Home Malware Programs Backdoors Dasda

Dasda

Posted: March 28, 2006

Dasda is a backdoor that gives the remote attacker unauthorized access to a compromised PC. The malicious person can download and install additional applications, execute certain commands and manage the computer. Dasda automatically runs on every Windows startup. Its main file is located in the computer directory C:WinntSystem32.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 dwdas.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsstata=c:WinntSystem32dwdas.exe
Loading...