Home Malware Programs Backdoors Backdoor.Jukbot.B

Backdoor.Jukbot.B

Posted: January 5, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 703
First Seen: November 30, 2011
Last Seen: February 2, 2022
OS(es) Affected: Windows

Backdoor.Jukbot.B is a hazardous backdoor Trojan which opens a back door in your computer system and allows attackers to gain remote access and control over the affected machine. Backdoor.Jukbot.B communicates with a remote server to receive instructions on further malicious actions. When Backdoor.Jukbot.B is installed, it makes some system changes such as registry modification. Backdoor.Jukbot.B can easily download and execute malicious files. Backdoor.Jukbot.B uses different file and service names throughout the installation. The registry is modified in order to run Backdoor.Jukbot.B as a Windows service. Backdoor.Jukbot.B copies the names of the legitimate services and hijacks them, tricking the PC system into running it every time Windows starts. Once Backdoor.Jukbot.B is installed and executed, it attempts to connect to a remote website in order to receive configuration data from the remote server. Backdoor.Jukbot.B can also expose the corrupted PC to rouge attacks. Backdoor.Jukbot.B can unexpectedly restart or shut down your computer, or initiate a denial of service attack. Get rid of Backdoor.Jukbot.B as soon as possible.

Aliases

Backdoor.Win32.Zegost [Ikarus]Backdoor/Win32.Hupigon [AhnLab-V3]DDoS.Attack.301 [DrWeb]Packed:W32/PeCan.A [F-Secure]Gen:Trojan.Heur.PT.guW@aehIxgp [BitDefender]HEUR:Trojan.Win32.Generic [Kaspersky]Win32:Rootkit-gen [Rtk] [Avast]Generic BackDoor!1tp [McAfee]Backdoor.Jukbot [CAT-QuickHeal]Generic Malware [Panda]Fat-Obfuscated [AVG]W32/Redosdru.ID!tr [Fortinet]Trojan.Win32.Jorik [Ikarus]Win-Trojan/Agent.102416.B [AhnLab-V3]Trojan/Win32.Jorik.gen [Antiy-AVL]
More aliases (245)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\SysWOW64\svch0st.exe File name: svch0st.exe
Size: 102.18 KB (102182 bytes)
MD5: cf9548e21a7ffae63ec35148507ea9ec
Detection count: 255
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: March 6, 2013
%WINDIR%\syswow64\sdfeba.exe\file.exe File name: file.exe
Size: 51.71 KB (51712 bytes)
MD5: c7dceff6cde29293abfbfdb423299f6c
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\syswow64\sdfeba.exe
Group: Malware file
Last Updated: June 26, 2020
%APPDATA%\Microsoft\015D\38A.exe File name: 38A.exe
Size: 284.67 KB (284672 bytes)
MD5: 3275203f1041b62ed23c9d1b55f99737
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\015D
Group: Malware file
Last Updated: December 5, 2011
file.exe File name: file.exe
Size: 729.08 KB (729088 bytes)
MD5: 7af6b847478a8f470298e51ec12577d0
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 1, 2017
file.exe File name: file.exe
Size: 22.53 KB (22530 bytes)
MD5: a95fbec1b3aba9e0b8354749699fa04d
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%WINDIR%\system32\sqlcsw32.dll File name: sqlcsw32.dll
Size: 162.81 KB (162816 bytes)
MD5: 85a8fc6b1dedab9c8085e037680b7cf1
Detection count: 68
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 1, 2011
%USERPROFILE%\Local Settings\Application Data\ang.exe File name: ang.exe
Size: 299.52 KB (299520 bytes)
MD5: a0b052c56c4d94c36e2a5b04c0bf75bc
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 5, 2011
c:\windows\syswow64\jukbot.exe File name: jukbot.exe
Size: 24.06 KB (24064 bytes)
MD5: f249f4cdbd11adb5202de3a588aa2e0b
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: c:\windows\syswow64
Group: Malware file
Last Updated: November 19, 2018
%PROGRAMFILES(x86)%\C7E22\lvvm.exe File name: lvvm.exe
Size: 188.41 KB (188416 bytes)
MD5: a85e79a1ce7c293611a311f89b063cf8
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\C7E22
Group: Malware file
Last Updated: December 5, 2011
%USERPROFILE%\Local Settings\Application Data\way.exe File name: way.exe
