









 |
W32/Magania.BEVF Trojan
| Name |
W32/Magania.BEVF Trojan |
| Aliases |
Trojan.Spy.Win32.Undef.ig, W32/Lineage.KWJ, Worm:Win32/Taterf.B, Trojan.Agent.AMZA. |
| Updated on |
June 15, 2009 |
Virus Information - W32/Magania.BEVF Trojan:
W32/Magania.BEVF is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan drops the following files in Windows\system32 folder:
udaprop.dll
cmuda.dll
cmirmdrv.dll
Audio3D.dll
a3d.dll
nmdfgds0.dll
nmdfgds1.dll
olhrwef.exe
cmirmdrv.exe
It drops the following files in Windows\system32\dllcache folder:
a3d.dll
ksuser.dll
drmk.sys
It drops the following files in Windows\system folder:
cmids3d.dll
SmWizard.exe
It also drops the following files:
cmuda.sys in Windows\system32\drivers folder drmk.sys in Windows\LastGood\system32\drivers folder
ksuser.dll in Windows\LastGood\system32 folder
The trojan modifies registry at the following locations:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
HKEY_USERS\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\Run

|