Link to home
Start Free TrialLog in
Avatar of slooprv
slooprv

asked on

After downloading and installing CCleaner my anti-virus program detected malware on my computer.

Last night, I took the advice of an expert on EE and downloaded and installed CCleaner.  I was trying to clear space on my C.drive(see previous question re: defragging my C drive)After running it and deleteing alot of filess (mostly cookies, temp files, log files, etc.) I left my computer for a few hours(it was left running)and when I came back one of my anti-malware programs (PREVX 2.0) had detected malware on my system. My other program E Trust EZ Antivirus did not report anything.  Prior to this, I had run anumber of full system scans for malware by both programs and both had pronounced my system clean and free from malware. I had downloaded the CCleaner application from a site call somthing like Hippo(I don't have the full site information since all my history files were "cleaned" after I had run the CCleaner.  The malware detected is called "ISMPACK8.EXE"PREVX 2.0specfied  this action it took :
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235F52-3DCC-476D-AAA2-C774280ACA35}\RP383\A005503
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235F52-3DCC-476D-AAA2-
C774280ACA35}\RP383\A005504
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235F52-3DCC-476D-AAA2-
C774280ACA35}\RP383\A005504"
Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235F52-3DCC-476D-AAA2-
C774280ACA35}\RP383\A005509
"Blocked C:\SYSTEM VOLUME INFORMATION\_RESTORE{9D235F52-3DCC-476D-AAA2-
C774280ACA35}\RP383\A005509

I am wondering How and Where this malware got on to my system? Is this malware serious? What should I do about it? and Can there be more malware lurking about my system even after many full system scans with several anti-malware programs., Thanks ,Rick
Avatar of Tolomir
Tolomir
Flag of Germany image

ccleaner can be downloaded from this site:

http://www.filehippo.com/download_ccleaner/


PREVX 2.0 instead is a malware detector:

www.prevx.com

So could you check if you got a green / yellow / red ball in your system tray (this is the icon of prevx)

Start->Programs->prevx (anything like that?)
should read your posting more carefully, ok...
SOLUTION
Avatar of Tolomir
Tolomir
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of slooprv
slooprv

ASKER

Thanks for these suggestions, First , Iwill try to locate the folder and open it and upload it to virusscan.jotti.org.  Seondly, I did not know I could turn off system restore, and am concerned that if I do turn it off, that ifin the futre I have a problem and need to restore my system back to an earlier date I won't be able to.  In the past, I have had to do this quite a few times. Obviously I really don't understand the system restore feature very well. Another EE expert suggested I turn it of also  to create more room on my C drive.  and that it is a good hiding space for malware to lurk . I still need to know what to do with these malware files (if that is what they are) residing in my PREVX 2.0 jail.  I have the choices to "cleanup now" to remove all the files, "Cleaanup Logs" to restore changes or "set to probation" what ever that is !!, thank rick
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of slooprv

ASKER

TOLOMIR,  I located my system volume information folder , but it is empty.  I assume this is because all the files(6 of them) are now in my PREVX jail, waiting for me to do somthing with them.  Unfortunately, rigth clicking on these files in my prevx jail does not give me the option of copying them.  So ,unless I restore them back to the folder, I amunable to upload them to the viruscan website for evaluation.  I still need to know what to do with them.  Should I just delete them from the jail, or restoe them back to the folder, or put them on "Probation" what ever that is ? Rick
Avatar of slooprv

ASKER

TOLOMIR,
I set all the files to probation, and PREVX informs that they have been set to probation and allowed to run.  I went back to the C:Documents and Settings/System Volume Information folder but it is still empty.  I don't seem to be able to find where these files are now, I thought they should be in that folder.  I still have no way of copying them or uploading them to virusscan.org.  Now I am worried that they are running on my system. Not sure of what to do now. How does one upload these files?
"I located my system volume information folder , but it is empty."

Was this just by hovering over the folder? That would be normal if your UserID is denied access to it.....Make sure you can double click the folder, and go to the _restore{LONG STRING OF NUMBERS HERE} folder as thats where the large restore points are kept....
Avatar of slooprv

ASKER

John, I found the folder, did a search for it, opened it in windows explorer, bbut it is empty, I double clickd it, right clicked and clicked "open" etc. . So where would these files go after selecting "probation" on PREVX?  It says there are now running on my system(according to PREVX) so where are they?   I really feel frustarated and am ready just to clean them from PREVX and forget about sending them to virus scan .org. Any other ideas?, Thanks,Rick
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of slooprv

ASKER

ok, I will try that. I will be back later this evening to let you know what happens, thanks, Rick
Avatar of slooprv

ASKER

well I innaly got fed up with trying to find out what happened to the virus file after I clicked "probation" on PREVX 2.0.  I even ran two full system scans for it and it no longer was picked up, so I did go ahead and disable the restore feature, restarted and did another full system scan with PREVX and with EZ-Antivirus and still it no longer was picked up. I just wonder what ever happened to i? I also finnally had more than enough room now to defrag my c drive (6.74G now!) My computer is starting to run better Ater doing this and also running CCleaner.  I will follow up with other suggestions now  such as submitting a hijack this scan for analysis., , hopefully I will get this 5 year old vaio back up to speed. Thanks everyone for great help, Rick