Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 07-18-2012, 06:45 AM   #1
Saved by grace
 
quartet-man's Avatar
 
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
Trojan

After I updated the pro version of Malwarebytes and rebooted, Winpatrol detects the following: C:\WINDOWS\is-H4DR1.exe /REG /REGSVRMODE
when I attempt to look it up with the pro version (Winpatrol) it searches for
israndom.exe which appears to be a trojan. It is a run once program and so far I have not allowed it to start. I did find one webpage that mentioned this in conjunction with Malwarebytes. I wonder if it is legit or not.
__________________
My custom work system:
ASUS P7P55D-E LGA 1156 / Intel Core i5-750 / CORSAIR XMS3 4GB (2 x 2GB) / Windows XP SP3 /
SAPPHIRE 100292L Radeon HD 5450 / 2 LITE-ON 24X DVD Writers SATA Model iHAS424-98 / 2 W.D. Caviars Black WD1001FALS 1TB SATA 3.0Gb/s / Antec Sonata III 500 Black with 500W Power Supply / Rosewill RCR-IC002 74-in-1 USB 2.0 3.5" Internal Card Reader w/ USB port
quartet-man is offline   Reply With Quote
Old 07-18-2012, 07:27 AM   #2
Ride 'em Cowboy
Staff
Premium Member
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,472
Have I ever told you I HATE YOU

I installed the pro version of Malwarebytes yesterday cause I had an infection....

So I searched my hard drive just now for is-H4DR1.exe ... Didn't find anything.

I then search the registry for the same thing... And not only did it find it - but it also found several other nasty EXE files I looked for yesterday..... After I regained conscious I realized that the reg search had found the "search assistant" hard drive items that I had already searched for.

Quote:
Winpatrol detects the following: C:\WINDOWS\is-H4DR1.exe /REG /REGSVRMODE
That too looks like a registry entry due to the /REG command switches.

Do you actually have the is-H4DR1.exe somewhere?
__________________
Imagine a world where dogs took bad owners to the pound...
EzyStvy is offline   Reply With Quote
Old 07-18-2012, 07:34 AM   #3
Saved by grace
 
quartet-man's Avatar
 
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
1. Not yet today, but you sort of are insinuating it now.

It is Winpatrol saying it is a run once program detected and asking permission for me to let it run at startup. So far I have said "no", but winpatrol keeps coming up asking me again and again if it should let it run at startup.

I'm at work now and am scanning with MSE. I have logmein enabled, so I will change over to Malwarebytes later when the MSE scan is done.
quartet-man is offline   Reply With Quote
Old 07-18-2012, 09:29 AM   #4
Ride 'em Cowboy
Staff
Premium Member
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,472
I searched Malwarebytes forums for is-H4DR1.exe and didn't get any hits.

You can remove the RunOnce entry from the registry - save it for later if needed.
EzyStvy is offline   Reply With Quote
Old 07-18-2012, 10:20 AM   #5
Saved by grace
 
quartet-man's Avatar
 
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
Yeah, I did too. I have submitted the question to them via their website. I post what I find out.

Here is the response that is germane to this:

"If you are seeing this during an installation of Malwarebytes Anti-Malware, this is part of our program's installation process. Disable WinPatrol during the installation, or approve the message. This is how InnoSetup updates files in use."

Last edited by quartet-man; 07-18-2012 at 10:31 AM.
quartet-man is offline   Reply With Quote
Old 07-18-2012, 12:20 PM   #6
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,185
So let it run.

This is what happens when you have multiple antimalware apps running. They fight with each other. That response makes total sense to me.
glc is offline   Reply With Quote
Old 07-18-2012, 12:52 PM   #7
Saved by grace
 
quartet-man's Avatar
 
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
I actually am trying something. I did a system restore back and am going to see if it comes up (so far not). I will then update to the new version of Malwarebytes again and try again. The weird thing was that usually I think the Winpatrol will tell which software company the program belongs to. This time it didn't. I also had done a scan with MSE and found a problem on the computer (unrelated)? I am going to rescan now that I went back a couple of days and see if it is still there. If so, I will remove it (not just quarantine it). I can't recall what it was, but might add it later here or a new thread.
quartet-man is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -5. The time now is 02:14 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1