Jump to content

Malwarebytes

Is this file legit?


7 replies to this topic

#1
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
I am almost afraid to reboot my computer... Noticed this file in the "Startup" section of CCleaner... It's set to RunOnce and I've never heard of or seen it before.

c:\windows\is-icdra.exe /REG is the startup value with the name being InnoSetupRegFile.0000000001.

No information is easily found through google; I uploaded it to Jotti and it came back as clean. Any clues?

swagger
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#2
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,161 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
Everything is fine! The file is legitimate.
http://www.bleepingcomputer.com/startups/I...0001-16618.html
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#3
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
Is the filename randomly generated then? Because that entry at BC has a different file name...
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#4
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,161 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
The file name doesnt matter, the important thing in this case is the value name - InnoSetupRegFile.0000000001. Don't worry!
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#5
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
See if you can locate the file in your Windows directory InnoSetupRegFile.0000000001
You should be able to open it with Notepad and look and see what it's trying to do.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#6
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina

View PostManiac, on Apr 3 2009, 06:46 PM, said:

The file name doesnt matter, the important thing in this case is the value name - InnoSetupRegFile.0000000001. Don't worry!

I understand... I'm not panic worried as my computer has been up for over a week and I am sure I have installed 2-3 programs that could be related to this entry. Just would like more information on this.

View PostAdvancedSetup, on Apr 3 2009, 06:47 PM, said:

See if you can locate the file in your Windows directory InnoSetupRegFile.0000000001
You should be able to open it with Notepad and look and see what it's trying to do.

No file by that name in the Windows directory.. There is a is-ICDRA.lst and is-ICDRA.msg however.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#7
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Well it is unlikely dangerous, but since the file does not appear to be there (do you have file set to show hidden files? )

Reconfigure Windows XP to show hidden files:
To enable the viewing of Hidden files follow these steps:

* Close all programs so that you are at your desktop.
* Double-click on the My Computer icon.
* Select the Tools menu and click Folder Options.
* After the new window appears select the View tab.
* Put a checkmark in the checkbox labeled Display the contents of system folders.
* Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
* Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
* Remove the checkmark from the checkbox labeled Hide protected operating system files.
* Press the Apply button and then the OK button and exit My Computer.
* Now your computer is configured to show all hidden files.


If you have not installed anything recently and have rebooted recently then the item should have already been removed on it's own. If it has not then you can remove it on your own. It is set in RunOnce just as the key name implies ONCE, not every time you boot the computer.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#8
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
Yeah, hidden files/folders, protected system files was shown already... I believe it could be related to CDBurnerXP. I think that was the only program that I have installed in the last week or so since my last shutdown/reboot. I understand it's only going to run once but I wanted to make sure that it should run at all. Cause I have never heard of it or seen it before prior to today and that was just by coincidence (checking CCleaner).
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us