![]() |
![]() | Sirius.Annihilator | ![]() |
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
please read this thread on how to remove a virus from System Restore area:
https://forums.clamwin.com/viewtopic.php?t=147 |
|||||||||||
|
![]() |
![]() | ![]() |
pa
![]() |
![]() |
I deleted this files but others whith very similar name appear almost every day.
The last scan shows: C:\System Volume Information\_restore{409B3DB4-A37A-425B-9A65-AC47D6A2ECC3}\RP284\A0034085.exe: Broken.Executable FOUND C:\System Volume Information\_restore{409B3DB4-A37A-425B-9A65-AC47D6A2ECC3}\RP284\A0034086.dll: Sirius.Annihilator.272 FOUND ClamWin moved then to the quarantine folder, i delete them but they appears again the next day. I scan then whith virustotal, for A0034085.exe no antivirus found virus, for A0034086.dll only AVAST found a virus, Win32:CTX. I don't know if it's a virus or a false positive or how can i find the file who origin this ones. thanks a lot! |
|||||||||||
|
![]() |
![]() | how do i delete sirius.annihilator.272 | ![]() |
johnnyB
![]() |
![]() |
This is a scan report on the infected file ,which was quarantined, after i scanned the whole computer.
What is my next step?? thanks.. C:\WINDOWS\SYSTEM32\ASPRO\pskavs.dll: Sirius.Annihilator.272 FOUND C:\WINDOWS\SYSTEM32\ASPRO\pskavs.dll: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\infected.pskavs.dll' ----------- SCAN SUMMARY ----------- Known viruses: 95274 Engine version: 0.90 Scanned directories: 0 Scanned files: 1 Skipped non-executable files: 0 Infected files: 1 Data scanned: 2.25 MB Time: 10.953 sec (0 m 10 s) |
|||||||||||
|
![]() |
![]() | ![]() |
omnidrive
![]() |
![]() |
i just found the same problem, and i am trying to get rid of it. most online virus scans i have tried don't seem to find it, i am going to quarantine it and see what happens. my dell notebook won't go on temporary mod, so i think the infection is a getting deeper...
![]() |
|||||||||||
|
![]() |
![]() | ![]() |
K-LUM
![]() |
![]() |
hi a pop up came up saying an error had occured with panda platinum automatic protectiction and said it would no longer be able to function, it mentioned the virus Sirius.Annihilator.272. Now I can't open Panda
![]() C:\Program Files\Panda Software\Panda Internet Security 2007\Pskavs.dll: Sirius.Annihilator.272 FOUND ----------- SCAN SUMMARY ----------- Known viruses: 140122 Engine version: 0.90.2 Scanned directories: 26 Scanned files: 302 Skipped non-executable files: 0 Infected files: 1 Data scanned: 271.59 MB Time: 418.531 sec (6 m 58 s) -------------------------------------- Completed -------------------------------------- When I scan C:\Program Files\Panda Software\Panda Internet Security 2007\Pskavs.dll online and on other antiviruses it saya there's no virus! HELP!!! What should I do? ![]() |
|||||||||||
|
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
That's probably no virus but a false positive. This has been mentioned recently on this forum. I can't find it right now, but if you seach on the this forum for Panda or Sirus Annihilator, I'm sure you will find the thread(s). Christop Cordes, the ClamAV chief virus researcher mentioned it at the end of a thread.
Antivirus programs (including ClamWin) create files containing bits/pieces of viral code as they scan. They usually "police" them up after a scan or "mangle" them so they are unreadable. Panda doesn't always do this, however, and ClamWin sometimes finds the Sirus Annihilator virus when it scans a leftover Panda file. In this case there is no virus--just a false positive. This is borne out by the fact that no other antivirus software found a virus. Christoph said ClamAV doesn't regard this as a Clam problem--Panda needs to "police" up its file(s). If you want to use Panda and ClamWin, you should configure the exact file name in ClamWin preferences to be excluded from its scans. That should take care of the problem when you use ClamWin to scan your entire hard drive or the directory containing the file. However, if you scan the file by itself, ClamWin will ignore the exclusion and still treat it as a virus. |
|||||||||||
|
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
It seems a false positive
you can either restore pskavs.dll from quarantine directory: go to Start-Run and type the following command: copy "C:\Documents and Settings\All Users\.clamwin\quarantine\infected.pskavs.dll" "C:\WINDOWS\SYSTEM32\ASPRO\pskavs.dll" then press enter. Alternatively reinstall Panda |
|||||||||||
|
![]() |
![]() | ![]() |
drgoa.r
![]() |
![]() |
OFF-TOPIC:
I am not 100% sure...but think that last time I tryed to install Panda Antivirus...it won't install if ClamWin is installed. Seems Panda has a list of antivirus softwares, checks if they are present on the system (for me it seems like simple registry scan for installed software) and if find something - install stops with advise to remove other antivirus products. I manually removed the registry entries for ClamWin, installed Panda, then restored removed ClamWin entries. And after that they both work good. |
|||||||||||
|
![]() |
![]() | ![]() |
K-LUM
![]() |
![]() |
thanks a lot guys! It really helped. Panda works now
![]() |
|||||||||||
|
![]() |
![]() | Sirius.Annihilator | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.