The Disability-Research Discussion List

Managed by the Centre for Disability Studies at the University of Leeds

Help for DISABILITY-RESEARCH Archives


DISABILITY-RESEARCH Archives

DISABILITY-RESEARCH Archives


DISABILITY-RESEARCH@JISCMAIL.AC.UK


View:

Message:

[

First

|

Previous

|

Next

|

Last

]

By Topic:

[

First

|

Previous

|

Next

|

Last

]

By Author:

[

First

|

Previous

|

Next

|

Last

]

Font:

Proportional Font

LISTSERV Archives

LISTSERV Archives

DISABILITY-RESEARCH Home

DISABILITY-RESEARCH Home

DISABILITY-RESEARCH  January 2001

DISABILITY-RESEARCH January 2001

Options

Subscribe or Unsubscribe

Subscribe or Unsubscribe

Log In

Log In

Get Password

Get Password

Subject:

Re: stitch in time: virus protection

From:

John Homan <[log in to unmask]>

Reply-To:

John Homan <[log in to unmask]>

Date:

Thu, 25 Jan 2001 22:13:54 +1100

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (254 lines)

 Good morning all,

a follow up on the previous hard luck story. If you go to this address in
the Symantec (norton) website, you will find two downloads that will check
your system for two seperate manifestations of Kakworm. I downloaded both of
them to my 'download' directory, then found them back in there through
'windows explorer, and executed them by double click. they both told me that
my system is clean, which was very reassuring, alternately it may tell you
that 'your computer is successfully restored'. You can also feel good about
that: you had a problem but it is fixed, or it may tell you that you have
problems it can not fix.

I suggest you read the below page carefully, follow the procedure, and  - if
you haven't done so yet - install the patch I referred to earlier.

Leave the two fixer downloads in your directory: when in doubt you can run
them again.

Good luck, rgds John

http://www.sarc.com/avcenter/venc/data/kak.worm.b.removal.html

© 1995-2001 Symantec Corporation.
All rights reserved.
Legal Notices
Privacy Policy


  Kak.Worm.B Fix
The KAK.Worm.B fix tool only works under Windows 9x or Windows NT operating
systems

To use the tool, we recommend you download the fixkakb.exe file to your
Windows desktop or to a folder on your hard drive. After the file finishes
downloading:

Close all programs.
Double-click the file fixkak.exe to run it. A Repair Tool dialog box will
appear.
Click Remove. One of the following three messages will appear after you
click Remove:
Your computer is not infected. (Your system is safe, and you do not need to
do anything.)
Your computer has been successfully restored. (The worm has been removed,
and your system is now free of the damaged done by the worm.)
An error occurred during execution of this program. (The removal tool has
encountered a problem that it cannot fix. You will need to manually remove
the virus. Refer to this page for manual removal instructions.)
What the tool does

The tool searches for the DAY.HTA file dropped into the Start up directory.
If the file is present, the tool will delete it.

The tool will remove the DEFAULT.HTM, if it exists, from the Windows Command
directory.

The tool will restore the original AUTOEXEC.BAT from the DAYS.DAY created by
the worm. The tool will delete DAYS.DAY after the restoration.

The tool will check cDays value in the Run registry key. If the value
present, then the tool will extract the string form this value (string
contains the name of the file dropped into the system directory) and delete
the value. Then the tool will delete the file, whose name was extracted from
the cDays value.

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run

The tool will enumerate through all the keys under HKCU\Identities,
searching for the Default Signature value in the Signatures key for Outlook
Express 5.0. The tool will delete this value, if it was found.

HKEY_CURRENT_USER\Identities\???\Software\
Microsoft\Outlook Express\5.0\Signatures


??? represents all the possible subkeys of HKCU\Identities

The tool will delete the 00000000 sub key created by virus, if sub key is
present.

HKEY_CURRENT_USER\Identities\???\Software\Microsoft\
Outlook Express\5.0\Signatures\00000000

NOTE: The tool is unable to restore the default signature for Outlook
Express if existed before being infected. The worm does not save this
information.

