Home Malware Programs Worms Daboom

Daboom

Posted: March 28, 2006

Daboom is a dangerous Internet worm distributed by e-mail in messages with infected attachments. The spyware exploits certain Microsoft Outlook and Microsoft Outlook Express vulnerabilities that allow it to instantly infect the computer when the user previews or opens a malicious letter. In most cases there is no need to manually run the attachment. Daboom sends infected messages to all the addresses it find in the Windows Address Book and cached web pages . The worm includes an integrated backdoor that notifies the attacker by e-mail and gives him unauthorized remote access to a compromised PC. The intruder can manage files, alter computer configuration, download and run arbitrary applications, collect computer and network information and control the CD-ROM drive. Daboom can also act as a keylogger recording all user keystrokes and passwords. The spyware runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 systray32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesActiveDesktop=%System%systray32.exe
Loading...