Backdoor

About “Backdoor:Win32/Jukbot.B” infection

Malware Removal

The Backdoor:Win32/Jukbot.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Jukbot.B virus can do?

  • Executable code extraction
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
fcakyou1.3322.org

How to determine Backdoor:Win32/Jukbot.B?


File Info:

crc32: ACA109C6
md5: 1a362df1394e9c7f789c8bbfe28fb696
name: 1A362DF1394E9C7F789C8BBFE28FB696.mlw
sha1: 1b7bc371ff8d9224847d91ff6ef590d749f43a78
sha256: 6779b678b25926c2d856c4617a2cf015efde12f408e0f2ea5d1f956f062d383b
sha512: 3375eed956aa6fe72406f9c76fef353f537605045ea0fb3a7fbca1ba4fe0f3630209aeb0fa5307e9355473adf5eaabe2b71267a20cca7d1eb94fd404eb09b71c
ssdeep: 1536:uFa6+TAlctbY+5c/Z5OzX+hyda2MpR3vnaVWK43Kh:uFa6+klkTmh5Ocy1Mb3vnaUKuY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Jukbot.B also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0006f5441 )
LionicTrojan.Win32.Agent.m!c
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.7370
CynetMalicious (score: 100)
CMCGeneric.Win32.1a362df139!CMCRadar
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.1271
SangforTrojan.Win32.pci.88
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaBackdoor:Win32/Jukbot.51c5d282
K7GWTrojan ( 0006f5441 )
Cybereasonmalicious.1394e9
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.OWJ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Agent.adtg
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.Agent.rany
ViRobotBackdoor.Win32.Agent.78848.B
MicroWorld-eScanGen:Heur.Mint.Zard.30
TencentWin32.Backdoor.Agent.Dxww
Ad-AwareGen:Heur.Mint.Zard.30
SophosMal/Generic-S
ComodoMalware@#kndaurspobuy
BitDefenderThetaAI:Packer.F2E919171E
VIPREVirTool.Win32.Obfuscator.XZ (v)
TrendMicroBKDR_AGENT.AVJE
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
FireEyeGeneric.mg.1a362df1394e9c7f
EmsisoftGen:Heur.Mint.Zard.30 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Agent.bnqr
WebrootW32.Trojan.Malware.Gen
AviraTR/Spy.PCI.88
Antiy-AVLTrojan/Generic.ASMalwS.2F123F
KingsoftWin32.Heur.KVMH004.a.(kcloud)
MicrosoftBackdoor:Win32/Jukbot.B
ZoneAlarmBackdoor.Win32.Agent.adtg
GDataGen:Heur.Mint.Zard.30
TACHYONBackdoor/W32.Agent.78848.G
AhnLab-V3Win-Trojan/Malpacked3.Gen
Acronissuspicious
McAfeeSpyware-Ssppyy.g
MAXmalware (ai score=100)
VBA32BScope.Trojan.Wacatac
PandaGeneric Malware
TrendMicro-HouseCallBKDR_AGENT.AVJE
RisingTrojan.Win32.Nodef.bpv (CLASSIC)
YandexTrojan.GenAsa!TSJ+AuSTCMg
IkarusTrojan.Win32.Veslorn
MaxSecureTrojan.Malware.828304.susgen
FortinetW32/Agent.ADTG!tr.bdr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Backdoor:Win32/Jukbot.B?

Backdoor:Win32/Jukbot.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment