Severity scale  
  (70/100)

Harakit. How to Remove? (Uninstall Guide)

removal by - -   Also known as W32.Harakit | Type: Worms
12
Harakit worm is typical representative of its kind. Harakit (also known as W32.Harakit) spreads through network shares and online chat applications. It also creates copies of itself on every removable drive it can locate; this is how it reaches new victims.

Harakit makes changes in Windows registry in order to hide itself from computer’s owner. The modifications it makes also enables Harakit worm to run on every startup. Harakit usually deletes some registry entries that are responsible for security settings; this way it stays unobserved by anti-spyware and anti-virus scans. Changing security settings also helps Harakit to achieve its goals. Replicating itself is not the main purpose of W32.Harakit; it targets personal information. Harakit collects sensitive data and delivers it to remote attackers. Harakit is as threat to person’s privacy and security. Harakit properties:
• Sends out logs by FTP or email
• Connects itself to the internet
• Hides from the user
• Stays resident in background

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Harakit. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Harakit. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
Plumbytes
We are testing Plumbytes's efficiency (2008-12-10 08:12)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2008-12-10 08:12)
Webroot SecureAnywhere AntiVirus

Harakit manual removal

Kill processes:
csrcs.exe
cftm.exe
cftmen.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"cftm" = "C:\WINDOWS\system32\cftm.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"csrcs" = "C:\WINDOWS\system32\csrcs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"cftm" = "C:\WINDOWS\system32\cftm.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\"cftm" = "C:\WINDOWS\system32\cftm.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"ShowSuperHidden" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe csrcs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM
HKEY_LOCAL_MACHINE\SOFTWARE\ESET\Nod
Delete files:
System\\csrcs.exe
System\\autorun.inf
SystemDrive\\khq
SystemDrive\\khr
System\\cftm.exe
System\\cftmen.exe

Information updated:

Comments on Harakit

0
0
<Guest>
I deleted most of the files above, but found the khr system file on my drives. My hard drive has been failing so I hope that is the problem.

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)