Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 28 April 2007 04:14:51 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/DeadCat-A is a worm for the Windows platform.
W32/DeadCat-A spreads to other network computers.
W32/DeadCat-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer.
W32/DeadCat-A spreads to other network computers.
W32/DeadCat-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer.
When first run W32/DeadCat-A copies itself to <System>\DeadKitty.exe. W32/DeadCat-A may create archives of itself under one or more of the following filenames:
- Necronomikon.zip
- genetix.zip
- WarGame.zip
- DeadKitty.zip
- free0n.zip
whose contents unarchive to either ViewMe.exe or OpenMe.exe in <Root>.
Additionally W32/DeadCat-A may create archives of itself under one or more of the following filenames:
- Freedom_for_Tibet.zip
- Fuck_Nazi.zip
- Fuck_Fascist.zip
- Fuck_Communist.zip
- Romano_Prodi_is_idiot.zip
whose contents unarchive to either ViewMe.exe or OpenMe.exe in directories which have names containing the following strings:
*ownload
*omplete
*hare
*coming
W32/DeadCat-A may install one or more of the following files:
- <System>DeadKittySpammer.vbs - also detected as W32/DeadCat-A
- <Windows>Credit.html - clean html file, may simply be deleted
The following registry entry is created to run W32/DeadCat-A on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
DeadKitty
<System>\DeadKitty.exe

