Home Malware Programs Viruses Virus.Hidrag.a

Virus.Hidrag.a

Posted: June 21, 2007

Threat Metric

Ranking: 4,485
Threat Level: 8/10
Infected PCs: 16,552
First Seen: July 24, 2009
Last Seen: October 12, 2023
OS(es) Affected: Windows

Virus.Hidrag.a is a malicious virus that delivers itself via browser security holes, IRC, and over network shares. After execution, Virus.Hidrag.a will stay in your computer memory and will seek to infect any .exe or .scr files that are executed on your system. Virus.Hidrag.a is designed to load on every Windows startup. Additionally, Virus.Hidrag.a may create a backdoor hole that provides the intruder to receive unfettered access over your system, placing any financial or banking information at a high risk. Virus.Hidrag.a represents a serious security violation and is recommended to be eliminated with no delay.

Aliases

Generic Malware [Panda]Win32:Gardih [Avast]W32/Jeefo.e [McAfee]Heuristic: Suspicious File With Bad Child Associat [Prevx1]Jeefo (v) [Sunbelt]Worm.VB.dz [eWido]TROJ_FLOOD.AF [TrendMicro]W32.Jeefo [Symantec]ProAgent [Sunbelt]W32/Jeefo-A [Sophos]Virus:Win32/Jeefo.A [Microsoft]Win32.Hidrag.a [McAfee-GW-Edition]W32/Jeefo [McAfee]Virus.Win32.Hidrag [Ikarus]Virus.Win32.Hidrag.a [F-Secure]
More aliases (48)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



csrss.exe File name: csrss.exe
Size: 4.44 MB (4440801 bytes)
MD5: 46a66516dc3024c4cbd9ba96447bc358
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 3, 2016
NoDNS.exe File name: NoDNS.exe
Size: 102.4 KB (102400 bytes)
MD5: 37cecd1b557a87056a0a6b48df807410
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\svchost.exeHKEY..\..\..\..{RegistryKeys}Software\shudaxiaSYSTEM\ControlSet001\services\PowerManagerSYSTEM\ControlSet002\services\PowerManagerSYSTEM\CurrentControlSet\services\PowerManagerRun keysMSN
Loading...