Home Malware Programs Trojans Mal/Emogen-P

Mal/Emogen-P

Posted: November 25, 2009

Mal/Emogen-P a Trojan horse that may place a compromised system, as well as its network environment, at risk. Mal/Emogen-P may infiltrate a computer and open a passage through which large amounts of adware and spyware can be piped onto a compromised system. In order to protect your PC and the sensitive information stored on it, remove Mal/Emogen-P immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Baidu\AddressBar\AddressBar.dll
    2 %ProgramFiles%\Baidu\AddressBar\AddressBar_Tmp\AddressBar.dll
    3 %ProgramFiles%\��ݷ�ʽ\kkjie_skins\Default\line.png
    4 %ProgramFiles%\��ݷ�ʽ\languages\Chinese.lang
    5 %ProgramFiles%\��ݷ�ʽ\xiezai.exe
    6 %ProgramFiles%\��ݷ�ʽ\��ݷ�ʽ.url

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}][HKEY_LOCAL_MACHINE\SOFTWARE\AddressBar\iexp][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-0593-4356-9CF7-1D8C2B3343C0}]HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AddressBar]��ݷ�ʽ]
Loading...