Home Malware Programs Trojans Trojan.Win32.Genome.ebmm

Trojan.Win32.Genome.ebmm

Posted: May 1, 2011

Trojan.Win32.Genome.ebmm is a label covering a broad group of Trojan infections that share many characteristics. A computer infected with Trojan.Win32.Genome.ebmm should be considered a top-level security risk, since Trojan.Win32.Genome.ebmm can attack firewalls and other security features, enable attacks by remote criminals and hide copies of itself to be unintentionally shared with other computers. Because Trojan.Win32.Genome.ebmm is a complex threat that will try to avoid being deleted, try to remove Trojan.Win32.Genome.ebmm with good anti-malware programs rather than deleting Trojan.Win32.Genome.ebmm on your own.

Trojan.Win32.Genome.ebmm is More Than Just a Trojan

Reports indicate that Trojan.Win32.Genome.ebmm attacks computers running Windows NT, Windows XP, Windows 2000 and Windows Vista, although Windows 7 users are not necessarily guaranteed safety. Trojan.Win32.Genome.ebmm is usually distributed by other Trojans that infect your computer through browser exploits or by pretending to be updates for legitimate software. Although Trojan.Win32.Genome.ebmm is rated to be a critical-level threat, there may be no symptoms or obvious signs of Trojan.Win32.Genome.ebmm's attacks. Since Trojan.Win32.Genome.ebmm or the original Trojan may be packed, they may avoid preemptive anti-malware defenses that would block them in normal situations.

Entries inserted into your Windows Registry will let Trojan.Win32.Genome.ebmm run without your permission as a background memory process. From this privileged position, Trojan.Win32.Genome.ebmm may practice any or all of the succeeding attacks:

  • Trojan.Win32.Genome.ebmm may attack security features or programs. This may be subtle, such as burrowing exceptions into your firewall, or very obvious, such as disabling the use of anti-virus scanners and programs like Windows Update.
  • Trojan.Win32.Genome.ebmm may download other harmful files. These files may be other types of malware, or they can be remote tools that remote attackers can use to take full control over your PC.
  • Trojan.Win32.Genome.ebmm also exhibits characteristics of a worm by copying itself to removable drives and network-shared folders. These copies will be rendered invisible by being given the Hidden or System attributes, although you can change your file-viewing settings to see files with such attributes. Anyone who accesses a folder or removable drive device infected by Trojan.Win32.Genome.ebmm will acquire a case of Trojan.Win32.Genome.ebmm of their very own.

Keep Your Gates Fortified Against Trojan.Win32.Genome.ebmm

Because Trojan.Win32.Genome.ebmm is able to reproduce and spread very quickly it's important that you maintain heavy security to keep your PC uninfected. Avoid accessing network-shared resources unless you're certain that a computer isn't infected by Trojan.Win32.Genome.ebmm, and never use a removable device until the contents have been verified to be safe.

Trojan.Win32.Genome.ebmm is a fairly recent infection, with reports indicating that Trojan.Win32.Genome.ebmm arose only in 2011. Update your anti-malware scanners on a regular basis to have the best chance of catching Trojan.Win32.Genome.ebmm before Trojan.Win32.Genome.ebmm can cause severe harm.

Trojan.Win32.Genome.ebmm is also noted to have an origin point in Russia. Avoiding files from that region, or being particularly careful to scan such files before opening them will also help you evade possible infection.

Once you remove Trojan.Win32.Genome.ebmm, preferably by using the best anti-malware software you can find, remember to revert your security settings back to their normal values. Firewall exceptions and other changes may still remain in place even after you delete Trojan.Win32.Genome.ebmm.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}KEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XTray.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XTray.exe
Loading...