Remove Harakit. Description and removal instructions

 
Title: Harakit
Also known as: W32.Harakit
Type: Worms
Severity scale:Harakit severity is 70  (70 / 100)
 
Harakit worm is typical representative of its kind. Harakit (also known as W32.Harakit) spreads through network shares and online chat applications. It also creates copies of itself on every removable drive it can locate; this is how it reaches new victims.

Harakit makes changes in Windows registry in order to hide itself from computer’s owner. The modifications it makes also enables Harakit worm to run on every startup. Harakit usually deletes some registry entries that are responsible for security settings; this way it stays unobserved by anti-spyware and anti-virus scans. Changing security settings also helps Harakit to achieve its goals. Replicating itself is not the main purpose of W32.Harakit; it targets personal information. Harakit collects sensitive data and delivers it to remote attackers. Harakit is as threat to person’s privacy and security.


Related files: System\csrcs.exe, System\autorun.inf, SystemDrive\khq, SystemDrive\khr, System\cftm.exe, System\cftmen.exe

Harakit properties:
• Sends out logs by FTP or email
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Harakit removal:

remover for Harakit

Harakit manual removal:

Kill processes:
csrcs.exe cftm.exe cftmen.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"cftm" = "C:\WINDOWS\system32\cftm.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"csrcs" = "C:\WINDOWS\system32\csrcs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"cftm" = "C:\WINDOWS\system32\cftm.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\"cftm" = "C:\WINDOWS\system32\cftm.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"ShowSuperHidden" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe csrcs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM
HKEY_LOCAL_MACHINE\SOFTWARE\ESET\Nod
Delete files:
System\\csrcs.exe System\\autorun.inf SystemDrive\\khq SystemDrive\\khr System\\cftm.exe System\\cftmen.exe

Other programs to remove Harakit:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 12/11/08
Information updated: 10/12/08

Additional resources related to Harakit:

Attention: If you know or you have a website or page about Harakit removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Harakit parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by . 2008-12-10 08:12:32
I deleted most of the files above, but found the khr system file on my drives. My hard drive has been failing so I hope that is the problem.


Latest spyware news:
Similar parasites: