|
Step 1.
Click Start > Find/Files or Folders. Search all drives
for files with the name "KAK.HT?". Delete them all
and empty your recycle bin.
Step 2.
Click Start > Run and type Regedit.
Step 3.
Follow the paths using regedit and find:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\cAg0u
In the right window, look for 'C:\WINDOWS\SYSTEM\.hta'.
Highlight this key and delete it (Right click and choose delete).
Step 4.
Follow the paths using regedit and find:
HKEY_CURRENT_USER\Identities\Software\Microsoft\Outlook Express\5.0\Signatures
In the right window, look for 'Default Signature = 00000000'.
Highlight this key and delete it (Right click and choose delete).
Step 5.
Exit the Registry.
Step 6.
Click Start > Run and type Sysedit.
Click on the AUTEXEC.BAT file and look for the line
'@echo off>C:\Windows\STARTM~1\Programs\StartUp\kak.hta'.
If you find one, delete it from the line, save the change.
Skip to the END.
Step 7.
The worm will alter the 'Home Page' in the Microsoft Internet
Explorer browser. You will need to restore the original 'Home
Page'.
Step 8.
Click Start > Shutdown > Reboot.
Congratulations, KAK aka VBS/Kakworm has now been removed
from your system.
|