Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

W32.JEEFO Repair?

Status
Not open for further replies.

kramerd1506

Technical User
Jul 18, 2003
20
0
0
US
Does anyone know of a tool, utility, or any other way to repair .exe files infected with the w32.jeefo virus?

I would REALLY appreciate the help.

ThAnKs!!
 
Yes, I know. I had Norton AV but had let the definitions lapse for about 90 days or so. When I renewed it is when I found the virus.

I have read the link you posted thoroughly. Do you understand what is meant by this:

"When svchost.exe (the first-generation W32.Jeefo executable) runs, it checks whether the program parameter specifies an infected application. If it detects that another application dropped and ran it, and that the application contains the following infection marker at a fixed file offset:

Hidden Dragon virus. Born in a tropical swamp.

it will perform the following actions:

Waits until the infected host quits so that its file is unlocked.
Reconstructs the original host by detaching appended data, decoding it, and moving the resources back to it.
Runs the reconstructed executable that does not contain W32.Jeefo code.

In other words, when an application infected with W32.Jeefo is executed, the dropped W32.Jeefo first-generation program repairs it."

If the virus itself repairs these files, then shouldn't it be rather easy to find a repair tool on the internet somewhere? I can find no repair option talked about on the Symantec website or anywhere else. Does the above quote make any sense to you?
 
It's NOT repairing the file, simply "morphing" it to the new generation Jeepo.. Finds infected file, repairs to original and then re-infects.. The "repair" is to re-infect NOT fix !!!!

Murray
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top