Size: 286.2 KB (286208 bytes)
MD5: 04fcd92131958aa0a743f63ebb22ef55
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 5, 2011
c:\windows\syswow64\dbelh.exe File name: dbelh.exe
Size: 13.82 KB (13824 bytes)
MD5: fbdc9f9793d0f7d7633739c1140925b6
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: c:\windows\syswow64
Group: Malware file
Last Updated: March 6, 2018
%WINDIR%\SysWOW64\svch0sts.exe File name: svch0sts.exe
Size: 102.41 KB (102416 bytes)
MD5: 47dc6120ea76568d3fa6db38a754438f
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: March 1, 2013
%USERPROFILE%\Application Data\thq88rx6p.exe File name: thq88rx6p.exe
Size: 5.12 KB (5120 bytes)
MD5: 6afaea332a84de981715de7881d9f228
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: December 5, 2011
file.exe File name: file.exe
Size: 98.81 KB (98816 bytes)
MD5: 8cfc667714d6dee857137f92203986f0
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 23, 2017
%WINDIR%\system32\sqlesw32.dll File name: sqlesw32.dll
Size: 37.88 KB (37888 bytes)
MD5: 6129bf6c0e0281587053c2bb39f9fb78
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 5, 2011
%ALLUSERSPROFILE%\Dati applicazioni\NfWOkoyrvDaoRQH.exe File name: NfWOkoyrvDaoRQH.exe
Size: 466.94 KB (466944 bytes)
MD5: 0ea318a1f802030209a70f9f6bf5d6c7
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Dati applicazioni
Group: Malware file
Last Updated: December 5, 2011
%ALLUSERSPROFILE%\Dati applicazioni\ZjevH3HwzpNRaA.exe File name: ZjevH3HwzpNRaA.exe
Size: 370.68 KB (370688 bytes)
MD5: 0b07f47b65d44764c8f83fb4bbc8c69d
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Dati applicazioni
Group: Malware file
Last Updated: December 5, 2011
%WINDIR%\TEMP\hki283.exe File name: hki283.exe
Size: 116.22 KB (116224 bytes)
MD5: 72b6a7e7c15faa446887fe5ec3e124fd
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP
Group: Malware file
Last Updated: December 5, 2011
%USERPROFILE%\Local Settings\Application Data\rjy.exe File name: rjy.exe
Size: 291.84 KB (291840 bytes)
MD5: f84056ed084e58f6fcdc487ec931843b
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 5, 2011
%PROGRAMFILES%\NewtonDictate\NewtonDictate.exe File name: NewtonDictate.exe
Size: 2.27 MB (2279424 bytes)
MD5: 9a1485f3c67ecc2e4f3fb907866afed7
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\NewtonDictate
Group: Malware file
Last Updated: January 22, 2019
%APPDATA%\68.exe File name: 68.exe
Size: 327.68 KB (327680 bytes)
MD5: acb887fe28c2d1206b8835935506e6b8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 15, 2020
%USERPROFILE%\AppData\LocalFiles\svchosts.exe File name: svchosts.exe
Size: 792.32 KB (792320 bytes)
MD5: 604bb71fb6f91b4927c1a0fe526dc148
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\AppData\LocalFiles
Group: Malware file
Last Updated: December 5, 2011
c:\windows\syswow64\smvccs.dll File name: smvccs.dll
Size: 89.08 KB (89088 bytes)
MD5: 9c390d3b8e508f0a1b601ba814d7e078
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\windows\syswow64
Group: Malware file
Last Updated: October 15, 2018
bsn.exe File name: bsn.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
AbdioPdfEditor.exe File name: AbdioPdfEditor.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
uhu.exe File name: uhu.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
t00el32.dll File name: t00el32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
svchosts.exe File name: svchosts.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
eygen.exe File name: eygen.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
skfp.exe File name: skfp.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
NewtonDictate.exe File name: NewtonDictate.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
rjy.exe File name: rjy.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
qxd.exe File name: qxd.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files
Loading...