Ack! NAV just intercepted a virus!!!

dennilfloss

Past Lifer 1957-2014 In Memoriam
Oct 21, 1999
30,509
12
0
dennilfloss.blogspot.com
About one hour ago, when I opened Outlook Express, just as I was receiving an email from a Mr. Noseworthy (the manager of my moving company, so this was an expected email), a bright red Norton Antivirus screen appeared with the following message:

"The file C:\...et Files\Content.IE5\09MJWDMB\Your upcoming relocation.dat is infected with the WScript.KakWorm virus.

What would you like to do?

Stop Continue Repair Delete Exclude
"

Since this was a needed email, I chose Repair but NAV was unable to repair it. So I chose Delete which caused a BSD.

"An exception OE has occurred at 0028:C1944ADF in VxD Navap (02) + 0000D4AF. it may be possible to continue normally."

I clicked 'any key to resume...' and my email showed up in the preview pane with an Microsoft little warning box that an unsafe Active X control was present. I closed the little box and read the message (I have QuickView Plus integrated into Explorer and Outlook Express), then deleted it and emptied my 'deleted files' bin.

I then went to upgrade the signatures on my Norton Antivirus (which I run in realtime mode) and Ontrack's Fix-It Utilities 2000 improved version of Trend's PC-Cillin (which I run in on-demand mode). They were already up to date (I update every Sunday evening). I then scanned all files on my hard disk 2 partitions with NAV twice, paused this one and scanned all files with Ontrack's PC-Cillin twice.

These 4 scans of all files declared my hard disk clean of infected files. The deleted folder in my Outlook Express is empty. I phoned my moving company and they said they caught this virus on Friday and had cleaned it from their system during the weekend. I told them that if this email was sent today, then it appears that their cleaning was unsuccessful.

So I now have a system which reads as clean on 2 major antivirus programs. I have not rebooted yet. Is there any place I should look to be sure that the virus is gone(in DOS, ack!?) or can I be reasonably sure that my system did not get infected because NAV intercepted the virus in time?

I am very paranoid because in September 1999 a virus nuked my AX6BC mobo. :|

Thanks for any input. I won't reboot until I feel safe. :(
 

erikistired

Diamond Member
Sep 27, 2000
9,739
0
0
from www.symantec.com:

VBS.KakWorm spreads using Microsoft Outlook Express. It attaches itself to all outgoing messages via the Signature feature of Outlook Express and Internet Explorer newsgroup reader.

The worm utilizes a known Microsoft Outlook Express security hole so that a viral file is created on the system without having to run any attachment. Simply reading the received email message will cause the virus to be placed on the system.

Microsoft has patched this security hole. The patch is available from Microsoft's website. If you have a patched version of Outlook Express, this worm will not work automatically.

Click here to download tool to repair Wscript.Kakworm damage

the url is http://www.symantec.com/avcenter/venc/data/wscript.kakworm.fix.html

you can download a file here that is supposed to kill the thing. i've actually run down directions to killing the thing in past manually, but this thing should do the same. i think it also shows a few registry keys to patch up.

~erik
 

Orange Kid

Elite Member
Oct 9, 1999
4,457
2,230
146
It was just the page from symantec that fisher copy to here.
Looks like you aren't the only one, but there is a cure :cool:

Edit ----- mail was returned --- got the right addy in your profile?
 

dennilfloss

Past Lifer 1957-2014 In Memoriam
Oct 21, 1999
30,509
12
0
dennilfloss.blogspot.com
The kakworm fix dialog box says that my system is not infected. Neither does the kakwormB tool. Looks like NAV caught it in time. I'll hold on those tools though, just in case. :)

As far as I can tell, my email addy in my profile is correct. I received mail on that account just yesterday. Go figure. :)
 

GT1999

Diamond Member
Oct 10, 1999
5,261
1
71
Kak spreads like you won't believe.. it's #1 or close to it right now for the most wild viruses. It isn't that dangerous, though. We had all of our machines at work with it on there. That's when it was my job to install Windows 2000 Pro, SP1, ZoneAlarm, NIS v2.0 and NAV 2000 on ALL of the machines to replace Win98SE.

Another way to check and see if there's anything poking around in your system is to use msconfig under run. Go to autoexec.bat and your win.ini and startup tabs and look for anything out of the ordinary. Whenever I see something new that doesn't have the program vendor's name in it I just do a search for the file, look it up under properties and find out who the hell made it.

Hope that helps a bit. ;) Btw, good to see you'r virus free as of right now.
 

dennilfloss

Past Lifer 1957-2014 In Memoriam
Oct 21, 1999
30,509
12
0
dennilfloss.blogspot.com
Geekish Thoughts,

There doesn't appear to be anything suspicious in the three places you mentioned (though the win.ini files are numerous and most mean nothing to me ;)).

Thanks for the info. :)

BTW, according to Windows Update, all my patches were up to date. Yet that thing would have worked if NAV hadn't caught it.
 

JimMc

Platinum Member
Oct 9, 1999
2,305
0
0
dennilfloss--unfortunately, I don't think WIndows Update catches all the Outlook problems, I believe there is a seperate page for that. Check here Outlook Patches
 

dennilfloss

Past Lifer 1957-2014 In Memoriam
Oct 21, 1999
30,509
12
0
dennilfloss.blogspot.com
Mine isn't Outlook 98 or 2000, it's Outlook Express (not listed there). I went to look for Outlook Express downloads, tried to install the two most recent and a little window popped out saying they weren't needed on this system. :)

I guess my IE 5.5 and tools is up to date then. ;)
 

hubbs

Platinum Member
Mar 26, 2000
2,442
0
0
My aunt got this same virus. I deleted all instances of this file but I could for some reason not get rid of one of the hidden files in the windows directory. But I did stop it from sending it to other people by going into her signature options and deleting the file attachment on ever message and click on the text option and it no longer sends that file to other people. But I'll have to run that program to get it out when I go back this weekend. Thanks this helped me out too.