Web Explorer
Web Explorer is a spyware that stealthily monitors and records all websites visited. It is not visible in add/remove programs or task manager.
General information:
Malware Name: |
Web Explorer |
Malware Type: |
Spyware |
Company Name: |
All-Spy.com |
Company URL: |
http://www.all-spy.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
All-Spy.com provides you the software Web Explorer that is an easy to use application that stealthily monitors and records all websites visited. All reports can be sent in real time to a specified email address or can be accessed form the application
interface. It also monitors the websites visited and is easy to read xml reports. Its not visible in add/remove programs or task manager. Web Explorer has a password protected interface and hot-key combination for accessing the application. Also all
recorded information is stored in a secret, encrypted file.
Spyware Description:
Web Explorer is a spyware that stealthily monitors and records all websites visited. It is not visible in add/remove programs or task manager.
Characteristics/Symptoms:
-> It stealthily monitors and records all websites visited. -> Its not visible in add/remove programs or task manager.
Additional information might be found here:
Processes Running:
WEL.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Documents and Settings\[USER]\Application Data\WEL\Reps\WELErrors.txt |
40 |
Text Document |
C:\Documents and Settings\[USER]\Application Data\WEL\Reps\WELWeb.xsl |
3227 |
XSL Stylesheet |
C:\Documents and Settings\[USER]\Application Data\WEL\Reps\WELbk.bmp |
246 |
Bitmap Image |
Folder information Created after Installation:
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WEL |
ESMTPPORT |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WEL |
ESMTPPass4MailServer |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WEL |
ESMTPSRV |