Home Malware Programs Worms Magflag

Magflag

Posted: March 28, 2006

Magflag is a rapidly spreading Internet worm that propagates by e-mail in messages with infected attachments and through file sharing networks using popular peer-to-peer softwares.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 flg.exe
    2 rechnung.pdf.exe
    3 winldr.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}%System%svchost.exe:*:Enabled:svchostHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.exewinldr.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%System%svchost.exe=

Related Posts

Loading...