SpywareGuide powered by Actiance Security Labs
Search SpywareGuide Database & Site
Home Access the Guide
List of Products List of Companies List of Categories
Tools
X-RayPC
Terms and Definitions
 
Full Name:
BackDoor.JK Websearch   Read More
Type: Trojan
Also Known as: Peerbot.B (PandaSoftware), W32/Peerbot.B.worm
SG Index: 7 [Explain]
Category Description: Trojans are malicious applications that pose themselves as legitimate software in order to trick users to install them. Once on the victim's machine, it may run any number of malicious process to steal vital information or inflict damage to other software.
Comment: BackDoor.JK is an IRC Backdoor Trojan Horse that gives its author control of an infected computer through Internet Relay Chat (IRC).

It adds False IP's to more than 50 popular antivirus companies urls in the Host file, disables antivirus notifications, firewall notifications, update notifications, and overrides firewalls. It also steals data from SQL Server and Mysql databases.

BackDoor.JK creates the folder, %Windir%\system32\programs\.
These files are used for Transmission through P2P programs.

Copies itself to the %Windir%\system32\programs\ folder as the following filenames:
2 Find MP3 8.2.0.exe
Adobe InDesign CS 2.exe
Adobe keygen for photoshop indesign incopy SERIAL crack.exe
Adobe Photoshop CS 2.exe
Autocad 2002 Crack.exe
Autocad 2004 Crack.exe
Autocad 2005 Crack.exe
Autocad 2006 Crack.exe
BEST HACK TOOL FOR REAL HACKERS KEYLOGGER WEBCAM SPY! - PRIVATE.exe
Counter strike - cs full version.exe
Counter strike keygen WORKING FOR ONLINE STEAM.exe
Credit card generator.exe
Eric vd Vogt Gay Movie - Dutch homosexual fetish raped.exe
Fifa 2006 FULL with crack.exe
Fifa 2007 FULL with crack.exe
flash 8.exe
Free SMS Bomber.exe
Google hack tutorial for beginners.exe
HalfLife 2 WORKING Steam crack.exe
Hotmail account hacker in 30 minutes.exe
Hotmail hacker.exe
hotmail_account_sniffer.exe
Hotmailhacker v1.0.exe
IP Changer.exe
Microsoft Office Activation Crack.exe
Microsoft Office Professional Crack.exe
Microsoft Office Professional Serial.exe
Microsoft Office Professional Universal Crack without serial.exe
Microsoft Office Universal Activator v1.0.exe
MSN hacker - password stealer.exe
norton anti virus FULL NEWEST VERSION.exe
Norton AntiVirus 2005 crack.exe
Norton AntiVirus 2006 crack.exe
Norton antivirus crack.exe
Norton firewall 2006 crack.exe
porn.exe
porn_account_cracker.exe
porn_account_hacker.exe
psx2 - playstation 2 emulator.exe
toon boom.exe
UniVersal GSM unlocker for removing simlock (NOKIA,ERICSSON,SONY,SAMSUNG,OTHERS).exe
WinRAR 4 beta.exe
yahoo_cracker.exe
yahoo_hacker.exe
Yahoo_mail_cracker.exe
ZoneAlarm crack (keygen).exe
   
Manual removal: Large amount of Hijacked domains are placed in the Hosts file. Its probably better to delete the file itself than to fix each item.(and create a Backup)
File location is C:\Windows\System32\drivers\etc\hosts

To Correct Modified Registry Values:

1.Click on Start , click run.
2.Type "regedit" and press enter.
3.Navigate to "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center"
4.Right Click on "AntiVirusDisableNotify" ,click on Modify , Type " 0 " in Value Data field in place of "1" and press Enter.
5.Right Click on "FirewallDisableNotify" , click on Modify , Type "0" in Value Data field in place of "1" and press Enter.
6.Right Click on "FirewallOverride" , click on Modify , Type "0" in Value Data field in place of "1" and press Enter.
7.Right Click on "UpdatesDisableNotify" , click on Modify , Type "0" in Value Data field in place of "1" and press Enter.
8. Navigate to "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" .
9. Right Click on "Shell" , click on Modify , Type "Explorer.exe" in Value Data field in place of "Explorer.exe taskdrv.exe" and press Enter.
10. Restart computer.
Properties:
  •  Allows remote connect
  •  Allows remote control
  •  Alters Key Windows Components
  •  Attacks security software
  •  Autostarts/Stays Resident
  •  Blocks Security Sites
  •  Changes HOSTS file
  •  Opens ports
  • Click here to leave feedback for this product

    Recent Modifications
    2023-3-28  Adult Networks/Services
    2023-3-7  New York Islanders Fans
    2017-2-10  Adult Hosts
    2016-3-30  CoolWebSearch
    2015-9-29  Malicious URLS
    2015-5-19  Dialers
    2015-1-5  Email Threats
    2013-7-20  Date Manager
    2013-4-10  BeeBus
    2012-12-18  JT.Moonwalk
     
    Company  | Site and Spyware FAQ
    © Copyright 2003-2023, Actiance, Inc. All rights reserved.   Privacy Policy