Home Malware Programs Backdoors Backdoor.Boda

Backdoor.Boda

Posted: February 11, 2013

Threat Metric

Threat Level: 6/10
Infected PCs: 94
First Seen: February 11, 2013
OS(es) Affected: Windows

Backdoor.Boda is a backdoor Trojan that opens a back door on the infected computer system. Once executed, Backdoor.Boda creates the potentially malicious files on the corrupted machine. Backdoor.Boda also creates the configuration file that stores command-and-control (C&C) server information. Backdoor.Boda creates registry entries one of them allowingto execute automatically whenever you start Windows. Backdoor.Boda stops antivirus-related processes on the targeted PC. Backdoor.Boda may then insert a code into certain processes on the victimzed computer system. Backdoor.Boda opens a back door and allows a remote attacker to get access to the infected computer. Backdoor.Boda gathers system-related information and may transmit it to a remote location.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 209.85 KB (209852 bytes)
MD5: 432dce23d00694b103dd838144253d1b
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2013
file.exe File name: file.exe
Size: 33.28 KB (33280 bytes)
MD5: 815db4b8b5935ee0150bb5dd99847fb1
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2013
file.exe File name: file.exe
Size: 209.31 KB (209314 bytes)
MD5: a7c79c7e13a6f3e5bfe4852efd937096
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2013
file.exe File name: file.exe
Size: 88.01 KB (88016 bytes)
MD5: d399e5b8d0d6a01e14e713488d1ee6d9
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2013
file.exe File name: file.exe
Size: 241.57 KB (241570 bytes)
MD5: e7c326f7cc20783ffc564d6e91f0457b
Detection count: 39
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2013
%Temp%\seccenter.xxx File name: %Temp%\seccenter.xxx
Mime Type: unknown/xxx
Group: Malware file
%UserProfile%\Application Data\config.sys File name: %UserProfile%\Application Data\config.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Micorsoft\Windows\CurrentVersion\Run\"Update" = "%UserProfile%\Application Data\googleupdate.exe"HKEY_CURRENT_USER\Software\Classes\"softbin" = "[BINARY DATA]"
Loading...