Skip to main content

Dasher.A

Classification

Aliases:

  • Dasher.A
  • W32/Dasher.A

Summary

Dasher.A is a worm that exploits a vulnerability in Microsoft Windows Distributed Transaction Coordinator (MS05-051).

Removal

Technical Details

Installation to system

The worm's dropper is a self-extracing RAR archive which drops the following files:

  • %windir%\Temp\SqlExp.exe
  • %windir%\Temp\Sqlrep.exe
  • %windir%\Temp\SqlScan.exe
  • %windir%\Temp\Sqltob.exe

The file Sqltob.exe is the actual worm main file. Sqlrep.exe is utilty called "Replace Commander". SqlScan.exe is a port scan utilty and SqlExp.exe is a component that is used in MSDTC exploiting.

When the main file is run, it adds the following registry entry to ensure that it is started when a user logs on or the system is restarted:

  • [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Update" = "%windir%\Temp\Sqltob.exe"

The worm may also create the following files:

  • %windir%\Temp\Result.txt
  • %windir%\Temp\SqlScan.bat

These files are used in exploiting.

Spreading using MSTDC vulnerability

The worm scans for systems vulnerable to MSTDC (MS05-051) through TCP/1025. It constructs random addresses using a fixed list of A-class networks. If it finds a system responding to TCP SYN scan, it sends the exploit payload. The payload connects to remote address and waits for instructions. At the time of this writing, the remote server is not accessible. According to reports, the server may instruct the infected system to download and activate the worm's dropper.

Please see the following page for detailed information on the vulnerability:

https://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.