Home Malware Programs Worms W32.Blaster.C.Worm

W32.Blaster.C.Worm

Posted: March 28, 2006

W32.Blaster.C.Worm is a worm that exploits the DCOM RPC vulnerability using TCP port 135. It targets only PCs with Windows 2000 and Windows XP. It tries to download the Teekids.exe file to the System folder, and then execute it.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 eekids.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunDeletethevaluecalledMicrosoftInetXp..
Loading...