Home Malware Programs Trojans Trojan.Jifake

Trojan.Jifake

Posted: February 25, 2011

Trojan.Jifake is a Windows-based Trojan that will use the host system to send premium Short Message Service messages. Although Trojan.Jifake's infection rate and risk level are currently assessed as low, maintaining a vigilant attitude against this Trojan is necessary to keep Trojan.Jifake a low threat. Trojan.Jifake infections may represent a security risk by connecting to malicious domains and downloading files without your consent. Users of Windows ME or Windows XP will find deleting Trojan.Jifake to be slightly more challenging, and should be prepared to circumnavigate the Trojan's additional defenses.

Trojan.Jifake is a Multi-Platform Infection

The Trojan.Jifake Trojan will only target Windows versions 9x, 2K, Vista and Windows 7. Users of these operating systems shouldn't require any unusual defenses to prevent Trojan.Jifake from penetrating their defenses – standard security programs and settings should be more than sufficient, provided that all application is reasonably up to date. Trojan.Jifake was only identified as a threat in 2011, and anti-virus programs with earlier threat databases may be unable to recognize Trojan.Jifake.

What makes Trojan.Jifake truly unique is Trojan.Jifake's function of using infected computers to send out premium SMS messages. Although these mobile text messages are much less versatile than the messages a true Windows operating system is capable of, they can nonetheless be dangerous and spread malware and other threats indirectly, which means that deleting Trojan.Jifake is generally courteous behavior besides being a wise precaution for the well-being of one's machine.

High-Danger Aspects of Trojan.Jifake Infections

There are some aspects of Trojan.Jifake that are more alarming than Trojan.Jifake's SMS behavior. Like many other Trojans, Trojan.Jifake will inherently reduce the security on your system, and Trojan.Jifake may use this lowered security to download other malware. While Trojan.Jifake's scope is limited, Trojan.Jifake may download other malware with more broad-reaching functions such as spyware that records keyboard input or browser hijackers that redirect your web browser towards dangerous websites.

Users of Windows XP or Windows ME will find removing Trojan.Jifake to be a little harder than people on other operating systems. The extra trick Trojan.Jifake throws in your path in this case is to use the System Restore capability to restore itself whenever Trojan.Jifake is deleted! Temporarily disabling this feature will allow you to delete Trojan.Jifake completely. Keeping your System Restore feature permanently disabled is generally inadvisable, but until the Trojan.Jifake Trojan is dealt with, Trojan.Jifake may be doing more harm than good.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CurrentFolder%\jimm2010.jar
    2 %CurrentFolder%\love_mms.rar

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
Loading...