Feb 19, 2009

Malware - Khatra.exe

Khatra.exe (Khatra) Trojan Virus File Information

Danger Khatra.exe is a dangerous file which creates activities on a user’s computer which may be highly undesirable. This file is unsafe.
Type: Trojan Virus
Location: C:\WINDOWS\system32\khatra.exe
Threat name Win32.Autoit.BP 
Filename [System32Root]\khatra.exe 
Filesize : Unknown
The filename KHATRA.EXE was last seen on 02.13.2009, and it is considered unsafe. This threat is associated with the malware group Win32.Autoit.BP.

Characteristics 

1.     It can make unexpected changes to your system.
2.     It can disable control panel and creates a file in each folder of your drive.
3.     This file may be of size 600 kb thus filling half of your hard disk.
4.     It also runs as process and will use your CPU/Memory.
5.     It spreads mainly through Pen/USB/Flash drives.

It is recommended that you remove any malicious software such as Khatra.exe from your computer immediately.

The file "khatra.exe" is known to be created under the following filenames:
AllUsersProfile:- C:\Users\HP\desktop.exe
AllUsersProfile:- C:\Users\HP\favorites.exe
C:\Users\HP\AppData\microsoft\cd burning\khatra.exe
C:\Users\HP\Desktop\desktop.exe
C:\Users\HP\Favorites\favorites.exe
C:\Windows\khatarnakh.exe or khatra.exe
C:\Windows\system\ghost.exe
C:\Windows\xplorer.exe
C:\inetpub.exe
C:\inetpub\inetpub.exe
C:\inetpub\wwwroot\wwwroot.exe
C:\khatra.exe
Here C:\ is the drive in which OS is installed. HP is the user name.
OriginNumber of Incidents
United Kingdom63

The following threats are known to be associated with the file "khatra.exe":
Threat AliasNumber of Incidents
Generic.dx [McAfee]60
Trojan-Dropper.Win32.Autoit.k [Kaspersky Lab]60
Trojan-Dropper.Win32.Autoit [Ikarus]42
W32.SillyFDC [Symantec]21
Virus.Win32.Sality [Ikarus]15
Trojan Horse [Symantec]12
W32/Autoit-BP [Sophos]12

How to remove Khatra.exe ?

Mostly when your computer is infected with khatra.exe, you will not be able to perform any normal operations. In this situation the only option is to format your OS drive. After OS installation, install a good antivirus and perform a full scan. I would recommend Nod32. Be careful not to double-click any files with the folder name. It's mostly a virus file created by khatra.exe.
Please follow these instructions:

1. Reboot computer in SafeMode.

2.  Delete any values added to the registry related with KHATRA.EXE.

3. Clean/delete all KHATRA.EXE related file(s).

4. Please delete all your IE temp files with KHATRA.EXE manually and run a whole scan with antivirus program.

5. Enable 'show all hidden files..' option in Windows explorer view menu. Search all your hard drive files and folders for '*.exe' with size less than 1mb and delete only '.exe' files having folder symbol(name of the folder). The file type will be shown as an application. 

No comments:

Post a Comment