Home Malware Programs Worms Slammer worm

Slammer worm

Posted: March 28, 2006

It is a very dangerous worm that targets the computers running Microsoft SQL Server 2000, as well as Microsoft Desktop Engine 2000. The worm sends 376 bytes to UDP port 1434, the SQL Server Resolution Service Port.

The worm has the unintended payload of performing a Denial of Service attack due to the large number of packets it sends.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 02_N803.DAT
    2 BCTOOL.EXE
    3 GFXACC.EXE
    4 Q216309.EXE
    5 VTNMSCCD.DLL
    6 WINNETW.EXE

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunDeletethekey:HKEY_LOCAL_MACHINESoftwareAVTechRemovethereferencesto3dfxAccandLoadDBackup
Loading...