Download: fixkakb.exe

fixkakb.exe is digitally signed. Symantec recommends only using copies of
fixkakb.exe that have been downloaded directly from this site. The following
tool is available to verify the digital signature of fixkakb.exe:

File: chktrust.exe

To verify the digital signature of fixkakb.exe using chktrust.exe:

Download chktrust into the same directory where fixkakb.exe is located.
Launch the MS-DOS prompt via the Start/Programs/MS DOS prompt menu.
Change to the directory where fixkakb.exe and chktrust.exe are stored. If
the files were saved to the desktop folder the command to enter in the MS
DOS prompt is:

cd \windows\desktop


Type the following command to check the digital signature of fixkakb.exe:

chktrust -i fixkakb.exe


If the digital signature is valid you will see a dialog asking the following
question:

Do you want to install and run "Fix Utility B" signed on 08/10/2000 1:06 PM
and distributed by Symantec Corporation?


The date and time that are displayed in this dialog will be adjusted to your
timezone if your computer is not set to the Pacific time zone. For example,
if you live in the Eastern time zone the date and time you will see will be
08/10/2000 4:06 PM.
You may also see a DOS box with the entry
"c: Result:0" (without the quotes) . If you do, then the test was positive
and the file is confirmed as being from Symantec.


If the above messages do not appear or the date and time are not properly
adjusted for your timezone on the original message then do not use your copy
of fixkak.exe. It is not from Symantec.


If dialogue from steps 5 and 7 above appear and the text is correct for your
timezone per step 6, this copy of fixkakb.exe is from Symantec.
Click the "Yes" button to dismiss the chktrust dialog.
Type exit and then press the enter key. This will terminate the MS DOS
session.


Updated: October 05, 2000
  Tell a Friend about this Write-Up

   Security Updates
 Symantec AntiVirus Research Center and SWAT

 Download Virus Definitions
 Keep your protection up to date

 Virus Encyclopedia
 Search for Information on Viruses, Worms and Trojan Horses

 Virus Hoaxes
 Information on Virus Hoaxes

 Newsletter
 Email Sent from the Symantec AntiVirus Research Center

 Virus Calendar
 Monthly Calendar Listing Trigger Dates for Viruses

 Reference Area
 Learn About Virus Detection Technologies

 Submit Virus Samples
 Send Suspected Threats for Review








----- Original Message -----
From: John Homan
To: Young, Philip ; WILSON NAOMI ; Wex, Val ; Thompson, Kylie ; Stonier
Russell ; Stehlik Daniela ; Stark, Wayne ; Spencer, Nancy ; Searles Roz ;
Schroor, Sirk & Jenny ; Schnick, Yvonne ; Schick, Joselyn ; Saunders, Nick &
Jill ; Rodgers, Steve ; Bert & Desley Rial ; Qiuinn, Des ; Sue Pullar ;
Pidgeon, Jennie ; Patterson, Mark ; McVilly, Keith ; Martin, Stephen ;
Macrae, Campbell ; Ludwig, Bill ; Leipoldt, Erik ; Lang, Bill ; Michael KNOX
; Kennedy Mark ; Jones Ken ; Joachim, Ron ; Hutcheon Rod ; Heyen, Heather ;
Herbert, Cathy ; Henry, Maree ; Jeff Heath ; Harris Sue ; Harle, Dion ;
Graham, Sara ; gihan ; Frisch, Jack ; Ebelt, Len ; Dennien, Karen ; Den
Exter, Artie ; Davidson, Gail ; Crowley, Jan ; jack crigan ; Charlie
Covington ; Copping, Lorraine ; Cooper, Roz ; Conway, Tony ; Colyer, Lyn ;
Collins, Suzan ; Carroll, Mary ; Byrne, Anjel ; Burridge Robyne ; Brockie,
Maree ; Brett, Mike ; Boyd, Janet ; Bowser, Kerrie ; Boorman, Fiona ;
kathryn boles ; Eric Boardman ; Bennett, Ian & Pamela ; Beazley, Barbara ;
Beasley Steven ; Richardson Angela ; Alexander, Dianne ;
[log in to unmask] ; [log in to unmask] ; [log in to unmask]
Sent: Monday, January 22, 2001 10:35 PM
Subject: stitch in time: virus protection




Good morning all,

This is a miserable story with - I hope - a happy ending.

Last week I spent $A120 to have a version of 'kak worm' removed from my
computer system, after it did some unspeakable things and caused me much
grief. I had been relying on Nortons for protection which proved futile: it
did not pick the contamination.

With the help and advice of friends I have taken some actions that I believe
will make my system safer, and I offer them here for your consideration:

The conventional wisdom is that viruses travel with attachments. To make the
system more secure against that I installed Inocculate and set up some
routines to make it easy to check attachments for viruses.

