|
| How to remove Trackware.WebExplorer |
|
| Author:Trackware.WebExplorer Hits: UpdateTime:2008-8-11 19:42:50 |
|
|
|
|
|
|
For remove Trackware.WebExplorer virus,please clean/delete all Trackware.WebExplorer infected files and Delete/Modify any values Trackware.WebExplorer added to the registry as following:
The risk is manually downloaded and installed by the user.
When the risk is executed, it creates the following folders:
- C:\Documents and Settings\All Users\Application Data\WEL\
- C:\Documents and Settings\All Users\Application Data\WEL\Reps\
It then creates the following files:
- C:\Documents and Settings\All Users\Application Data\WEL\EML.exe
- C:\Documents and Settings\All Users\Application Data\WEL\Reps\TestEmail.xml
- C:\Documents and Settings\All Users\Application Data\WEL\Reps\WELAllDayWELWeb.xsl
- C:\Documents and Settings\All Users\Application Data\WEL\Reps\WELbk.bmp
- C:\Documents and Settings\All Users\Application Data\WEL\Reps\WELErrors.txt
- C:\Documents and Settings\All Users\Application Data\WEL\Reps\WELWeb.xsl
- C:\Documents and Settings\All Users\Application Data\WEL\WEL.chm
- C:\Documents and Settings\All Users\Application Data\WEL\WEL.dll
- C:\Documents and Settings\All Users\Application Data\WEL\WEL.exe
- C:\Documents and Settings\All Users\Application Data\WEL\WELUninstaller.exe
- C:\Documents and Settings\All Users\Application Data\WEL\xcacls.exe
Next it creates the following registry entry so that it runs every time Windows starts: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"WEL" = "C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\All Users\Application Data\WEL\WEL.dll"
It creates the following registry subkey: HKEY_LOCAL_MACHINE\SOFTWARE\WEL
The risk may then perform the following activities:
- Monitor and log Web sites visited.
- Create and send logs to a predefined email address.
- Run in stealth mode.
For successful remove Trackware.WebExplorer virus,you may also need do as following:
1. Temporarily Disable System Restore .
2. Update the virus definitions. Reboot computer in SafeMode;
3. Delete the IE temp files,some Trackware.WebExplorer temp file exisit there.
4.If you failed to remove Trackware.WebExplorer,please go to our remove help forum:http://help.antiviruses123.com
|
| End Of The Article How to remove Trackware.WebExplorer remove process |
|
Packed.Generic.180 Packed.Generic.64 Packed.Generic.179 W32.Koobface.B W32.Koobface.A Trojan.Spamuzle Trojan.Proscks.C Trojan.Wsnpoem Trojan.Brisv.A Trojan.Downexec.B Trojan.Ditsec Trojan.Spamuzle!inf Packed.Generic.177 RegistryDoctor2008 Trojan.Proscks.C!inf Trojan.Brisv.A!inf Backdoor.Lancafdo Packed.Generic.174 RegistryDefender Packed.Generic.157
|