MG-Shadow

It is a network application that allows users to manage and control PCs or networks from a remote location.0

General information:

Malware Name: MG-Shadow
Malware Type: Key Logger
Company Name: MG-Shadow.com
Company URL: http://www.mg-shadow.com/
Threat Level: Moderate Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

MG-Shadow.com provides us with the keylogger that saves the money by ensuring that whether the employees are working or surfing on net. It also protects children from the porn merchants. It also helps our relatives and friends knowing that their children and family were protected as well. It also puts us in total control of the business by boosting efficiency. Side by side it also gives peace and made our life much easier.

Spyware Description:

It is a network application that allows users to manage and control PCs or networks from a remote location.0

Characteristics/Symptoms:

    -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0

Additional information might be found here:

google Search at Google for MG-Shadow
bing Search at Bing for MG-Shadow
yahoo Search at Yahoo for MG-Shadow

Processes Running:

Shadow.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\MGS trial\Shadow.exe 998912 Application
C:\Program Files\MGS trial\ShadowExport.dll 226304 Application Extension
C:\Program Files\MGS trial\ShadowRes.dll 303104 Application Extension

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\Sapna\Start Menu\Programs\MG WAY CORP
C:\Program Files\MGS trial

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionRun MG-Shadow trial
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstallShadow UninstallString