Threat Database Trojans Mal/Emogen-B

Mal/Emogen-B

By Domesticus in Trojans

Mal/Emogen-B is a terrible computer trojan that is able to steal personal information collected on a targeted computer system and sends the stored data to remote servers. Mal/Emogen-B enables attackers get remote access to an affected computer system, and then execute numerous operations there. Mal/Emogen-B is able to download other malware infections from the web to the compromised computer without a user's authorization. Mal/Emogen-B will infect files and programs, steal a victim's confidential data, change system settings or drop backdoors to the computer system. Mal/Emogen-B should be removed as quickly as possible once detected on a PC system.

File System Details

Mal/Emogen-B may create the following file(s):
# File Name Detections
1. %Temp%\decrypted.exe
2. c:\safe36.exe
3. %System%\jx.exe
4. %Temp%\ddd1.exe
5. c:\cab10.log
6. %System%\SENDED_LOG.LOG
7. %System%\version.bin

Registry Details

Mal/Emogen-B may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\MiscStatus\1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{59EAE925-6127-11D3-9CA9-00A024F0AF03}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9EC30203-384D-11D3-9CA3-00A024F0AF03}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9EC30203-384D-11D3-9CA3-00A024F0AF03}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CertifWin.ValidaUsuario
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CertifWin.ValidaUsuario\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CertifWin.ValidaUsuario.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\Insertable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\MiscStatus
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{59EAE925-6127-11D3-9CA9-00A024F0AF03}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9EC30203-384D-11D3-9CA3-00A024F0AF03}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9EC30203-384D-11D3-9CA3-00A024F0AF03}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EC301F7-384D-11D3-9CA3-00A024F0AF03}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EC301F7-384D-11D3-9CA3-00A024F0AF03}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CertifWin.ValidaUsuario\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\Control
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\ToolboxBitmap32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EC30204-384D-11D3-9CA3-00A024F0AF03}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{59EAE925-6127-11D3-9CA9-00A024F0AF03}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{59EAE925-6127-11D3-9CA9-00A024F0AF03}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EC301F7-384D-11D3-9CA3-00A024F0AF03} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EC301F7-384D-11D3-9CA3-00A024F0AF03}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EC301F7-384D-11D3-9CA3-00A024F0AF03}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EC301F7-384D-11D3-9CA3-00A024F0AF03}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CertifWin.ValidaUsuario.1\CLSID

Trending

Most Viewed

Loading...