iu14D2N.tmp What is that?

Yeah um hi. My comodo firewall just reported 3 attempts that iu14D2N.tmp was trying to get through, and i accidently clicked on Allow on the third time. I am now so scared. Could somebody please tell me, what the heck is this program? .__.‘’

Probably not good. tmp’s are supposed to be temporary files, not executables.

Is the file still present on your machine? If so, then I’ll suggest submitting it to http://www.virustotal.com/ and to http://www.cwsandbox.org/ to see what each of these on-line analyzers says about the file.

Umm yeah. Good question. It hasn’t popped up since my last message. Can’t find it from where i am looking. Any ideas where it should be? And i checked it in Uniblues ProcessLibrary. [url=http://]http://www.processlibrary.com/directory/files/iu14D2N.tmp/[/url] Says it belongs to Inno Setup. And what wikipedia has to say to this: Inno Setup - Wikipedia

So nothing too serious, i think? But any help regarding this thing, and, if it is a virus, info about how to remove it is most appreciated. :slight_smile:

I found a script on google that was refering to Skype the voip software with this file…
Did you install this lately ? Maybe it’s a good time to do some antivirus/spyware scan…

It is not normal for .tmp files to connect to the internet, these are most of the times packed installers within a setup file but i’ve also seen this in malware analysis the “downloader” get’s started and executes .tmp files to install nasty stuff… don’t mean to scare you but make sure to run at least 2 virus and spyware scanners to be sure.

Also check you firewall policy to see if it’s there and change the alllow to block.
Can’t hurt to check the Defence+ policy also.

No, this computer does not have Skype installed to it. Defence+ has some temp files on the pending list, but no iu14D2N.tmp. And stupid question. How and from where can i check my firewalls allowed/blocked list and etc? :s

Edit: Well now i found something. In “networks security policy->Application rules->C:\Documents and settings\Bracca\Local settings[b]temp[/b][b]iu14D2N.tmp[/b]
—>Allow IP Out From IP Any To IP Any Where Protocol Is Any”

Seems like that it is in the temp folder. But why did it try to connect to internet then?

Editedit: Well i blocked it untill i get more information about this. And if something radical happens when im trying to install a new piece of software in the future, we could say that it has something to do with that thing?

It appears also on http://www.iolo.com/ for the System Mechanic.
Does that ring a bell ? or did it “drive-by-download” while you where surfing ?

Can you check to see if there is something left of this in c:\windows\prefetch\iu14d2n… ?

Have you run Virusscanners and Spyware scanners yet ? because there are some articles on the net being referenced to virus/malware for this file.

Just ran Evido, AVG, F-secure and ad-avare and norton free scan. Every single one of them with full-system scan. Found nothing. And i have never, ever heard of system mechanic O_o Anyways, iu14D2N.tmp connected to internet for the first time while i was about to start playing Valve’s Portal-game few days ago. Just few minutes before i contacted you guys in here. Only Comodo firewall pro said that this .tmp file tried to connect to internet. F-secure and other programs said nothing during that time.

Does this file stil exist on your machine: C:\Documents and settings\Bracca\Local settings\temp\iu14D2N.tmp

If it is still there, upload it to http://www.virustotal.com/ and to http://www.cwsandbox.org/ to see what each of these on-line analyzers says about the file. Post the results here.

Ehhehheeh, how to explain this now. I cannot find the folder local settings. Window’s own “search” funktion finds some files from that folder. But when i MANUALLY try to navigate my self to C:\Documents and settings\Bracca\Local settings\temp\iu14D2N.tmp, There is no folder “local settings”. What is this now?

The “Local Settings” folder is a hidden folder. That’s normal Windows setup.

There are two ways to proceed:

First, open Windows Explorer, then click Tools → Folder Options, the View tab, and topwards the top of the long list of options is Hiden Files and Folders. Make the setting for Show Hidden Files and Folders. Then Apply to All Folders, and OK back out. Then go back and navigate to the folder. You should see it now.

Second method, using a command prompt, with these commands:

cd "\Documents and settings\Bracca\Local settings\temp\"
copy iu14D2N.tmp "\Documents and settings\Bracca\Desktop\"

This will put a copy of that file onto your Desktop. Submit that file to the on-line scanners.

Note all the quotes on the pathnames. Command lines don’t like pathnames with spaces. You have to quote everything that has spaces.

Well i got the folder to show up, but. The iu14D2N.tmp is nowhere in there. Hmmm.

do you have any “undelete” sofware installed on your system like

PC Inspector file recovery

maybe you can still undelete it and upload to the mentioned sites ?

Have you checked the Windows Recycle bin?

Are there any other files in the “Local Settings/Temp/” directory? It likely would be worthwhile to submit some of those also, if the dates on the files are recent.

Just as a paranoia check, check c:\windows\system32 for newly added files (sort by file date, either modification or creation). If there are new files, as in the last week or so, then submit those files also.

What anti-malware applications do you have installed? There may be some scan settings or tools that might be of use that aren’t in the default setup.

[i]hey, i came across the same problem while trying to install and uninstall some shareware. i’ve managed to find the hidden temp file _iu14D2N.tmp, and put it through www.virustotal.com.

These are the results i get:[/i]
( 0 exports )

i wonder if that helps. it seems that virustotal, and all the other virus scanners don’t see it as any type of threat! >_____<

Hey comodo, I have also found this file while running a scan with comodo but had to run it with the rootkit scan option enabled to locate it! I definitely think something is up with this file.

Since it has been found on my computer I haven’t been able to complete a full Comodo scan! it get’s right into the scan then just stops, when I stop the scan it keeps telling me insufficient resources.

Please upload this file to Virus Total, Comodo Instant Malware Analysis and Comodo Valkyrie and provide us with the links to their reports.