Home Malware Programs Backdoors Backdoor.Boda

Backdoor.Boda

Posted: February 11, 2013

Threat Metric

Threat Level: 6/10
Infected PCs: 94
First Seen: February 11, 2013
OS(es) Affected: Windows

Backdoor.Boda is a backdoor Trojan that opens a back door on the infected computer system. Once executed, Backdoor.Boda creates the potentially malicious files on the corrupted machine. Backdoor.Boda also creates the configuration file that stores command-and-control (C&C) server information. Backdoor.Boda creates registry entries one of them allowingto execute automatically whenever you start Windows. Backdoor.Boda stops antivirus-related processes on the targeted PC. Backdoor.Boda may then insert a code into certain processes on the victimzed computer system. Backdoor.Boda opens a back door and allows a remote attacker to get access to the infected computer. Backdoor.Boda gathers system-related information and may transmit it to a remote location.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 88.01 KB (88016 bytes)
MD5: d399e5b8d0d6a01e14e713488d1ee6d9
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2013
%Temp%\seccenter.xxx File name: %Temp%\seccenter.xxx
Mime Type: unknown/xxx
Group: Malware file
%UserProfile%\Application Data\config.sys File name: %UserProfile%\Application Data\config.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Micorsoft\Windows\CurrentVersion\Run\"Update" = "%UserProfile%\Application Data\googleupdate.exe"HKEY_CURRENT_USER\Software\Classes\"softbin" = "[BINARY DATA]"
Loading...