Full Disclosure mailing list archives

Re: kak removal


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Sun, 01 Jun 2003 13:03:30 +1300

btw nick.. this http://www.claymania.com/kak-removal.html still
leaves an infection.. you forgot to start in safe mode.

As I'm clearly nowhere as "profressional" as you, perhaps you would 
like to explain the precise sequence of events and infection scenario 
that leaves a machine infected with Kak after following those 
disinfection steps?

This really intrigues me as Kak has no resident components, does not 
cause any of its files to be held open, nor takes any steps of any 
complexity to evade simple manual removal.  Thus it is impossible for 
Kak to survive the removal process described at that URL, as 
innumerable tests of my own and many others have shown, and as is 
evidenced by the hundreds of ordinary, and often quite "system 
naive", computer users who have followed those steps and entirely 
removed Kak from their machines.

Perhaps you, as the self-styled consummate "profressional", could 
explain why starting in safe mode is necessary?  I would greatly 
appreciate the chance to understand the fundamental error you say I 
have made.  Further, to learn of this from such a great and respected 
master "profressional" as yourself would be immeasurably valuable to 
me and my future work in this field, where my efforts to date 
obviously must seem as a speck of sawdust to the mote of your own 
valuable contributions...


Regards,

Nick FitzGerald
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: