Help - Search - Members
Full Version: Virus: Please Look
Kaspersky Lab Forum > English User Forum > Protection for Small and Medium Businesses
jacko
Many computers on my network have been hanging or randomly rebooting lately. I have run Kaspersky scanners, but nothing has been found. I decided to try an online scanner to see what it showed. According to BitDefender online scanner, my Kaspersky setup files are infected with a trojan. Here is the file path, and I am attaching a screenshot:

C:\ProgramData\Kaspersky Lab Setup Files\Kaspersky Internet Security 2009\English

Click to view attachment

Is this a false positive, or has something infected my anti-virus somehow and made itself undetectable?

Please help!
Don Pelotas
With almost 100% certainty, yes thats a FP.....................only one way to find out for sure of course. smile.gif
ITNinja
jacko,

What version of KAV are you running?

Secondly do you have a hijack-this log? Check your minidump files or your event logs to see if there is any mention of a driver problem with klif.sys. Kaspersky released a module update a few weeks ago that updated the klif.sys file. This released contained a bug that would cause intermittent BSODs or computer hangs. Today (Feb 17th) Kaspersky released a hotfix for this issue that updates the klif.sys file under hotfix 'g'. This is supposed to resolve the intermittent hangs/BSODs caused by the previous update of klif.sys. This does require a reboot though to all the machines you are managing.
Don Pelotas
QUOTE(ITNinja @ 17.02.2009 18:35) *
jacko,

What version of KAV are you running?

Secondly do you have a hijack-this log? Check your minidump files or your event logs to see if there is any mention of a driver problem with klif.sys. Kaspersky released a module update a few weeks ago that updated the klif.sys file. This released contained a bug that would cause intermittent BSODs or computer hangs. Today (Feb 17th) Kaspersky released a hotfix for this issue that updates the klif.sys file under hotfix 'g'. This is supposed to resolve the intermittent hangs/BSODs caused by the previous update of klif.sys. This does require a reboot though to all the machines you are managing.

Not for Kaspersky Internet Security 2009...........the version is the picture, it's a home product and not affected or managed through the adminkit.
jacko
I'm running Kaspersky Anti-Virus 6.0 for Windows Workstations.

Should I look into this hotfix as mentioned above with my version?

jacko
I now see the acronym blue screen of death, and yes I have had these too across several workstations.




On a side not, if I have an active license am I eligible for upgrades to 2009? I believe I had a 2 year license which I purchased about a year ago. (50seat)
ITNinja
QUOTE(Don Pelotas @ 17.02.2009 10:41) *
Not for Kaspersky Internet Security 2009...........the version is the picture, it's a home product and not affected or managed through the adminkit.


Don,

Jacko says he has KAV 6.0 for windows workstations.

jacko, yes if you have KAV 6.0 for windows workstations you need to apply the hotfix by updating the application modules of your workstations. Don is right though your picture shows Kaspersky Internet Security being installed, was that an old install that you upgraded to KAV 6.0?
Don Pelotas
QUOTE(jacko @ 17.02.2009 19:33) *
I now see the acronym blue screen of death, and yes I have had these too across several workstations.
On a side not, if I have an active license am I eligible for upgrades to 2009? I believe I had a 2 year license which I purchased about a year ago. (50seat)

You're entitle to any upgrade within the license. Please update again and reboot..................a fix has been released.
jacko
Yes, I believe I tried a trial version of 2009 and then purchased a license. I'm not sure why Greenpages(or whoever I bought from) sold me a license to an earlier version, but that's why I'm asking about an upgrae. If I'm eligible I may as well have the latest and greatest.

I will call my third party seller and see what the deal is.

I am in the process of sending an email out to my entire network, gosh I hope this solves the issue! I have been pulling my hair out for days....

Don Pelotas
QUOTE(jacko @ 17.02.2009 20:39) *
Yes, I believe I tried a trial version of 2009 and then purchased a license. I'm not sure why Greenpages(or whoever I bought from) sold me a license to an earlier version, but that's why I'm asking about an upgrae. If I'm eligible I may as well have the latest and greatest.

I will call my third party seller and see what the deal is.

I am in the process of sending an email out to my entire network, gosh I hope this solves the issue! I have been pulling my hair out for days....

It doesn't matter which executable they (whoever you bought from) send you with the license...........the important thing is that you can use the home license for any version including the latest 2009 products, all you have to do is download the latest from downloads and use the code on it.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.