Home Malware Programs Worms Dasher

Dasher

Posted: March 28, 2006

Dasher is an Internet worm that spreads to vulnerable remote PCs running the Microsoft Windows operating computer with unpatched security flaws. The infection process doesn't require any user interaction. Once installed, Dasher runs a spreading routine. It searches for vulnerable remote PCs and infects them. Once the computer is infected, the worm instructs it to contact a predetermined host and wait for some specific commands. Dasher automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sqlexp.exe
    2 sqlrep.exe
    3 sqlscan.exe
    4 sqltob.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunWindowsUpdate

Related Posts

Loading...