Dear All,

Quite a few watchful list members have notified me that my previous post to
this list was infected by the VBS/Kakworm virus.
This is an e-mail worm virus that is activated by pre-viewing the message in
combination with Microsoft Internet Explorer v5.0. If you have read or
pre-viewed my e-mail with the topic: MI Re: Gradient/slope shading and you
are using Microsoft Internet Explorer 5.0 please take action.

The following extract is from a virus removal utility and describes the
virus:

Memory-resident: In macro environment

This is an email worm. It only infects users with Microsoft Internet
Explorer V5.0. If the user opens or previews an infected email message the
worm drops KAK.HTA program into Windows startup folder so that it runs on
starting Windows.
The KAK.HTA file creates C:\WINDOWS\KAK.HTM hidden file and changes the
Microsoft Outlook Express registry settings so that the KAK.HTM is
automatically included in every outgoing message as a signature file.
KAK.HTA also changes the Windows registry key
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\cAg0u so that it includes
the name of the worm file. On the 1st of any month the worm displays the
messagebox "Kagou-Anti_Kro$oft says not today" and runs Windows shutdown.

First reported in January 2000.

Recovery:

To disinfect infected objects delete all macros belonging to the virus.


My sincere apologies to anyone infected,
Roeland


Roeland van der Spek
Mercator Geosystems
www.mercatorgeo.nl

----------------------------------------------------------------------
To unsubscribe from this list, send e-mail to [EMAIL PROTECTED] and put
"unsubscribe MAPINFO-L" in the message body, or contact [EMAIL PROTECTED]

Reply via email to