Home Malware Programs Worms Dasher.d

Dasher.d

Posted: March 28, 2006

Dasher.d is an Internet worm that infects vulnerable remote PCs running the Microsoft Windows operating computer with unpatched security flaws. The infection process does not require any user interaction. Once installed, Dasher.d runs a spreading routine. Then it opens a back door that provides the attacker with unauthorized remote access to a compromised PC. The intruder can download from a predefined FTP server and execute arbitrary files. Dasher.d also terminates some running antivirus applications, firewalls and other security-related software. It is able to lower security settings on the infected computer by altering the Windows registry.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sqlexp.exe
    2 sqlexp1.exe
    3 sqlexp2.exe
    4 sqlexp3.exe
    5 sqlscan.exe
    6 sqltob.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSDTCStart=4HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNetBTParametersSMBDeviceEnabled=0
Loading...