Should I block it?

No, this file is 100% safe to run.


Child process
Related files

PE structurePE file structure

Show functions
Import table
RegCloseKey, OpenThreadToken, RegQueryValueExA, RegOpenKeyExA, RegEnumKeyExA, RegSetValueExA, RegCreateKeyExA, RegDeleteKeyA, RegOpenKeyA, RegCreateKeyA, RegQueryValueA, FreeSid, EqualSid, AllocateAndInitializeSid, GetTokenInformation, OpenProcessToken
CreateCompatibleBitmap, CreateDCA, GetStockObject, GetTextExtentPoint32A, CreatePatternBrush, DeleteMetaFile, SetMetaFileBitsEx, SetStretchBltMode, SelectClipRgn, SetPixel, PatBlt, PlayMetaFile, StretchBlt, CreateBitmap, SetViewportExtEx, SetViewportOrgEx, SetWindowExtEx, SetWindowOrgEx, CreateDIBitmap, SaveDC, SetBkMode, SetTextColor, TextOutA, RestoreDC, GetTextExtentPointA, CreateFontIndirectA, SetBkColor, CreateRectRgn, DeleteObject, CreateSolidBrush, GetDIBColorTable, GetSystemPaletteEntries, CreatePalette, CreateHalftonePalette, GetDeviceCaps, GetObjectA, CreateCompatibleDC, UnrealizeObject, SelectPalette, RealizePalette, SelectObject, BitBlt, DeleteDC, SetMapMode
DeleteCriticalSection, GetShortPathNameA, SetEvent, HeapDestroy, GetDriveTypeA, GetExitCodeProcess, CopyFileA, lstrcpynA, GetFileAttributesA, FindClose, FindFirstFileA, CreateDirectoryA, GetCurrentThreadId, LoadLibraryA, SetFilePointer, LoadLibraryExA, GetTickCount, GetWindowsDirectoryA, FormatMessageA, LocalFree, SetFileAttributesA, UnmapViewOfFile, MapViewOfFile, CreateFileMappingA, GetFileSize, SizeofResource, GetTempPathA, GlobalSize, FreeResource, GetLocalTime, GetCurrentProcessId, SearchPathA, FindNextFileA, GetTempFileNameA, TerminateProcess, IsBadReadPtr, VirtualQuery, VirtualProtect, ResetEvent, QueryPerformanceCounter, SystemTimeToFileTime, lstrcmpA, GetCurrentThread, MoveFileExA, GetDiskFreeSpaceA, GetSystemDirectoryA, GetSystemInfo, GetPrivateProfileStringA, GetPrivateProfileIntA, MultiByteToWideChar, lstrcpyA, lstrcmpiA, lstrlenA, GetSystemDefaultLangID, lstrcatA, SetLastError, GetLastError, WideCharToMultiByte, CompareStringA, CompareStringW, GetVersionExA, GetProcAddress, MulDiv, GetPrivateProfileSectionNamesA, FlushFileBuffers, SetStdHandle, IsBadCodePtr, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, SetUnhandledExceptionFilter, HeapSize, IsBadWritePtr, VirtualAlloc, VirtualFree, HeapCreate, GetEnvironmentVariableA, TlsGetValue, TlsAlloc, TlsSetValue, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, GetOEMCP, GetACP, GetCPInfo, GetCommandLineA, GetStartupInfoA, RaiseException, HeapReAlloc, HeapAlloc, HeapFree, RtlUnwind, InterlockedExchange, InitializeCriticalSection, GetModuleHandleA, GetModuleFileNameA, Sleep, CloseHandle, ReleaseMutex, CreateMutexA, ReadFile, WriteFile, CreateEventA, QueryPerformanceFrequency, InterlockedDecrement, InterlockedIncrement, CreateFileA, CreateThread, EnterCriticalSection, LeaveCriticalSection, FreeLibrary, SetErrorMode, FindResourceExA, FindResourceA, LoadResource, LockResource, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, GetVersion, WaitForSingleObject, ExitProcess, GetCurrentProcess, DuplicateHandle, GetThreadContext, VirtualProtectEx, WriteProcessMemory, FlushInstructionCache, SetThreadContext, ResumeThread, DeleteFileA, RemoveDirectoryA, AddAtomA, WritePrivateProfileStringA, GetAtomNameA, lstrlenW, CreateProcessA
LZCopy, LZOpenFileA, LZClose
StringFromGUID2, CoTaskMemAlloc, CoMarshalInterThreadInterfaceInStream, CoReleaseMarshalData, CoInitialize, CoGetInterfaceAndReleaseStream, CoCreateInstance, CoCreateGuid, StringFromCLSID, CoTaskMemFree, GetRunningObjectTable, CoRegisterClassObject, CoRevokeClassObject, CoUninitialize
RpcStringFreeA, UuidCreate, UuidToStringA
ShellExecuteExA, SHGetPathFromIDListA, SHGetSpecialFolderLocation, SHBrowseForFolderA, SHGetMalloc
MoveWindow, EndDialog, LoadIconA, GetDlgItem, SendMessageA, SetDlgItemTextA, SetWindowLongA, DialogBoxIndirectParamA, CharUpperA, WaitForInputIdle, wsprintfA, GetWindowRect, GetWindowLongA, ShowWindow, GetClassInfoExA, SetWindowTextA, LoadCursorA, CreateWindowExA, GetClassNameA, GetDialogBaseUnits, RegisterClassExA, PostMessageA, CharLowerBuffA, GetDlgItemTextA, SetFocus, IsDlgButtonChecked, CheckDlgButton, BeginPaint, EndPaint, FillRect, ScreenToClient, GetParent, GetWindow, SystemParametersInfoA, MapWindowPoints, SetWindowPos, GetWindowTextLengthA, GetWindowTextA, GetWindowPlacement, SendDlgItemMessageA, DefWindowProcA, GetPropA, EnableMenuItem, SetPropA, RemovePropA, IsWindow, GetSysColor, IsDialogMessageA, TranslateMessage, LoadImageA, CreateDialogParamA, GetDC, ReleaseDC, MessageBoxA, GetMessageA, DispatchMessageA, MsgWaitForMultipleObjects, PeekMessageA, CharNextA, PostThreadMessageA, LoadStringA, SetActiveWindow, DestroyWindow, CreateDialogIndirectParamA, SetForegroundWindow, GetClientRect, EnableWindow, IsWindowEnabled, GetDesktopWindow, SetWindowRgn, GetWindowDC, UpdateWindow, InvalidateRect, DrawIcon, MapDialogRect, DrawFocusRect, InflateRect, DrawTextA, CopyRect, EnumChildWindows, IntersectRect, CallWindowProcA
GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA


