PDA

View Full Version : _IRAOFF:547109 Anyone heard of this file?


DTX
02-23-2006, 07:19 AM
Hi,

I have created an ftp auto uploader for a client, and he says his firewall alerts him that my EXE is accessing this file _IRAOFF:547109 , to gain access to the Internet, the client informs me, he can not find any information on what this file is or where it comes from. But he tells me this particular file, does the following on his PC....

As soon as he launches Outlook Express it grants itself Access to Internet and Trusted Zones (Full Access) and also grants itself Send Mail permisssions.

He has several well respected up to date anti virus packages, Zone Alarm Pro installed, and has scanned his PC many times with Trojan removers, yet can not find anything at all to do with this file.

He has reported to me, that this EXE that I created with Set Up Factory, is the first time Zone Alarm has kicked in with a warning about it.

Is this anything to do with an Indigo Rose product? _IRAOFF:547109

There is no info on google about it.

Any help appreciated.

Cheers
Drew

Brett
02-23-2006, 08:56 AM
That is not a file, it is merely a command line option that Setup Factory's launcher exe passes to the actual setup engine. This is just a case of the anti-virus software being overly protective, although it is really stange that it would interpret a command line argument in that manner. Either way, there is no real problem or virus there.

DTX
02-23-2006, 09:10 AM
Hi Brett,

Thank you very much for the prompt reply, as your the first person I have met who even knows what it is, could you possibly shed any light on why it would grant itself permissions in Zone Alarm (to Send Email) when Outlook Express runs on first run of the day? This is obviously causing some concern, as it resets everyday, but only once a day , weird!

When he runs Outlook Express he doesn't get the Firewall warning and on any subsequent running of Outlook Express during the day, Just the first time each day, but he does get a fire wall warning when it runs the Set up I created with Set Up Factory.

Could you offer any advice how to remove it?

Many thanks
Drew

Brett
02-23-2006, 09:13 AM
I have no idea whatsoever. I have never heard of this happening and would strongly question the integrity of the user's system. Most likely somethign somewhere is trying to run our setup enigine without the proper stub, etc. Unfortunately without seeing it happen I have no ideas. My guess might be that the user installed some sort of Outlook plugin that used setup factory's setup engine and something went wrong.

DTX
02-23-2006, 09:52 AM
Thanks Brett,

I'll see if I can do some further investigation.

Cheers
Drew