Weird Registry Entry... E.exe Found On My Pc As Well!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by superstar, Aug 5, 2009.

Thread Status:
Not open for further replies.
  1. superstar

    superstar Major-Superstar

    I have used this pc for four years. In the amount of time that I've had this pc I've had some small threats but removed them all. So I'm well aware of my pc's normal health and regular operating status. Anyways I let my girlfriend use my pc last night. While she was using it she claimed that she started typing in the address bar and words started typing backwards. So the word "Pizza" came out as "aizzP". I thought she might have pressed something wrong on the keyboard and told her to restart Firefox, which fixed the problem. After she used my pc a grey windows prompt message came up stating that adobe acrobat or something related to adobe couldn't run and resulted in an error. I wasn't even running adobe and rarely do [I probably run it three times a month]. Than all of a sudden a small yellow balloon popped up in my systray that said "windows virtual memory is low, increasing page file". I figured there must be some sort of memory leak, so I tried to restart my pc. Before the restart took place, my computer gave me yet another grey windows prompt message that said "error memory 820029010111xxx" with a whole bunch of numbers [I just made those numbers up]. My pc finally restarted... When it did so something happened that has never happened in the for years that I've had this pc.

    My computer notified me that some sort of application named DnsUpdater was trying to gain access to the internet. Which is weird because nothing ever tries to run when my pc boots up other than my sound manager, and antivirus. I quickly canceled that internet network connection request, and check my startup programs in an application I use that can disable and enable startup applications [System Mechanic 4]. To my surprise I now saw an extra startup application I had never seen before that appeared like so:

    Progam Name: DnsUpdater
    Command Line: C:\Program Files\Common Files\e.exe
    Startup Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

    I quickly disabled that startup item, and ran an intensive scan with my ESET Antivirus. As well as a scan with Spybot Search & Destroy, Malwarebytes Antimalware, and Trend Micro's Online Housecall scanner at www.trendmicro.com. They all found absolutely nothing wrong with my pc, and claimed my pc is 100% clean.

    I doubt this because I went to my C:\Program Files\Common Files folder and seen a file named "e.exe" that has a weird icon that looks like a blue circle with a white checkmark in it. It definitely looks like someone made the icon themselves, not some sort of a polished application. It's small in size...

    Anyways I don't know how this got on my pc. I don't know what a DnsUpdater is, and how this has tried to run on boot up. I don't know if it should be there, and what I need to do. Please help me find out what to do with this file, and registry entry. I could just delete it myself but don't know if maybe it is important or something... All my girlfriend did was surf the net, and go on business websites to learn about business. She did go on quite a lot of unknown business sites which I even saw looked amateur. But she claims no pop up window came up asking her to download something or whatever.


    Anyways any help would be greatful. Thanks!
     
  2. superstar

    superstar Major-Superstar

    Please delete this thread!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    sorry

    I have to run all those scans in the read me sorry

    I'll be back with those another time!
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I see you have cross posted at another malware removal forum. You need to decide where you want to work out these problems and if you decide to work with us then you need to go let the other forum know, so this way no resources and volunteers time is wasted by cross posting on multiple forums. :)

    Thanks
    Kes
     
  4. superstar

    superstar Major-Superstar

    Honestly if you checked I stopped asking for help on the other website, and chose to go with you guys. They even closed the thread since I told them I was getting help with you guys instead.

    I DID ALL THE SCANS here at majorgeeks and have been waiting almost 4 days for a response from anyone! This is the thread where I finally posted my problem here on majorgeeks, it has all my logs:

    http://forums.majorgeeks.com/showthread.php?t=195710

    That's the real thread I started with my entire explanation about my problem and every single log you guys asked for. I've been waiting quite long... I've had my pc on for about 4 days checking every hour for a reply, and than disconnecting the net and checking the next hour. I've seen many others get help before me in the past few days [no offense]. I just hope no one has forgotten about my thread.

    Once again go to IF YOU CAN HELP ME PLEASE! I'll be checking every hour...:

    http://forums.majorgeeks.com/showthread.php?t=195710


    Sorry about the confusion...
     
    Last edited: Aug 7, 2009
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in a reply to your PM, IT WAS NOT even 2 days since you posted before you received a reply. Its was only 43hrs and 16 min to be exact. Quite a big difference between 2 and 4 days. Please refrain from making statements like this in the future and just wait your turn in the queue.

    This duplicate thread is closed.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds