A Problem or Not?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Denise_M, Jun 15, 2007.

  1. Denise_M

    Denise_M MajorGeek

    I went into Safe Mode and ran winpfind3u according to the directions. I have a report but it's too big to attach. I just formatted my pc so that all the programs/files/folders were created within the past 30 day. If you want to see it, I'll split it in 2 and attach them.

    I also ran SUPERAntiSpyware Free Edition and Ad-Aware and they didn't find anything.

    When I came out of Safe Mode and rebooted, I ran SpyBot S&D again and Poka-Poka wasn't reported as being there.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for remembering to do this.

    That really looks like a false detection to me. What else do you see in the below folder?

    C:\Documents and Settings\Administrator\Local Settings\Temp\~setuptmp0

    Take a look at some of the files. And see if you can determine what program this is from. This is obviously and installer folder for something you use. You can even load binary type files (like the irsetup.exe file) into WordPad to search thru them looking for text that may give you an indication of what it is for.

    Do you use any P2P type programs or any Torrent type downloaders?
     
  3. Denise_M

    Denise_M MajorGeek

    C:\Documents and Settings\Administrator\Local Settings\Temp\~setuptmp0 doesn't have poka-poka any longer since I rebooted.

    I've attached 2 screenshots of the items in the folder. The first one is a screenshot of the top of the folder and the second one is a screenshot for the bottom of the folder. In between, there are only a multitude of the hpz type files.

    I don't use Torrent or P2P but I do use another file sharing program, but very infrequently, maybe once or twice a month.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ~setuptmp0 folder does not appear in those snapshots of the Temp folder. Who/what deleted it?

    I have seen some inferences that that irsetup.exe and also an irsetup.dat file may be related to some P2P software. You may want to observe whether these Poka-Poka notices from Spybot reappear after you have used the file sharing program. Also when you get it again, capture what is in the ~setuptmp0 folder to show me. Also you may want to ZIP a few of the files including irsetup.exe (if that is what reappears) and attach the ZIP file here.
     
  5. Denise_M

    Denise_M MajorGeek

    In the quote that I mentioned earlier, it said

    I'll give you more info if it appears again.

    BTW, I just purchased the full running version of SuperAntiSpyware Pro. It's going to be mailed to me and I'm hoping to receive it by the end of the week. It's on sale right now.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but that assumed it was for the Indigo Rose software. So if this really occurred it would then seem more likely that it is related to Indigo Rose and that it is not malware.

    Let me know how you like it. Especially since you are using it with x64.
     
  7. Denise_M

    Denise_M MajorGeek

    I don't have a program named Indigo Rose. I just installed the Indeo codec, but I'm betting it's not the same.

    Yesterday, I spent time downloading a few codecs that I need to edit and view my video files. It could have been attached to one of them. The only other downloads were Microsoft updates, Debugging Tools for Windows 64-bit (which won't work because I can't find the folder where my pc stores its dump file) and updates to Spybot, and Ad-Aware. I looked through my email and nobody sent me an email that had an attachment. So it must've been attached to one of the codecs. I won't be downloading more codecs for a few months because I got the most recent updates, but the next time I see poka-poka, I'll get the info for you:

     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to have it. It is used by software writers to create installers for their software. Thus some other program that you have installed could use it.

    See this for more info: http://www.indigorose.com/setup-factory-for-windows-installer/
     
  9. Denise_M

    Denise_M MajorGeek

    I did a search for IRSETUP.EXE (in hidden and system folders also). Two results shows up. They're both in my Prefetch folder. IRSETUP.EXE-187B22FA.pf and IRSETUP.EXE-32C09F85.pf. I had Avast scan them and it didn't report a problem.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are not the same as the original irsetup.exe file. They are just prefetch files which are not the real full EXE file. Try renaming one of them to irsetup.exe and see what happens. Even try copying another benign file like c:\windows\explorer.exe to C:\irsetup.exe and also see if that is detected. It could be that Spybot is just looking at the name of the file.
     
  11. Denise_M

    Denise_M MajorGeek

    Hi Chaslang,

    PokaPoka turned up under a scan by SpyBot this morning. I've attached a screenshot of the folder/path and the file that's in it.

    I then double clicked on the setup file and received the message that's in the second attachment.

    The third screenshot shows the contents of the folder that ~setupmp0 is in.

    When I woke up this morning, I found that my computer had crashed during the night.
    .
     

    Attached Files:

    Last edited: Aug 15, 2007
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a false positive. It is the Indigo Rose setup program which is an installer for some software you are probably using.
     
    Last edited: Aug 15, 2007
  13. Denise_M

    Denise_M MajorGeek

    Ok, thanks chaslang . . . when it shows up again, and I know it will, I'll just have SpyBot delete it. I'm happy to know that it's not a virus.
    .
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds