Home Malware Programs Adware Mighty Magoo

Mighty Magoo

Posted: January 10, 2011

Mighty Magoo (or Adware.Magoo) is a malicious adware program which collects data on browsing history and then sends it to remote server for hackers to access. Identity theft is the main aim for these hackers who use Adware.Magoo's spying ability to access the unwary users' profile and take over the browser to show corrupt adverts that correspond with the user's internet browsing habits. This adware may block search engines and legitimate websites and cause all sorts of system malfunctions. Get rid of Mighty Magoo immediately once it has been detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Mighty Magoo\ars.cfg
    2 %ProgramFiles%\Mighty Magoo\icon.ico
    3 %ProgramFiles%\Mighty Magoo\mightymagoo32.exe
    4 %ProgramFiles%\Mighty Magoo\mightymagoolib32.dll
    5 %ProgramFiles%\Mighty Magoo\mmagootl.dll
    6 %ProgramFiles%\Mighty Magoo\mmagooun.exe
    7 %UserProfile%\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@mmagoo.com\chrome.manifest
    8 %UserProfile%\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@mmagoo.com\chrome\mmtextlinks.jar
    9 %UserProfile%\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@mmagoo.com\components\mmagootlf.dll
    10 %UserProfile%\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@mmagoo.com\components\mmagootlf.xpt
    11 %UserProfile%\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@mmagoo.com\install.rdf

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\[SID]\Software\AppDataLow\mmagootlHKEY_CURRENT_USER\[SID]\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEAD004E-7E2D-49f8-831C-A01647E85B53}HKEY_CURRENT_USER\[SID]\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97E74A14-E5F1-40CC-9B0F-0D11946E5469}HKEY_CURRENT_USER\[SID]\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEAD004E-7E2D-49F8-831C-A01647E85B53}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\MightyMagooText.DLLHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97E74A14-E5F1-40cc-9B0F-0D11946E5469}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEAD004E-7E2D-49f8-831C-A01647E85B53}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MightyMagooText.LinkerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97E74A14-E5F1-40cc-9B0F-0D11946E5469}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEAD004E-7E2D-49f8-831C-A01647E85B53}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Mightymagoo" = "%ProgramFiles%\Mighty Magoo\mightymagoo32.exe a"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}MightyMagoo
Loading...