the damaged done by the worm.)
- "An error occurred during execution of this program." (The removal tool has encountered a problem that it cannot fix. You will need to manually remove the virus. Refer to this page for manual removal instructions.)
What the tool does
The Wscript.KakWorm removal tool makes the following changes to the system:
- It searches for the file Kak.hta that the worm placed in the StartUp folder. If the file is present and the CRC (cyclic redundancy check) matches, it deletes this file. (A CRC is a number derived from a block of data that detects corruption when data is transferred.)
- It checks for the cAgOu value in the following registry key:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
If this value is present, it is deleted.
- The tool searches all of the keys under:
HKEY_CURRENT_USERIdentities[SUBKEYS]SoftwareMicrosoftOutlook Express5.0Signatures
where [SUBKEYS] represents all of the possible subkeys of HKEY_CURRENT_USERIdentities
- It searches for the Default Signature value in the Signatures key for Outlook Express 5.0. If present, this value is deleted.
- It searches for and deletes Kak.htm from the Windows folder.
- It restores the original Autoexec.bat file.
- If present, the tool will delete the