Home Malware Programs Trojans Magflag.b

Magflag.b

Posted: March 28, 2006

Magflag.b is a trojan that secretly downloads from the Internet and executes arbitrary potentially harmful files without user consent. The spyware is able to hide itself by injecting malicious code into essential Windows components. It can also lower computer security settings in order to bypass Windows firewall. Magflag.b automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winldr.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.exewinldr.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%explorer.exe=%Windir%explorer.exe:*:Enabled:explorer
Loading...