Riskware in my PC

Dr.Web Cureit is doing a scan and so far it found this
Object A0006507.exe Path C:\System Volume Information_restore{26C00003-3B30-4DC6-B35F-A9DB8F009F97}\RP21 Status Program.PrcView.3741
I have no IRC or any Instant messenger in My computer. what is this anybody here have a clue ?

It’s some kind of weather picture from Sky???. Probably harmless. Put in Chest if you’re worried.

Avast 5 does not detect, was found by Dr. Web Cureit very sharp looking Ride you got there weather picture huh ???

I don’t know where “some kind of weather picture” came from given the very little information to work with. Riskware is basically a tool which could be used for good or evil and this could be almost any tool that could be used for good or evil.

There are many such tools, some will be flagged riskware/tool/pup, etc. but that definition is one that the different AV companies make, so do some don’t flag tools.

Also bearing in mind that this is a restore point you have also either deleted or moved this program, etc. that is why system restore created the restore point.

Googling prcview 3741 (the signature name) returns many hits as I would expect on a signature name, http://www.google.co.uk/search?q=PrcView+3741. None of it indicates what the file name is, the file name in the restore point A0006507.exe is generated by system restore so doesn’t reflect the original file name so no point searching on it.

So the only way to check this is by analysis to confirm first if the detection is good, what others that detect it call it, etc. - You could check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.

too late Dr. Web deleted it. all i have is the log file

That’s the problem with deletion, no way to investigate and confirm the detection.

yeah i saw that reply of yours a bit late.

Since this was discovered in a System Restore file, I suggest you turn off system restore to clear all entries and then
turn it on again if you intend to use system restore.