Home > Norton Anti Virus > Norton Anti-virus Protection & Wscript.kakworm -- Please HELP!

Norton Anti-virus Protection & Wscript.kakworm -- Please HELP!

neonrider replied Feb 21, 2017 at 2:59 PM Keep current hard drive? Click the + in front of 'Microsoft'. Since ZoneAlarm doesn't turn on intruder logging by default, though, you should: click on the main dialog box's Alerts button, then check the "Log alerts to a text file" check box. spyware eradicators won't touch it but you can get rid of it manually or use some other devices. http://directcomputerrepair.com/norton-anti-virus/norton-anti-virus.html

The Microsoft Instructions Newsletter Microsoft has just released a document which describes how users of various Microsoft Systems Software can protect themselves. NOTE: As noted previously, Wscript.KakWorm is spread as part of an email message--not an attachment. Do not use the reset button. Select the 'View' menu and select 'Layout...'.

If this does not resolve the problem, or if you prefer to work in MS-DOS mode, then please see Solution 2. Simply reading the received email message causes the virus to be placed on the system. Clear deleted items folder If you do not have Outlook Express set to clear deleted email when you close the program, clear this folder before you send or receive email. Restart the computer in Safe mode.

One indication of this worm--though it does not occur on all systems--is the message "Driver or memory error" that appears briefly as Windows starts. Keep repeating the search until all references to kak have been removed and you see the message "Cannot find kak." Exit the System Editor, and then click Yes to save changes. antivirus.vt.edu Enter your search here: Quicklinks Home Virus Alerts Downloads Symantec Endpoint Protection for Windows Symantec AntiVirus for Mac Symantec Endpoint Protection Known Issues Computer Security Videos Help antivirus.vt.edu Do not accept applications that are unsigned or sent from unknown sources.

Locate and delete the line that reads: C:\Windows\Start Menu\Programs\StartUp\kak.hta NOTE: Some variants of this worm insert one or both of the following lines instead of or in addition to the previous Click on the above link, I'll tell ya all about it. Of course it has the usual Melissa like protocol. Bo's Mission statement Should I Worry About Code Red?

The patch is available at: http://www.microsoft.com/technet/ie/tools/scrpteye.asp If you have a patched version of Outlook Express, this worm will not work automatically. While computers running either unpatched Microsoft Outlook or Outlook Express can be infected, only Outlook Express can automatically spread the infection. If you want to know the types of viruses to watch for, avoid the news headlines and check out Trend Micro's real-time virus watch. The System Configuration Editor opens.

Please, before you send a report of a virus....be sure it is one. click to read more Uncheck Enable Startup Menu, click OK, and then click OK again. 5. Close Outlook Express. I know you can do it!

In addition to the 'Run' folder some users will have a 'Run-' folder. have a peek at these guys Read An Email, Get Infected You can’t get a virus simply by reading an email, right? Symantec has also created an interactive tutorial to help you get rid of this worm. Remove a file entry Follow these steps to remove an entry from the Autoexec.bat file: 1.

As usual Symantec has done the job that Microsoft won't do. Remove the worm entry from the registry. Additional precautions that you can take: Some threats, such as this one, use the VBScript computer language to run. check over here In addition, the registry key: HKLM/Software/Microsoft/Windows/ CurrentVersion/Run/cAgOu is added which causes the worm to be executed each time the computer is restarted.

Install the Microsoft patch If you have not already done so, install the Microsoft Scripting update, which is available at: http://www.microsoft.com/technet/sec...n/MS00-043.asp For help with this, see the document, How to download Type sysedit and then click OK. lets get informed shall we?

You may have to register before you can post: click the register link above to proceed.

To enable show all files: Follow these steps to make sure that Windows is set to show all files: Start Windows Explorer. If this is the case, then you must do this for each one. Because the Windows Scripting Host is an optional part of Windows, it can be safely removed from your computer. (Some programs, however, need Windows Scripting Host in order to function properly.) Delete worm-infected files from Quarantine.

Delete the emails in your inbox if you didn't when you removed the virus. To remove the worm entry from the Autoexec.bat file: At the DOS prompt, typeedit autoexec.bat and then press Enter. These three programs are all freeware. this content If you know who sent you the email, contact them and tell them that their system is infected by this worm. "We are all born ignorant, but one must work hard