Watcher

Watcher is a spyware that can monitor your home or office. It can also run in stealth mode. It can capture video clips and audios also.

General information:

Malware Name: Watcher
Malware Type: Spyware
Company Name: Digi-Watcher.com
Company URL: http://www.digi-watcher.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Digi-Watcher.com provides you the software Watcher that monitors your home or office 24 hours a day, captures motion event using webcam, saves into compressed video clips with audio and triggers various alerts including ftp upload, email or phone. It also has camera image broadcasting capability, which can publish your webcam on a remote website or Watcher s embedded web server. Watcher can run in stealth mode, it can also be scheduled, or run as an NT service.

Spyware Description:

Watcher is a spyware that can monitor your home or office. It can also run in stealth mode. It can capture video clips and audios also.

Characteristics/Symptoms:

    -> It can monitor your home or office. -> It can also run in stealth mode. -> It can capture video clips and audios also.

Additional information might be found here:

google Search at Google for Watcher
bing Search at Bing for Watcher
yahoo Search at Yahoo for Watcher

Processes Running:

Watcher.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\Digi-Watcher.com\Watcher 2.30\Demo\cap_disabled_big.JPG 29514 JPEG Image
C:\Program Files\Digi-Watcher.com\Watcher 2.30\Demo\cap_main.jpg 30026 JPEG Image
C:\Program Files\Digi-Watcher.com\Watcher 2.30\Demo\cap_main_big.jpg 34496 JPEG Image

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\[USER]\Start Menu\Programs\Digi-Watcher.com\Watcher 2.3
C:\Program Files\Digi-Watcher.com\Watcher 2.3

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{A4545E47-89CA-11D6-AF8D-000347889858}
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{A4545E47-89CA-11D6-AF8D-000347889858}\InprocServer32 ThreadingModel
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\dgw_auto_file