Home Malware Programs Worms Katar.A

Katar.A

Posted: December 7, 2010

Threat Metric

Threat Level: 5/10
Infected PCs: 204
First Seen: December 7, 2010
Last Seen: June 8, 2022
OS(es) Affected: Windows

Aliases

Trojan.MulDrop2.6409 [DrWeb]Win32.GenHeur.Zq@rdj [eSafe]Heuristic.BehavesLike.Win32.Suspicious-BAY.G [McAfee-GW-Edition]TROJ_SPNR.03L612 [TrendMicro]Win32.HLLW.Autoruner1.27539 [DrWeb]Win32.TRCrypt.XPACK [eSafe]W32/Sohanat.KS [Panda]Proxy.ANZI [AVG]PossibleThreat [Fortinet]Heuristic.LooksLike.Win32.Suspicious.F!81 [McAfee-GW-Edition]DR/Autoit.abl [AntiVir]Win32.HLLM.Siggen.3196 [DrWeb]Worm.Generic.355075 [BitDefender]Win32.Dropper [eSafe]Suspicion: unknown virus [AVG]
More aliases (157)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\kak.bat File name: kak.bat
Size: 2.28 KB (2283 bytes)
MD5: d0c4fd538448e8622dbea7574ba537b9
Detection count: 52
File type: Batch file
Mime Type: unknown/bat
Path: %WINDIR%
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\Xplorer.exe File name: Xplorer.exe
Size: 417.28 KB (417280 bytes)
MD5: bc1041915c21811609bd37ea17f90fa6
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: April 22, 2020
%WINDIR%\system32\KHATRA.exe File name: KHATRA.exe
Size: 417.05 KB (417052 bytes)
MD5: 8e6921ab175118ec563825378e159dfd
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 17, 2012
%WINDIR%\Xplorer.exe File name: Xplorer.exe
Size: 417.05 KB (417052 bytes)
MD5: aabc6c1c98e1da7acfa4db52263566e8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: March 1, 2013

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\system32\KHATRA.exe%WINDIR%\Xplorer.exe
Loading...