How do I identify the infected email in a Msoft Outlook backup ?

E

envirographics

In readiness for a rebuild, I backed up my Outlook Express inbox and
sent items emails by exporting them into Msoft Outlook, then from
there I exported the inbox as a pst file, likewise the sent times.

After the rebuild I import the Inbox_backup.pst into Msoft Outlook,
ditto the Sent Items. No virus warnings yet. Then launch Outlook
Express and Import Inbox from Msoft Outlook. When so far into the
proceedings my McAfee detects the kak virus, saying found
C:\Windows|temp|2376kak.tmp The delete option says 'unable to
delete', same for quarantine or clear, only exclude and stop allow
continuation of import. Look for 2376kak.tmp in temp afterwards and
not there !

Is it that just McAfee cannot deal with a virus in this way or are all
anti-virus progs unable to delete or clean emails already in the
system, when being imported as such ?

I wish it would say which email was afected, it doesn't, the only
guide is that you see a text saying opening 213 of 645, moving rather
fast generally with pauses, so you remember the last pause, but is
email 1 the oldest you have, or youngest?

Why, despite running Mcafee on a PC check on C drive, did it not see
this email having kak before I backed the emails up ????? THATS
WHATS WORRYING, it was up to date !

Envirographics
 
R

Reece Bevan

The following link should help:
http://www.virusbtn.com/support/tutorials/kak.xml

Also, in OE/Outlook use the "text find" to locate "script language". This
should be the guilty email. There are few good reasons to put script in an
email.

Incidentally, NOD32's email checker does stop KAK.

Regards - Reece Bevan - London, UK

newsgroups (at) lon web des <dot> co (dot) uk
(The above is genuine if you use your initiative !!)
*******************************************************
 
E

envirographics

Reece, and Michael,
Thanks for the replies.
I have looked at the options available atop the Msoft Outlook window
but cannot see how to do the text find on script language. Also have
asked a 'guru' at work and he is also puzzled.
Perhaps you can give me a talkthrough of how to do it please and which
menus etc to click on, what to type in etc..please.
Is it best done in Msoft Outlook or Outlook Express,...the backups
open in Msoft Outlook first.
Thanks
Envirographics
 
F

FromTheRafters

envirographics said:
Reece, and Michael,
Thanks for the replies.
I have looked at the options available atop the Msoft Outlook window
but cannot see how to do the text find on script language. Also have
asked a 'guru' at work and he is also puzzled.

It doesn't contain that string anyway, it begins like this:

<SCRIPT><!--
function sErr(){return =
true;}window.onerror=3DsErr;scr.Reset();scr.doc=3D"Z

Here is the part that tells it to write that part:

WriteLine('<SCRIPT><!--');t3.write('function sErr(){return =
true;}window.onerror=3DsErr;scr.Reset();scr.doc=3D\"Z

So this string...

true;}window.onerror=3DsErr;scr.Reset();scr.doc=3D"Z

.....will be in there twice for each occurrence of a KAK carrying
e-mail.

HTH
Perhaps you can give me a talkthrough of how to do it please and which
menus etc to click on, what to type in etc..please.
Is it best done in Msoft Outlook or Outlook Express,...the backups
open in Msoft Outlook first.

Maybe you could have your guru use a dos editor.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top