Sophos

W32/DeadCat-A

Aliases
  • Net-Worm.Win32.Agent.e
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
  • Network shares
  • Web downloads
  • Peer-to-peer
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 April 2007 04:14:51 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/DeadCat-A is a worm for the Windows platform.

W32/DeadCat-A spreads to other network computers.

W32/DeadCat-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer.

W32/DeadCat-A is a worm for the Windows platform.

W32/DeadCat-A spreads to other network computers.

W32/DeadCat-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer.

When first run W32/DeadCat-A copies itself to <System>\DeadKitty.exe. W32/DeadCat-A may create archives of itself under one or more of the following filenames:

- Necronomikon.zip
- genetix.zip
- WarGame.zip
- DeadKitty.zip
- free0n.zip

whose contents unarchive to either ViewMe.exe or OpenMe.exe in <Root>.
Additionally W32/DeadCat-A may create archives of itself under one or more of the following filenames:

- Freedom_for_Tibet.zip
- Fuck_Nazi.zip
- Fuck_Fascist.zip
- Fuck_Communist.zip
- Romano_Prodi_is_idiot.zip

whose contents unarchive to either ViewMe.exe or OpenMe.exe in directories which have names containing the following strings:

*ownload
*omplete
*hare
*coming

W32/DeadCat-A may install one or more of the following files:
- <System>DeadKittySpammer.vbs - also detected as W32/DeadCat-A
- <Windows>Credit.html - clean html file, may simply be deleted

The following registry entry is created to run W32/DeadCat-A on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
DeadKitty
<System>\DeadKitty.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer