A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #16708  by thisisu
 Tue Nov 20, 2012 1:27 am
Hi, I'm looking for "eType Manager" which I suspect is just like "Browser Manager".

Creates...

Process:
C:\ProgramData\eType Manager\2.2.639.201\{16cdff19-861d-48e3-a751-d99a27784753}\etypemngr.exe

Service:
R2 eType Manager;eType Manager;c:\programdata\etype manager\2.2.639.201\{16cdff19-861d-48e3-a751-d99a27784753}\etypemngr.exe [2012-9-18 1698848]

AppInit_DLLs:
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\ETYPEM~1\22639~1.201\{16CDF~1\etypemngr.dll

Folder:
%allusersprofile%\eType Manager

Found it in this thread

This type of program is responsible for browser redirects. Usually accompanied by adding Babylon CLSIDs to Searchscopes.

Thank you :)