1.

Solve : IE7 will not display Windows Update?

Answer»

While checking Online Armors list of "allowed" Programs, I came across "Speedy PC". It was not something I recognized as having installed on my laptop so checked for more info from Online Armor. This is the information they showed:

About Au_.exe
Size 375,487 byte(s)
Status  Unknown 
Vendor SpeedyPC Software  (Unknown)
Product SpeedyPC 
Sighting 14-Apr-10  26-Apr-10
Actions Allowed by 33% user(s)


Au_.exe Description:
SpeedyPC Installer


Also known as:
uninst.exe


What does Au_.exe do?
Cache
Installer - Installs software on your computer.
Process - a process that runs on your computer
ProcessStart
ProcessSuspend
RemoteDataModification
StartWithParams


Au_.exe Version info
Au_.exe describes itself as follows. Note that this information can easy be faked

Product Name SpeedyPC
Product Version 3.0.1.0
File Version 3.0.1.0
Copyright Copyright © 2010 SpeedyPC Software
Description SpeedyPC Installer


OA Version(s):
4.0.0.35
4.0.0.44


Locations:
Au_.exe is found in location(s)

%ProfilesDirectory%\%UserName%\AppData\Local\Temp\~nsu.tmp\
%ProgramFiles%\SpeedyPC\

 


Countries
Au_.exe has been sighted in the following countries

Italy 14-Apr-10  14-Apr-10 
United Kingdom 20-Apr-10  20-Apr-10 
United States 20-Apr-10  26-Apr-10 

I find it ironic that the first sightings correspond to the first date AVG found a virus in my computer.
Tracked it down and it is located at "C\Documents and Settings\E. Jean Ruport\Local Settings\Temp\~nsu.tmp\Bu .exe"

The first TIME I checked with Online Armor, I am sure the exe was "Au .exe."

  Also, The infection on April 24 that AVG found was "TROJAN HorseDropper.Generic2.CKX" in "C:\Documents and settings\E. Jean Ruport\Desktop\a  .exe"

I find this SUSPICIOUS!

It is not listed in my PROGRAM Files....

I checked it with AVG and MBAM but it showed clean in both.

As I am not able to get to Anti Virus sites on Internet Explorer could you please investigate this for me.
As for me I am going to Isolate this program as much as possible until I hear from you.

Thank you so Much for all your help and time.

Tried to get AVG updated and updates failed so I Just Checked Online Armor again and it now has "Cu .exe" so this file is MULTIPLYING. The program is called Speedy PC. I  have blocked them through Online Armor. Don't know what else to do.



Discussion

No Comment Found