Advertisement


Jeefo Removal Tool

Application Information

License
Free version
OS
Windows Xp
Windows Vista
Windows 7
Windows 8
Size
1 MB
Application Website

Description

Jeefo Removal Tool



Jeefo Removal Tool is a lightweight utility that can help you clean the Win32.Jeefo.A malware from your system. This executable file infector is written in MinGW and presents a very interesting (and difficult to disinfect) infection technique. It contains various strings, encrypted with a trivial algorithm:

.text:004012B0 decryption_loop:
.text:004012B0 mov cl, [edx+ebx]
.text:004012B3 dec cl
.text:004012B5 mov [edx+eax], cl
.text:004012B8 inc edx
.text:004012B9 cmp edx, edi
.text:004012BB jl short decryption_loop

When an infected file is executed for the first time, the virus receives control and dumps a copy of itself in the Windows directory as svchost.exe and registeres itself to be executed at every system startup: under Windows 9x/Me it adds a key to HKEY_LOCAL_MACHINE SoftwareMicrosoftWindowsCurrentVersionRunServices; under NT/2000/XP, it creates a service called "Power Manager".

The file infection algorithm is complex; in some cases, infected files get corrupted (the virus is not capable of handling certain resource types).

The infected file has the following layout:
1) Virus
2) Original file's resources (bitmaps, icons, etc) -> thus the infected file has the same main icon as the original file
3) Original file chunks - encrypted

The disinfection routine decrypts the file chunks, re-links the file, adds the resources and re-locates them to the new relative virtual address. Resource relocation is tricky and in some cases may cause the virus to fail (crash); however, these files are correctly disinfected by BitDefender.

The virus contains the following text string: "Hidden Dragon virus. Born in a tropical swamp." encrypted with the same trivial encryption algorithm as above. When encrypted, the word "hidden" is transformed to "iJeefo" (this is where this virus got his name from).

Jeefo Removal Tool


Website - Jeefo Removal Tool

See also
Notice

You should be careful when using serials, cracks, torrents, keygens and warez that you download from crack sites. They often contain adware, spyware, malware or other nasty modifications that you definitely will not want to have on your computer. A lot of crack websites who offer such full version downloads or cracked programs, Kristanix serials and keygens try to infect your computer, in order to try to steal your bank account and credit card information, so we strongly recommend not downloading cracked versions, as you never know what they have modified... And did you know that even just visiting websites who offer this kind of downloads can be harmful to your computer? Many contain javascripts and ActiveX controllers that try to access your computer as soon as you visit it, so if you don't have a good firewall or browser, you might get attacked without even downloading anything. 

Your computer will be at risk getting infected with spyware, adware, viruses, worms, trojan horses, dialers, etc while you are searching and browsing these illegal sites which distribute a so called keygen, key generator, pirate key, serial number, warez full version or crack for Jeefo Removal Tool download. These infections might corrupt your computer installation or breach your privacy. A keygen or key generator might contain a trojan horse opening a backdoor on your computer. Hackers can use this backdoor to take control of your computer, copy data from your computer or to use your computer to distribute viruses and spam to other people.

Download links are directly from our mirrors or publisher's website, Jeefo Removal Tool torrent files or shared files from free file sharing and free upload services, including Rapidshare, HellShare, HotFile, FileServe, MegaUpload, YouSendIt, SendSpace, DepositFiles, Letitbit, MailBigFile, DropSend, MediaMax, LeapFile, zUpload, MyOtherDrive, DivShare or MediaFire, are not allowed!

Link To Jeefo Removal Tool