Civcat manual removal:
Delete registry values:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[service name]\Parameters\ServiceDll=[file name]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\Detect=[encrypted string]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\nDebug=300000
Misc:[service name] is a name of system service modified by the backdoor.
[file name] is the parasite's main file.
[encrypted string] contains encrypted IP addresses of remote hosts that Civcat contacts.
Civcat creates a randomly named library (DLL) file.
The parasite uses TCP ports 53, 80, 110 and 443.
Post Comment:
Attention: Use this form only if you have additional information about Civcat parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.