InstallShield by Macrovision Corporation (Signed)

Remove _isa71a.exe
Version:   12.0.49985
MD5:   ba30773120175ee6a40c261f9de7fcd3
SHA1:   bcb4f448bfabb274aefa41f7b34e822616084ab3
SHA256:   ce548a7aa1cca4a6c2eb1be077058a511c8a1e7cfac82ba103e4375d30ce22ca


_isa71a.exe executes as a process with the local user's privileges. It is installed with a couple of know programs including Supreme Commander published by Gas Powered Games, Sid Meier's Civilization 4 - Beyond the Sword from Firaxis Games and Sid Meier's Civilization 4 - Beyond the Sword by Firaxis Games. The file is digitally signed by Macrovision Corporation which was issued by the Thawte Consulting (Pty) Ltd. certificate authority (CA). This particular version is usually found on Windows 7 Professional (6.1.7601.65536).


File name:_isa71a.exe
Publisher:Macrovision Corporation
Product name:InstallShield
Typical file path:C:\users\user\appdata\local\temp\_isa71a.exe
Original name:Setup.exe
File version:12.0.49985
Product version:12.0
Size:445.72 KB (456,416 bytes)
Issued to:Macrovision Corporation
Authority (CA):Thawte Consulting (Pty) Ltd.
Digital DNA
PE subsystem:Windows GUI
File packed:No
More details


The following programs will install this file
5% remove
2K Games
4% remove
BioShock is a first-person shooter video game by Irrational Games with role-playing game customization and stealth elements, and is similar to System Shock 2. The player takes the role of Jack, who aims to fight his way through Rapture, using weapons and plasmids, in order to complete objectives. BioShock is set during 1960, in the fictional underwater city of Rapture; the player learns of its history through in-game audio recordings sc...
Firaxis Games
1% remove
Civilization IV: Beyond the Sword is the second official expansion pack of the turn-based strategy video game Civilization IV.
Firaxis Games
5% remove
Multiple multiplayer options including the ability to compete with friends via the Internet, play by E-mail modes or compete locally via the Hotseat and LAN modes. Includes four classic games: Sid Meier's Civilization IV, Civilization IV: Warlords expansion pack, Civilization IV: Beyond the Sword expansion pack and Sid Meier's Civilization IV Colonization. Innovative features in all four games including: Great People, Holy Cities, missi...
Gas Powered Games
3% remove
Supreme Commander is a real-time strategy computer game focused on using a giant bipedal mech called an Armored Command Unit.
Gas Powered Games
6% remove
The last days of man are at hand.. Two years after the Infinite War the once great warring nations now lie in ruins, and humanity’s hope for a brighter future is nothing but a bitter memory. A new, seemingly unstoppable enemy, supported by the zealots of The Order, now seeks to eradicate mankind: UEF, Aeon Loyalist, and Cybran alike. With their backs against the wall and staring into the abyss, the tattered remnants of Humanity’s forces...

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Total CPU:0.02314736%
Kernel CPU:0.01274744%
User CPU:0.01039992%
Kernel CPU time:370,346,374 ms/min
Context switches:1,302/sec
Private memory:15.23 MB
21.59 MB
Private (maximum):23.71 MB
Private (minimum):19.99 MB
Non-paged memory:15.23 MB
21.59 MB
Virtual memory:132.69 MB
140.96 MB
Virtual memory (peak):147.7 MB
169.69 MB
Working set:23.71 MB
18.61 MB
Working set (peak):26.4 MB
37.95 MB
Resource allocations
GUI GDI count:61
GUI GDI peak:79
GUI USER count:40
GUI USER peak:59

BehaviorsProcess properties

Integrety level:High
Command line:C:\users\user\appdata\local\temp\_isa71a.exe -clone_of"C:\" -your_launchersetup.exe -tempdisk1folder"C:\users\user\appdata\local\temp\{89ac6b7a-04df-4ff2-a8b0-b90489324ab9}\"

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Professional 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE