W32/DeadCat-A

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/DeadCat-A is a worm for the Windows platform.

W32/DeadCat-A spreads to other network computers.

W32/DeadCat-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer.

W32/DeadCat-A is a worm for the Windows platform.

W32/DeadCat-A spreads to other network computers.

W32/DeadCat-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer.

When first run W32/DeadCat-A copies itself to <System>\DeadKitty.exe. W32/DeadCat-A may create archives of itself under one or more of the following filenames:

- Necronomikon.zip
- genetix.zip
- WarGame.zip
- DeadKitty.zip
- free0n.zip

whose contents unarchive to either ViewMe.exe or OpenMe.exe in <Root>.
Additionally W32/DeadCat-A may create archives of itself under one or more of the following filenames:

- Freedom_for_Tibet.zip
- Fuck_Nazi.zip
- Fuck_Fascist.zip
- Fuck_Communist.zip
- Romano_Prodi_is_idiot.zip

whose contents unarchive to either ViewMe.exe or OpenMe.exe in directories which have names containing the following strings:

*ownload
*omplete
*hare
*coming

W32/DeadCat-A may install one or more of the following files:
- <System>DeadKittySpammer.vbs - also detected as W32/DeadCat-A
- <Windows>Credit.html - clean html file, may simply be deleted

The following registry entry is created to run W32/DeadCat-A on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
DeadKitty
<System>\DeadKitty.exe

download Try Sophos products for free
Download now