Home Malware Programs Worms Malware.Jeefo

Malware.Jeefo

Posted: November 30, 2010

Malware.Jeefo is a network-aware worm that attempts to replicate across the existing network. Malware.Jeefo makes use of a program that downloads files to the local computer that may represent security risk as it is capable of modifying other files by infecting, prepending, or overwriting them with its own body. Use a reliable malware remover to make sure your PC is free from Malware.Jeefo.

Aliases

W32.Jeefo (Symantec)
Virus.Win32.Hidrag.a (Kaspersky Lab)
W32/Jeefo (McAfee)
PE_JEEFO.A (Trend Micro)
W32/Jeefo-A (Sophos)
Virus:Win32/Jeefo.A (Microsoft)
Virus.Win32.Hidrag (Ikarus)
Win32/Hidrag (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\addons.dat
    2 %AppData%\Bifrost\logg.dat
    3 %AppData%\Xenocode\Sandbox\1.0.0.0\2010.08.30T00.09\Virtual\STUBEXE\@SYSTEM@\server.exe
    4 %AppData%\Xenocode\Sandbox\1.0.0.0\2010.08.30T00.09\Virtual\XRegistry.bin
    5 %Windir%\svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}(Default) =[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...