Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Win32.Jeefo.A
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Win32.Jeefo.A  
Forum Quick Jump
 
New Topic Post reply to : Win32.Jeefo.A Printable version of : Win32.Jeefo.A
[ << Previous Thread | Next Thread >> ]

icewonder
New Member


Date Joined Sep 2004
Total Posts : 1
 
   Posted 9-21-2004 8:10 (GMT +1)    Quote: Win32.Jeefo.AAlert an admin about: Win32.Jeefo.A
Plz can someone help me: how can I  get rid of this virus: Win32.Jeefo.A. Thanks

Post Edited (icewonder) : 9/24/2004 8:16:20 PM GMT

Back to Top
 

AdrianC
New Member


Date Joined Sep 2004
Total Posts : 1
 
   Posted 9-30-2004 11:54 (GMT +1)    Quote: Win32.Jeefo.AAlert an admin about: Win32.Jeefo.A
I have some information about this pain-in-the ass.

Win32.Jeefo.A is a virus that infects PE files.

Once activated, it copies itself as SVCHOST.EXE to the Windows directory, launches it as a separate process, then passes control back to the host program. The virus then installs itself as a service to stay in memory. The following registry key is created on Win9x systems:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\PowerManager, = "%Windows%\SVCHOST.EXE"

On Win2k, the service name is "Power Manager":

HKLM\System\CurrentControlSet\Services\PowerManager\ImagePath, "%Windows%\svchost.exe"

Note that SVCHOST.EXE is a valid system filename that exists in the System directory. The virus-created SVCHOST.EXE contains only the virus itself and is 36,352 bytes in size.

The virus searches drive letters C to Z for fixed disks. Once found, all directories are searched for suitable PE file to infect. Infected files increase 36,352 bytes in size, but the last modified date and time remains the same.

The virus body contains the following hidden message (although this is never displayed to the user):

"Hidden Dragon virus. Born in a tropical swamp"

Note: The virus may corrupt some files. Such files may not work correctly after cleaning and removal of the virus code. The corrupted programs will need to be restored from backups or the original installation packages.


I use bitdefender 7.2 with updates and it works. Here is the link: http://www.bitdefender.com/index.php

Good luck!
Back to Top
 
New Topic Post reply to : Win32.Jeefo.A Printable version of : Win32.Jeefo.A
 
Forum Information
Currently it is Saturday, November 22, 2008 12:58 PM (GMT +1)
There are a total of 64.046 posts in 15.836 threads.
In the last 3 days there were 26 new threads and 155 reply posts. View Active Threads
Who's Online
This forum has 27196 registered members. Please welcome our newest member, Catlady UK.
47 Guest(s), 1 Registered Member(s) are currently online.  Details
Behram
5 Latest Threads
Generic.PWS.WoW.B7078E0 (16)22-11-2008 11:55:15 (Behram)
Redirecting virus? (5)22-11-2008 10:29:08 (r1ch1e)
Help please!!! (15)22-11-2008 10:05:45 (Touch)
HELP I AM GOING MAD (5)22-11-2008 06:51:49 (Touch)
Win 32-trojan-gen (17)22-11-2008 05:29:27 (Touch)