Remove Civcat. Description and removal instructions

 
Title: Civcat

Type: Backdoors
Severity scale:Civcat severity is 73  (73 / 100)
 
Civcat is a backdoor that gives the attacker unauthorized remote access to a compromised computer. Once executed, the parasite installs itself to the system by reconfiguring a particular Windows system service. Then it contacts predetermined remote hosts and awaits for specific commands from the attacker. The intruder is allowed to retrieve system and network information, download and upload arbitrary files, execute files and run programs, alter the backdoor's configuration and load specified DLL libraries. Civcat automatically runs on every Windows startup.


Civcat properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Civcat removal:

remover for Civcat

Civcat manual removal:

Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[service name]\Parameters\ServiceDll=[file name]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\Detect=[encrypted string]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\nDebug=300000
Misc:
[service name] is a name of system service modified by the backdoor.
[file name] is the parasite's main file.
[encrypted string] contains encrypted IP addresses of remote hosts that Civcat contacts.

Civcat creates a randomly named library (DLL) file.

The parasite uses TCP ports 53, 80, 110 and 443.

Other programs to remove Civcat:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 01/11/05
Information updated: 01/11/05

Additional resources related to Civcat:

Attention: If you know or you have a website or page about Civcat removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Civcat parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: