Quote:
F-Secure Anti-Virus detects the worm. When the worm has been detected, the user should delete the following files, if they exist:
C:\Windows\kak.htm
C:\Windows\System\(filename).hta
where (filename) is a variable, and it changes from one system
to another
C:\Windows\Start Menu\Programs\Startup\kak.hta
[French only] C:\Windows\Menu Demarrer\Programmes\Demarrage\kak.hta
The "autoexec.bat" file can be restored by renaming "C:\AE.KAK" to "C:\autoexec.bat".
Kak uses a known security hole in Microsoft Outlook Express to create the local HTA file.
Mine was an unusual case, because I got infected twice, that complicated things a bit. But I'm clean now.