Jeefo Removal Tool icon

Jeefo Removal Tool

2 big stars
Jeefo Removal Tool screenshot
Name: Jeefo Removal Tool
Works on: windowsWindows 7 and above
Developer: Bitdefender LLC
Version: 1
Last Updated: 27 Feb 2017
Release: 02 Aug 2010
Category: Antivirus > Removal Tools
Rate this software:
1028 downloads
screenshotsView Screenshots(1)
commentsComments
downloadDownload
Liked it? Tell others:
details

Jeefo Removal Tool Details

Works on: Windows 10 | Windows 8.1 | Windows 8 | Windows 7 | Windows 2012
SHA1 Hash: 084afffda0dff5af6f966b6de6d80f58f7b5a799
Size: 58.88 KB
File Format: exe
Rating: 2.260869565 out of 5 based on 23 user ratings
Downloads: 1028
License: Free
Jeefo Removal Tool is a free software by Bitdefender LLC and works on Windows 10, Windows 8.1, Windows 8, Windows 7, Windows 2012.
You can download Jeefo Removal Tool which is 58.88 KB in size and belongs to the software category Removal Tools.
Jeefo Removal Tool was released on 2010-08-02 and last updated on our database on 2017-02-27 and is currently at version 1.
download button
Thank you for downloading from SoftPaz! Your download should start any moment now. It would be great if you could rate and share:
Rate this software:
Share in your network:
features

Jeefo Removal Tool Description

Jeefo Removal Tool is a lightweight utility that can help you clean the Win32.Jeefo.A malware from your system.
This executable file infector is written in MinGW and presents a very interesting (and difficult to disinfect) infection technique. It contains various strings, encrypted with a trivial algorithm:
.text:004012B0 decryption_loop:
.text:004012B0 mov cl, [edx+ebx]
.text:004012B3 dec cl
.text:004012B5 mov [edx+eax], cl
.text:004012B8 inc edx
.text:004012B9 cmp edx, edi
.text:004012BB jl short decryption_loop
When an infected file is executed for the first time, the virus receives control and dumps a copy of itself in the Windows directory as svchost.exe and registeres itself to be executed at every system startup: under Windows 9x/Me it adds a key to HKEY_LOCAL_MACHINE \Software\Microsoft\Windows\CurrentVersion\RunServices; under NT/2000/XP, it creates a service called "Power Manager".
The file infection algorithm is complex; in some cases, infected files get corrupted (the virus is not capable of handling certain resource types).
The infected file has the following layout:
1) Virus
2) Original file\s resources (bitmaps, icons, etc) -> thus the infected file has the same main icon as the original file
3) Original file chunks - encrypted
The disinfection routine decrypts the file chunks, re-links the file, adds the resources and re-locates them to the new relative virtual address. Resource relocation is tricky and in some cases may cause the virus to fail (crash); however, these files are correctly disinfected by BitDefender.
The virus contains the following text string: "Hidden Dragon virus. Born in a tropical swamp." encrypted with the same trivial encryption algorithm as above. When encrypted, the word "hidden" is transformed to "iJeefo" (this is where this virus got his name from).
screenshots

Jeefo Removal Tool Screenshots

Jeefo Removal Tool screenshot 1
similarSimilar Software