BleepingComputer.com: Antivir warnings.

Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Antivir warnings.

#1 User is offline   FunkyChicka 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 110
  • Joined: 15-October 08

Posted 11 November 2008 - 10:23 AM

In the antivir logs after scanning, it says how many warnings and how many viruses etc.. how do they define the warnings?

And while I'm here to save me posting a separate topic, just wondering what SPR/PSW.ProductKey.AC is, because antivir found it on my computer and I was just wondering what it was.

#2 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,113
  • Joined: 09-July 05
  • Location:Virginia, USA

Posted 13 November 2008 - 02:18 PM

Quote

how do they define the warnings
What version are you using? Did you check the user manual?
User manual AVIRA ANTIVIR PERSONAL
User manual AVIRA ANTIVIR PROFESSIONAL

Quote

just wondering what SPR/PSW.ProductKey.AC is, because antivir found it on my computer
Did AntiVir provide a specific file name associated with this threat(s) and if so, where was it located (full file path) at on your system? Each security vendor uses their own naming conventions to identify various types of malware so it's difficult to determine exactly what has been detected or the nature of the infection without knowing more information about the actually file(s) involved.
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#3 User is offline   FunkyChicka 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 110
  • Joined: 15-October 08

Posted 13 November 2008 - 03:06 PM

Thanks for replying.

I can't remember the full path, but i think it was system restore or something like that

although i delete the 'infection' whenever i scan again, its always detected again.

#4 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,113
  • Joined: 09-July 05
  • Location:Virginia, USA

Posted 13 November 2008 - 03:11 PM

Sounds like its an infected RP***\A00*****.exe/.dll file(s) in the System Volume Information Folder (SVI) which is a part of System Restore. This is the feature that allows you to set points in time to roll back your computer to a clean working state. The SVI folder is protected by permissions that only allow the system to have access and is hidden by default unless you have reconfigured Windows to show it.

System Restore will back up the good as well as the bad files so when malware is present on the system it gets included in any restore points as an A00***** file. When you scan your system with anti-virus or anti-malware tools, you may receive an alert or notification that a virus was found in the SVI folder (System Restore points) but the anti-virus software was unable to remove it. Since the SVI folder is a protected directory, most scanning tools cannot access it to disinfect or delete these files. If not removed, they sometimes can reinfect your system if you accidentally use an old restore point.

To remove these file(s), the easiest thing to do is Create a New Restore Point to enable your computer to "roll-back" to a clean working state and use Disk Cleanup to remove all but the most recent restore point.
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#5 User is offline   FunkyChicka 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 110
  • Joined: 15-October 08

Posted 13 November 2008 - 04:37 PM

I thought restore points are set automatically by the computer no?

#6 User is offline   extremeboy 

  • Da Bleepin' Instructor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 12,924
  • Joined: 21-March 08
  • Gender:Male

Posted 13 November 2008 - 05:27 PM

Hello FunkyChicka.

Quote

I thought restore points are set automatically by the computer no?

Yes. They can be created automatically from your computer however; they can also be created manually with what Quietman7 said.

Once you create a new restore point and use Disk Cleanup, it will remove all older restore points so it will remove all the restore points that were created after the day you create the new restore point. This will remove the infected files in the System Volume Information folder previously.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 User is offline   Pickums1283 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 9
  • Joined: 06-March 08
  • Gender:Female
  • Location:New Jersey

Posted 15 November 2008 - 10:32 PM

You might have already gotten an answer to this, but I figured I'd give it a shot anyway.

I couldn't find any info on Avira on your particular threat, but I do know that SPR is a Security Privacy Risk, which Avira defines as "Software that maybe is able to compromise the security of your system, initiate unwanted program activities, damage your privacy or spy out your user behavior and might therefore be unwanted". I had an SPR threat on my computer a couple months ago and it was eBlaster, full Avira name SPR/Tool.eBlaster, which is a keylogger, plus it records emails, chats, IMs, websites visited, etc.

This post has been edited by Pickums1283: 16 November 2008 - 07:09 PM


#8 User is offline   FunkyChicka 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 110
  • Joined: 15-October 08

Posted 16 November 2008 - 06:51 AM

That's helpful too. Thanks.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users