Welcome to the Virus Encyclopedia of Panda Security.
|Alias:||Vesser, W32/Deadhat.worm.a, W32.HLLW.Deadhat|
|Effects: ||It causes the computer to not start up correctly, ends processes belonging to security programs and opens a TCP port.|
|Detection updated on:||Feb. 9, 2004|
|Yes, using TruPrevent Technologies
Deadhat.A is a worm with destructive effects that spreads through the peer-to-peer (P2P) file sharing program SoulSeek and via Internet.
Deadhat.A causes the affected computer to not start up correctly, as it deletes files that are vital to its functioning.
Deadhat.A ends processes belonging to some antivirus programs and firewalls, among others. This leaves the computer vulnerable to the attack of other malware. It also ends the processes belonging to Mydoom.A and Mydoom.B.
In addition, Deadhat.A opens the TCP port 2766, allowing to download files to the affected computer by using a remote connection.
Deadhat.A is easy to recognize, as it displays the following error message on screen when it is run: