Home Malware Programs Browser Hijackers Exlee.com

Exlee.com

Posted: April 25, 2016

Threat Metric

Ranking: 14,938
Threat Level: 5/10
Infected PCs: 1,237
First Seen: April 25, 2016
Last Seen: September 13, 2023
OS(es) Affected: Windows


Exlee is a suspicious Web extension with browser hijacking features. Exlee.com may become part of your system if you download any freeware from unreliable platforms, and skip details during the installation process. Exlee may alter the configuration of Google Chrome, Mozilla Firefox and Intenet Explorer automatically. You may not appreciate the modifications. This browser hijacker may change your homepage to exlee.com, which is a low-quality search provider. If you don't want to risk visiting potentially harmful sites, you should not use this engine. The developers of Exlee gain profits from transferring unsuspecting users towards specific third-party pages. The partner network is very large. Whenever the sponsored links that exlee.com shows lead you to some of these domains, the developers of the browser hijacker will get certain commissions. On the other hand, the administrators of the partner sites will receive a steady flow of visitors, which may help them grow their business. You should know that some of the affiliated pages may be unsafe. It is true that in some cases exlee.com may open legitimate e-commerce platforms, but in other circumstances you may end up on compromised domains. One of the main issues with this search engine is that Exlee.com doesn't mark the ads properly. The sponsored links may seem to be legitimate results. You may notice them in the front positions. As long as the browser hijacker remains in your system, exlee.com may be your default search engine. This shady provider may appear as your homepage or default new tab screen. The unwanted add-on may enter inconspicuously in software bundles. You may fail when trying to disable this extension manually since it is very stubborn. The most efficient way to delete the browser hijacker is to use advanced security software.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathwww.exlee[1].xmlRegexp file mask%WINDIR%\System32\Tasks\exlee[RANDOM CHARACTERS]%WINDIR%\Tasks\exlee[RANDOM CHARACTERS].jobHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\exlee.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.exlee.com

Additional Information

The following directories were created:
%APPDATA%\exlee%PROGRAMFILES%\exlee%PROGRAMFILES(x86)%\exlee
The following URL's were detected:
exlee.comwww.exlee.com
Loading...