Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
EMULE.EXE has been seen to perform the following behavior:
- This Process Contains User Mode Rootkit Functionality and can hide itself from the running process list
- Found on infected systems and resists interrogation by security products
- This process creates other processes on disk
- Adds products to the system registry
- This Process Deletes Other Processes From Disk
- Changes the Internet Explorer Home Page Settings
- Uses low level functions to hide itself from the user and from system/security processes
- Creates a TCP port which listens and is available for communication initiated by other computers
- Communicates with other computers using FTP connections
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
- Can communicate with other computer systems using HTTP protocols
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Can communicate with other computers using TCP protocols
- Can examine and send Email using POP3 protocols
- Executes a Process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Registers a Dynamic Link Library File
- Can communicate with other computers using TELNET protocols
- Creation and Registers a Browser Helper Object in Internet Explorer
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Sends email using SMTP protocols
- The Process is packed and/or encrypted using a software packing process
- Creates new file extentions so that Internet Explorer will automatically open and potentially execute additional file types
EMULE.EXE has been the subject of the following behavior:
- Created as a process on disk
- Deleted as a process from disk
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Executed by Internet Explorer
- Registered as a Dynamic Link Library File
- Terminated as a Process
Country Of Origin
The filename EMULE.EXE was first seen on May 12 2007 in the following geographical regions of the Webroot community:
- Poland on May 12 2007
- Hungary on Jun 1 2007
- Italy on Jun 1 2007
- Spain on Mar 1 2008
- South Africa on Mar 1 2008
- Russian Federation on May 24 2012
File Name Aliases
EMULE.EXE can also use the following file names:
- SOFTWARE.EXE
- SETUP.EXE
- USB2.0.EXE
- WIN2K.EXE
- WINXP.EXE
- RESTORE.EXE
- MUSIC.EXE
- RNB G PUFF JOHNSON.EXE
- MIRACLE.EXE
- UNKNOWN ARTIST.EXE
- DAVID BYRNE.EXE
- LUDWIG VAN BEETHOVEN, COMPOSER. SEATTLE SYMPHONY. GERARD SCHWARZ.EXE
- MARC SEALES COMPOSER. NEW STORIES. ERNIE WATTS SAXOPHONE_.EXE
- LSG.EXE
- YESTERDAY, TODAY & TOMORROW.EXE
- PURA.EXE
- HAMPER.EXE
- HOUSE FOLDER.EXE
- WINDOWS.EXE
- PROGRAM FILES.EXE
- AOG REGION.EXE
- PROGRAMS.EXE
- AOG NATIONAL.EXE
- DOCUMENTS AND SETTINGS.EXE
- LEADERSHIP TRAINING.EXE
- PHOTOS.EXE
- SONGS.EXE
- MY MUSIC.EXE
- AOG WOMEN.EXE
- WORSHIP.EXE
- MY PICTURES.EXE
- MY DATA SOURCES.EXE
- PICTURE.EXE
- SAMSUNG.EXE
- ALIWAL VISIT.EXE
- CAYLEN'S BIRTHDAY AND FAMILY PHOTOS.EXE
- CRECHE PHOTOS.EXE
- ED VISIT.EXE
- JEFFS.EXE
- MOTHERSDAY.EXE
- OUDTSHOORN TRIP.EXE
- SERMONS.EXE
- AOG KING.EXE
- CRECHE.EXE
- AOG NEWSLETTER MATERIAL.EXE
- NEW FOLDER.EXE
- MICROSOFT CLIP ORGANIZER.EXE
- SONG WORDS.EXE
- CAPCOM GAMES.EXE
- SAMPLE PICTURES.EXE
- CFG.EXE
- ROMS.EXE
- SAMPLES.EXE
- SNAP.EXE
- SAMPLE MUSIC.EXE
- SAMPLE PLAYLISTS.EXE
- MY PLAYLISTS.EXE
- SMITHS PLASTICS.EXE
- SOBABILI TRADING.EXE
- BIT BUSSINESS DOCUMENTS.EXE
- CREDIT APPLICATION.EXE
- AAAANEW HOLLAND.EXE
- CHUBB ARTWORKS.EXE
- CHUBB FIRE STORES.EXE
- BEST IMAGE BROCHURE.EXE
- ADMIN NAMES.EXE
- EMULE049B.EXE
- EMULE049B[n].EXE
- EMULE048A.EXE
- EMULE049B(n).EXE
- EMULE049B (n).EXE
- EMULE.EXK
- LOTUS.EXE
- XMAS PARTY PICS.EXE
- TIAGO PICS.EXE
- SNOW07.EXE
- JESSICA'S 2ND BIRTHDAY PARTY.EXE
- FAMILY PICS.EXE
- GHOST.BAT
- RECYCLER.EXE
- SLIZ.EXE
- GAMES.EXE
- PACMAN.EXE
- GAMES 1.EXE
- SIYALIZUA SCHOOL.EXE
- INTERVIEW QUESTIONS.EXE
- PC SKILLS TEST.EXE
- PC SKILLS TEST 2.EXE
- VVR.EXE
- CONFIG.EXE
- S-1-5-21-1482476501-1644491937-682003330-1013.EXE
Filesizes
The following file size has been seen:
- 61,440 bytes
- 2,632,230 bytes
- 6,052,864 bytes
- 4,517,888 bytes
- 2,209,280 bytes
- 5,746,688 bytes
- 5,599,232 bytes
File Type
The filename EMULE.EXE refers to many versions of an executable program.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.