Home Malware Programs Backdoors BKDR_HTTBOT.EA

BKDR_HTTBOT.EA

Posted: May 19, 2010

BKDR_HTTBOT.EA is a backdoor parasite that may be dropped onto the compromised system by other malware. BKDR_HTTBOT.EA adds corrupt keys and files as part of its installation routine. BKDR_HTTBOT.EA also creates registry entries to enable its automatic execution at every system startup. BKDR_HTTBOT.EA requires other components in order to run properly. Remove BKDR_HTTBOT.EA immediately once it has been detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\mywmimutex.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}(Default) = "{Malware Path and File Name}"HKEY_CLASSES_ROOT\CLSID\InprocServer32{C310395D-6D4A-4191-A60D-F5DD338F178D}\
Loading...