Home Malware Programs Worms Dafet

Dafet

Posted: March 28, 2006

Dafet is an Internet worm that infects PCs running Microsoft Windows operating computer with unpatched security vulnerabilities. The spyware downloads from a predetermined remote server and executes certain files, which install a backdoor. Dafet automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msvcrtdd.dll
    2 update.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunMouseDrvHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMouseDrv
Loading...