Welcome to the Virus Encyclopedia of Panda Security.
It carries out plenty of modifications in the Windows Registry, which prevent the computer from working properly. It disables several functions of the Start menu, such as Search or Run, and applications such as the Task Manager. It also ends processes belonging to security programs. It spreads via IRC channels.
|First detected on:||Dec. 19, 2007|
|Detection updated on:||Dec. 20, 2007|
|Yes, using TruPrevent Technologies
Evata.A is a worm that carries out plenty of modifications in the Windows Registry, which prevent the user from working with the computer as usual.
These modifications prevent the user from carrying out the following actions, among others:
- Doing searches and running files in a fast and straight way, as it disables the options Search and Run from the Start menu.
- Viewing the processes that are being run through the Task Manager.
- Modifying the configuration of the features of the folders.
- Displaying the context menu, that is, the one that appears when right clicking the mouse.
Additionally, it ends processes belonging to several antivirus programs, leaving the computer vulnerable against possible threats and obtains information about the characteristics of the system, such as IP address and computer name.
Evata.A spreads via IRC channels, by sending copies of itself to the users that are connected to the same channel as the infected user.
Evata.A is easy to recognize, as when it is run, a game is opened. In order to play, the user must register. The following image belongs to the game: