W32/Autoit-CV

Category: Viruses and Spyware Protection available since:15 Jun 2009 19:18:13 (GMT)
Type: Win32 worm Last Updated:15 Jun 2009 19:18:13 (GMT)
Prevalence: Small Number of Reports

Download Download a free security scan - Find threats your antivirus missed

Affected Operating Systems

Windows

Recovery Instructions:

Please follow the instructions for removing worms.

The worm might also affect the following system setting, user is recommended to manually restored them to their default setting on the system.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun = 0x000000ff
HKCU\Software\Microsoft\Internet Explorer\Main\Window Title = Internet Exploiter

A random autostart existing autostart entry might also be replaced by the path of the worm. User is recommended to search in registry for entries pointing to "KHATRA.exe" and restore those entries to their backup entries.

The Program Files / start menu folder will be emptied and a backup copy can be found in:
%WINDOWS%\K.Backup

download Try Sophos products for free
Download now