Advanced Email Monitoring

Advanced Email Monitoring is a spyware that records and forwards incoming and outgoing emails. It can also be installed in stealth mode.0

General information:

Malware Name: Advanced Email Monitoring
Malware Type: Spyware
Company Name: Softbe, Inc
Company URL: http://www.email-monitoring.net/
Threat Level: High Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Softbe, Inc provides you the software Advanced Email Monitoring that is well known e-mail monitoring software. It allows you to record and forward incoming and outgoing emails, including web-mail services like Hotmail and Yahoo mail. Once installed on monitored computer it sends copies of all incomng and outgoing emails to your secret email address. It can also be installed in stealth mode.

Spyware Description:

Advanced Email Monitoring is a spyware that records and forwards incoming and outgoing emails. It can also be installed in stealth mode.0

Characteristics/Symptoms:

    -> It records and forward incoming and outgoing emails. -> It can also be installed in stealth mode.

Additional information might be found here:

google Search at Google for Advanced Email Monitoring
bing Search at Bing for Advanced Email Monitoring
yahoo Search at Yahoo for Advanced Email Monitoring

Processes Running:

aemshell.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\Advanced Email Monitoring\aemshell.exe unknown
C:\Program Files\Advanced Email Monitoring\license.rtf unknown
C:\Program Files\Advanced Email Monitoring\readme.txt unknown

Folder information Created after Installation:

Folder Location
C:\Program Files\Advanced Email Monitoring

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Advanced Email Monitoring 0
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AdvEM 0
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AdvEM Changed0