Home Malware Programs Trojans Mal/Emogen-R

Mal/Emogen-R

Posted: March 7, 2011

Predominantly an alias for password-stealing spyware and generic dropper Trojans, Mal/Emogen-R can install malware onto your machine without you knowing it, disable your security, and in some cases may also be able to record and steal sensitive information. The majority of Mal/Emogen-R infections can't propagate through networks, but some can, which encourages strong attention paid to network-shared file security and the integrity of your removable drive devices. Deleting Mal/Emogen-R should be done promptly and thoroughly; this Trojan may be an older threat, but Mal/Emogen-R hasn't lost its potential for damage over time.

Gamers, Guard Your Passwords against Mal/Emogen-R

Detection of Mal/Emogen-R can pop up for many different types of Trojans and a few other infections, but commonly occurs in the case of malware focused on stealing passwords for online bank accounts, online games and other popular applications. Thus, one of the foremost threats whenever you see Mal/Emogen-R is in the potential for losing private login information.

If you suspect that your PC has a Mal/Emogen-R infection, try to avoid typing passwords or other delicate information. Many kinds of spyware are keyloggers, which can record individual keystrokes from your keyboard. Avoiding typing isn't a perfect solution, however; Mal/Emogen-R and other possible spyware can search for this information in other ways, up to and including taking screen captures of your monitor display.

Mal/Emogen-R has been online in one form or another since 2008 and can be easily caught by any reasonably up to date anti-malware program. This isn't necessarily an excuse to be lax about updating your anti-virus scanners; since Mal/Emogen-R can encompass a number of different threats, you should keep security applications updated to cover all possibilities.

In the best case, Mal/Emogen-R can be a false positive detected from a completely innocent file. Most good security programs have been reported to have fixed these problems in database patches, which gives you yet another reason to update every once in a while.

A Probable Trojan, but What Else?

Mal/Emogen-R's other side effects and attacks are summed up below:

  • In some rare cases, Mal/Emogen-R is a worm detection. Worms are able to spread through network-shared files and removable drive devices by infecting innocent files and exploiting Autorun-based functions. Secondary PCs should never come in contact with any peripheral or file that has been linked to a Mal/Emogen-R-infected PC until all devices and files are verified to be clean.
  • Much more often, Mal/Emogen-R is a Trojan that installs other kinds of malware like viruses, keyloggers or rogue anti-spyware products onto your PC. Trojan infection will continue to cause further infections until they're deleted, and their existence on your hard drive at all is a considerable security hazard.
  • In some cases, Mal/Emogen-R may be a backdoor Trojan. Backdoor types of Trojans will focus on destroying security to let remote attackers attack the PC. Remote attacks can be visible mouse or keyboard input control, additional malware downloads or forced behavior such as DDoS recruitment.

Deleting Mal/Emogen-R may require targeting different files depending on the type of infection. In most cases, cleaning the Registry is also required, and because of these two things it's usually better let an anti-malware program do the cleanup. A mistake in manually removing Mal/Emogen-R can harm your computer or allow the malware to come right back to life.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\Help\winhelp.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINHELPHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINHELP\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINHELP\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winhelpHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winhelp\EnumHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winhelp\Security
Loading...