It then came as a shock to me to find that worms attach themselves to email
addresses, and propagate that way. There is a weakness in Internet
Explorer - a wormhole? - that allows this to happen. Fortunately MS have
developed a 'patch' which can be downloaded (for free) which when installed,
will close this loophole.

It can be found at the following address:
http://www.microsoft.com/msdownload/iebuild/scriptlet/en/scriptlet.htm
Just follow the prompts.
Install InocculateIT
Un-install your present antivirus programme: my computer > controlboard >
install/un-install software.
Create a new directory: C:\ download
Download from: http://antivirus.ca.com - file: IPESetup.exe to download
directory.
Access IPESetup.exe in the download directory, and double click. Then just
follow the prompts
Write down your Customer number

Viruses & attachments
Do not open attachments:
Create new directory: C:\ program files\ internet explorer\ dirty linen
Create shortcut for dirty linen on desktop
Open email > right click on attachment > save as > dirty linen > save
Access dirty linen > higlight attachment (if more than one: > edit > select
all) > right click > InoculateIT PE > clean/dirty verdict
Access viruslog.txt - C:\ program files\ InocculateIT PE\ viruslog.txt
Create shortcut for viruslog.txt on desktop.

Good luck, rgds John

________________End of message______________________

Archives and tools for the Disability-Research Discussion List
are now located at:

www.jiscmail.ac.uk/lists/disability-research.html

You can JOIN or LEAVE the list from this web page.

Top of Message | Previous Page | Permalink

JiscMail Tools


RSS Feeds and Sharing


Advanced Options


Archives

April 2024
March 2024
February 2024
January 2024
December 2023
November 2023
October 2023
September 2023
August 2023
July 2023
June 2023
May 2023
April 2023
March 2023
February 2023
January 2023
December 2022
November 2022
October 2022
September 2022
August 2022
July 2022
June 2022
May 2022
April 2022
March 2022
February 2022
January 2022
December 2021
November 2021
October 2021
September 2021
August 2021
July 2021
June 2021
May 2021
April 2021
March 2021
February 2021
January 2021
December 2020
November 2020
October 2020
September 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
December 2019
November 2019
October 2019
September 2019
August 2019
July 2019
June 2019
May 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
October 2018
September 2018
August 2018
July 2018
June 2018
May 2018
April 2018
March 2018
February 2018
January 2018
December 2017
November 2017
October 2017
September 2017
August 2017
July 2017
June 2017
May 2017
April 2017
March 2017
February 2017
January 2017
December 2016
November 2016
October 2016
September 2016
August 2016
July 2016
June 2016
May 2016
April 2016
March 2016
February 2016
January 2016
December 2015
November 2015
October 2015
September 2015
August 2015
July 2015
June 2015
May 2015
April 2015
March 2015
February 2015
January 2015
December 2014
November 2014
October 2014
September 2014
August 2014
July 2014
June 2014
May 2014
April 2014
March 2014
February 2014
January 2014
December 2013
November 2013
October 2013
September 2013
August 2013
July 2013
June 2013
May 2013
April 2013
March 2013
February 2013
January 2013
December 2012
November 2012
October 2012
September 2012
August 2012
July 2012
June 2012
May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004
September 2004
August 2004
July 2004
June 2004
May 2004
April 2004
March 2004
February 2004
January 2004
December 2003
November 2003
October 2003
September 2003
August 2003
July 2003
June 2003
May 2003
April 2003
March 2003
February 2003
January 2003
December 2002
November 2002
October 2002
September 2002
August 2002
July 2002
June 2002
May 2002
April 2002
March 2002
February 2002
January 2002
December 2001
November 2001
October 2001
September 2001
August 2001
July 2001
June 2001
May 2001
April 2001
March 2001
February 2001
January 2001
December 2000
November 2000
October 2000
September 2000
August 2000
July 2000
June 2000
May 2000
April 2000
March 2000
February 2000
January 2000
December 1999
November 1999
October 1999
September 1999
August 1999
July 1999
June 1999
May 1999
April 1999
March 1999
February 1999
January 1999
December 1998
November 1998
October 1998
September 1998


JiscMail is a Jisc service.

View our service policies at https://www.jiscmail.ac.uk/policyandsecurity/ and Jisc's privacy policy at https://www.jisc.ac.uk/website/privacy-notice

For help and support help@jisc.ac.uk

Secured by F-Secure Anti-Virus CataList Email List Search Powered by the LISTSERV Email List Manager