slooprv
asked on
After downloading and installing CCleaner my anti-virus program detected malware on my computer.
Last night, I took the advice of an expert on EE and downloaded and installed CCleaner. I was trying to clear space on my C.drive(see previous question re: defragging my C drive)After running it and deleteing alot of filess (mostly cookies, temp files, log files, etc.) I left my computer for a few hours(it was left running)and when I came back one of my anti-malware programs (PREVX 2.0) had detected malware on my system. My other program E Trust EZ Antivirus did not report anything. Prior to this, I had run anumber of full system scans for malware by both programs and both had pronounced my system clean and free from malware. I had downloaded the CCleaner application from a site call somthing like Hippo(I don't have the full site information since all my history files were "cleaned" after I had run the CCleaner. The malware detected is called "ISMPACK8.EXE"PREVX 2.0specfied this action it took :
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235 F52-3DCC-4 76D-AAA2-C 774280ACA3 5}\RP383\A 005503
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235 F52-3DCC-4 76D-AAA2-
C774280ACA35}\RP383\A00550 4
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235 F52-3DCC-4 76D-AAA2-
C774280ACA35}\RP383\A00550 4"
Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235 F52-3DCC-4 76D-AAA2-
C774280ACA35}\RP383\A00550 9
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235 F52-3DCC-4 76D-AAA2-
C774280ACA35}\RP383\A00550 9
I am wondering How and Where this malware got on to my system? Is this malware serious? What should I do about it? and Can there be more malware lurking about my system even after many full system scans with several anti-malware programs., Thanks ,Rick
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235
C774280ACA35}\RP383\A00550
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235
C774280ACA35}\RP383\A00550
Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235
C774280ACA35}\RP383\A00550
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235
C774280ACA35}\RP383\A00550
I am wondering How and Where this malware got on to my system? Is this malware serious? What should I do about it? and Can there be more malware lurking about my system even after many full system scans with several anti-malware programs., Thanks ,Rick
Start->Programs->prevx (anything like that?)
should read your posting more carefully, ok...
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks for these suggestions, First , Iwill try to locate the folder and open it and upload it to virusscan.jotti.org. Seondly, I did not know I could turn off system restore, and am concerned that if I do turn it off, that ifin the futre I have a problem and need to restore my system back to an earlier date I won't be able to. In the past, I have had to do this quite a few times. Obviously I really don't understand the system restore feature very well. Another EE expert suggested I turn it of also to create more room on my C drive. and that it is a good hiding space for malware to lurk . I still need to know what to do with these malware files (if that is what they are) residing in my PREVX 2.0 jail. I have the choices to "cleanup now" to remove all the files, "Cleaanup Logs" to restore changes or "set to probation" what ever that is !!, thank rick
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
TOLOMIR, I located my system volume information folder , but it is empty. I assume this is because all the files(6 of them) are now in my PREVX jail, waiting for me to do somthing with them. Unfortunately, rigth clicking on these files in my prevx jail does not give me the option of copying them. So ,unless I restore them back to the folder, I amunable to upload them to the viruscan website for evaluation. I still need to know what to do with them. Should I just delete them from the jail, or restoe them back to the folder, or put them on "Probation" what ever that is ? Rick
ASKER
TOLOMIR,
I set all the files to probation, and PREVX informs that they have been set to probation and allowed to run. I went back to the C:Documents and Settings/System Volume Information folder but it is still empty. I don't seem to be able to find where these files are now, I thought they should be in that folder. I still have no way of copying them or uploading them to virusscan.org. Now I am worried that they are running on my system. Not sure of what to do now. How does one upload these files?
I set all the files to probation, and PREVX informs that they have been set to probation and allowed to run. I went back to the C:Documents and Settings/System Volume Information folder but it is still empty. I don't seem to be able to find where these files are now, I thought they should be in that folder. I still have no way of copying them or uploading them to virusscan.org. Now I am worried that they are running on my system. Not sure of what to do now. How does one upload these files?
"I located my system volume information folder , but it is empty."
Was this just by hovering over the folder? That would be normal if your UserID is denied access to it.....Make sure you can double click the folder, and go to the _restore{LONG STRING OF NUMBERS HERE} folder as thats where the large restore points are kept....
Was this just by hovering over the folder? That would be normal if your UserID is denied access to it.....Make sure you can double click the folder, and go to the _restore{LONG STRING OF NUMBERS HERE} folder as thats where the large restore points are kept....
ASKER
John, I found the folder, did a search for it, opened it in windows explorer, bbut it is empty, I double clickd it, right clicked and clicked "open" etc. . So where would these files go after selecting "probation" on PREVX? It says there are now running on my system(according to PREVX) so where are they? I really feel frustarated and am ready just to clean them from PREVX and forget about sending them to virus scan .org. Any other ideas?, Thanks,Rick
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
ok, I will try that. I will be back later this evening to let you know what happens, thanks, Rick
ASKER
well I innaly got fed up with trying to find out what happened to the virus file after I clicked "probation" on PREVX 2.0. I even ran two full system scans for it and it no longer was picked up, so I did go ahead and disable the restore feature, restarted and did another full system scan with PREVX and with EZ-Antivirus and still it no longer was picked up. I just wonder what ever happened to i? I also finnally had more than enough room now to defrag my c drive (6.74G now!) My computer is starting to run better Ater doing this and also running CCleaner. I will follow up with other suggestions now such as submitting a hijack this scan for analysis., , hopefully I will get this 5 year old vaio back up to speed. Thanks everyone for great help, Rick
http://www.filehippo.com/download_ccleaner/
PREVX 2.0 instead is a malware detector:
www.prevx.com
So could you check if you got a green / yellow / red ball in your system tray (this is the icon of prevx)