Home Malware Programs Trojans MagicControl

MagicControl

Posted: March 28, 2006

MagicControl memory-resident downloader Trojan carries a payload that terminates certain processes, some firewalls and anti-virus products. Works on Windows 95, 98, NT, ME, 2000 and XP computers
It has been reported than MagicControl installs Instant Access Dialer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 NAVPMC.EXE
    2 WINCOMP.EXE
    3 winmgts.exe
    4 WINTRIM.EXE

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMCdeletethevaluescpntmgcmslagent.
Loading...