|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Saved by grace
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
|
Trojan
After I updated the pro version of Malwarebytes and rebooted, Winpatrol detects the following: C:\WINDOWS\is-H4DR1.exe /REG /REGSVRMODE
when I attempt to look it up with the pro version (Winpatrol) it searches for israndom.exe which appears to be a trojan. It is a run once program and so far I have not allowed it to start. I did find one webpage that mentioned this in conjunction with Malwarebytes. I wonder if it is legit or not.
__________________
My custom work system: ASUS P7P55D-E LGA 1156 / Intel Core i5-750 / CORSAIR XMS3 4GB (2 x 2GB) / Windows XP SP3 / SAPPHIRE 100292L Radeon HD 5450 / 2 LITE-ON 24X DVD Writers SATA Model iHAS424-98 / 2 W.D. Caviars Black WD1001FALS 1TB SATA 3.0Gb/s / Antec Sonata III 500 Black with 500W Power Supply / Rosewill RCR-IC002 74-in-1 USB 2.0 3.5" Internal Card Reader w/ USB port |
|
|
|
|
|
#2 | |
|
Ride 'em Cowboy
Staff
Premium Member
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,472
|
Have I ever told you I HATE YOU
![]() I installed the pro version of Malwarebytes yesterday cause I had an infection.... So I searched my hard drive just now for is-H4DR1.exe ... Didn't find anything. I then search the registry for the same thing... And not only did it find it - but it also found several other nasty EXE files I looked for yesterday..... After I regained conscious I realized that the reg search had found the "search assistant" hard drive items that I had already searched for. Quote:
Do you actually have the is-H4DR1.exe somewhere?
__________________
Imagine a world where dogs took bad owners to the pound... |
|
|
|
|
|
|
#3 |
|
Saved by grace
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
|
1. Not yet today, but you sort of are insinuating it now.
![]() It is Winpatrol saying it is a run once program detected and asking permission for me to let it run at startup. So far I have said "no", but winpatrol keeps coming up asking me again and again if it should let it run at startup. I'm at work now and am scanning with MSE. I have logmein enabled, so I will change over to Malwarebytes later when the MSE scan is done. |
|
|
|
|
|
#4 |
|
Ride 'em Cowboy
Staff
Premium Member
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,472
|
I searched Malwarebytes forums for is-H4DR1.exe and didn't get any hits.
You can remove the RunOnce entry from the registry - save it for later if needed. |
|
|
|
|
|
#5 |
|
Saved by grace
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
|
Yeah, I did too. I have submitted the question to them via their website. I post what I find out.
Here is the response that is germane to this: "If you are seeing this during an installation of Malwarebytes Anti-Malware, this is part of our program's installation process. Disable WinPatrol during the installation, or approve the message. This is how InnoSetup updates files in use." Last edited by quartet-man; 07-18-2012 at 10:31 AM. |
|
|
|
|
|
#6 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 41,185
|
So let it run.
This is what happens when you have multiple antimalware apps running. They fight with each other. That response makes total sense to me. |
|
|
|
|
|
#7 |
|
Saved by grace
Join Date: Sep 2002
Location: Indiana
Posts: 1,549
|
I actually am trying something. I did a system restore back and am going to see if it comes up (so far not). I will then update to the new version of Malwarebytes again and try again. The weird thing was that usually I think the Winpatrol will tell which software company the program belongs to. This time it didn't. I also had done a scan with MSE and found a problem on the computer (unrelated)? I am going to rescan now that I went back a couple of days and see if it is still there. If so, I will remove it (not just quarantine it). I can't recall what it was, but might add it later here or a new thread.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|