Civcat manual removal:
Delete registry values:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[service name]\Parameters\ServiceDll=[file name]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\Detect=[encrypted string]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\nDebug=300000
Misc:[service name] is a name of system service modified by the backdoor.
[file name] is the parasite's main file.
[encrypted string] contains encrypted IP addresses of remote hosts that Civcat contacts.
Civcat creates a randomly named library (DLL) file.
The parasite uses TCP ports 53, 80, 110 and 443.
Post Comment: