Kakworm

     
SearchSearch

Search this site or the Internet.

Google
Web CKnow.com
Hot TopicsHot Topics
Hot UtilitiesHot Utilities

Utilities that may help you...

 

NotesNotes

DewaHost

DewaHost offers premium Web hosting service starting from $8.95/month and a high speed file hosting service - FileBurst!

No Spam
CKnow does NOT spam.
E-mail is easily forged.

Labelled with ICRA
 

Kakworm

Kakworm (KAK) is a worm. It takes advantage of a security vulnerability in Microsoft's Internet Explorer browser and Outlook Express mail program. A patch for this vulnerability has been published by Microsoft and should be installed (Microsoft Security Bulletin MS99-032). Non-Microsoft browsers and mail programs are not affected.

KAK is transmitted embedded in the HTML signature to a message. Users don't see it there because there is no displayable text (KAK is written in JavaScript).

Users do not need to click on any attachment or perform any action for KAK to activate. All that is necessary is for the user to view an infected message in the mail preview window (or open the mail and view the message).

Once activated, KAK saves the file KAK.HTA into the Windows Startup folder. The next time the computer is started, KAK.HTA runs and creates KAK.HTM in the Windows directory. The registry is changed so that KAK.HTM is included as a signature on all outgoing mails. This activity is controlled by a new \AUTOEXEC.BAT file (the original file is saved to \AE.KAK).

After 5pm on the 1st of any month the worm displays the message "Kagou-Anti-Kro$oft says not today" and then shuts the computer off.

KAK is based on Bubbleboy, the first worm able to spread without a user having to open an attachment.

CIH SpacefillerLaroux

Virus Tutorial Map

Tutorial Home Page

Introduction to Viruses: Virus Behavior | Number of Viruses | Virus Names | How Serious? | Good Viruses? | Why Write Viruses? | Hardware Threats | Software Threats | Virus Droppers

Types of Viruses

History of Viruses (Summary)

Virus Protection: Scanning | Integrity Checking | Interception | AV Product Use Guidelines | File Extensions | Safe Computing Practices (Safe Hex) | Outlook and Outlook Express | Disable Scripting | Backup Strategy | On-going Virus Information

Miscellaneous: Anti-Virus Software | Tutorial License | Virus Plural | Partition Sector | DOS Boot Sector | FDISK/MBR | False Authority | Logic Bombs | Trojans | Worms | Hoaxes



Last Changed: Thursday, February 02, 2006
Navigation: Computer Knowledge Home :: Virus Tutorial Home :: Kakworm