W32/Jeefo-A

Discussion in 'malware problems & news' started by FanJ, Jun 11, 2003.

Thread Status:
Not open for further replies.
  1. FanJ

    FanJ Guest

    W32/Jeefo-A

    Aliases : PE_JEEFO.A, W32/Jeefo, W32.Jeefo

    Type : Win32 worm

    Description
    W32/Jeefo-A may create the following registry entries upon execution, so that it is run every time the computer restarts:

    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\PowerManager
    = "<full file path>"

    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\PowerManager
    = "C:\<Windows>\SVCHOST.EXE"


    http://www.sophos.com/virusinfo/analyses/w32jeefoa.html
     
  2. FanJ

    FanJ Guest

  3. Randy_Bell

    Randy_Bell Registered Member

    Joined:
    May 24, 2002
    Posts:
    3,004
    Location:
    Santa Clara, CA
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.