Home Malware Programs Trojans Mal/Emogen-I

Mal/Emogen-I

Posted: May 5, 2011

Mal/Emogen-I is a malicious computer trojan that will do lots of malicious activities without an infected user's consent, for example, register a 32-bit in-process server DLL, register a browser helper object which will influence the normal performance of the computer system. Mal/Emogen-I may affect computers through file-sharing applications, via chat and messaging systems or via adult related websites. Mal/Emogen-I may spread via drive-by downloads and does not request a user's authorization to run on a computer. Mal/Emogen-I is created to download harmful files and change registry entries to slow down your computer. Mal/Emogen-I has to be removed immediately to keep your computer away from risk.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\log.bat
    2 %Windir%\orbit.exe
    3 %Windir%\reg.exe
    4 %Windir%\WindowsInstaller.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B2E2DA4E-B3CD-4D52-A074-A8063EC81BDF}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B2E2DA4E-B3CD-4D52-A074-A8063EC81BDF}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B2E2DA4E-B3CD-4D52-A074-A8063EC81BDF}
Loading...