Help - Search - Members
Full Version: KIS 2010 wont perform full scan/objects scan
Kaspersky Lab Forum > English User Forum > Virus-related issues
xxmopar17xx
When I first got it, it worked for a while, but now only the quick scan works. It says that an unknown malfunction occurred and then shuts off. Not sure what to do....
Don Pelotas
Which version?
xxmopar17xx
Kaspersky Insternet Security 9.0.0.463
Sjoeii
Please post a GSI for more information http://forum.kaspersky.com/index.php?showtopic=36444
xxmopar17xx
Alright here you go...
dh27564
Please click the link below to upload your GSI report so it can be viewed by the moderators. Click the browse button to find the file you created and then press the SUBMIT button. Once the file is uploaded, copy the address from the URL/address bar and post it back here. Once the address is posted, members can view your report and advise.

http://www.getsysteminfo.com/
xxmopar17xx
Was that what I needed to post?
dh27564
Yes. A moderator will be along to offer suggestions based on the report.
richbuff
Please clean upgrade to the current build, instructions are in the first important topic.

If still receive the same error after clean upgrade, attach the zipped virusinfo_syscure.zip; instructions, see: http://forum.kaspersky.com/index.php?s=&am...st&p=678334
xxmopar17xx
Here it is
richbuff
Run this script, instructions: http://forum.kaspersky.com/index.php?s=&am...st&p=678368 PC will reboot:
CODE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('NA.exe','');
DeleteFile('NA.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Power2GoExpress');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','Power2GoExpress');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

After run script, attach a Combofix log, please review and follow these instructions carefully.

Before Saving combofix to Desktop, please rename combofix to something like 123.exe to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows and pause Kaspersky (right click the K icon and click pause protection > Choose the
option "resume manually" if still active) until after the scanning and removal process has taken place.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall.
It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after
scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post. Also, please don't
forget to resume the Kaspersky that you paused.

Download Combofix here -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

(Also, please attach any older Combofix logs that you may have.)
xxmopar17xx
Alright we have a problem here... I can't find the combofix log...
richbuff
Did you try a Windows search? Did Combofix appear to complete?

Also, scan with Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php Update it first, scan and attach its log, but Please Don't fix anything yet, until the log is reviewed.
xxmopar17xx
I did do a Windows search but didn't find anything and I think comobofix did complete its cycle but no log was ever posted...

heres the malwarebytes log scan
Malwarebytes' Anti-Malware 1.41
Database version: 3065
Windows 5.1.2600 Service Pack 3

10/31/2009 4:38:01 PM
mbam-log-2009-10-31 (16-38-01).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Objects scanned: 275259
Time elapsed: 3 hour(s), 52 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
richbuff
Run this one:
CODE
begin
CreateQurantineArchive('c:\quarantine.zip');
end.

A file called quarantine.zip should be created in C:\. Then please zip up C:\qoobox\ and upload both it and C:\quarantine.zip to a filehost such as http://rapidshare.com/
Then, Private Message me the Download link to the uploaded file. Click my user name and select Send message. Lastly, after you send me the qoobox, uninstall Combofix by: pause Kaspersky > Start > run >
type combofix /u > ok. Or Start > run > type 123 /u > ok. Restart Kaspersky.

Also, if you use Windows System restore, turn it off > reboot and do a full scan with Kaspersky. This to remove malware from system volume information files. Then turn system restore back on, if you wish. How to turn it off/on: http://support.kaspersky.com/faq/?qid=208279208

Before doing the scan, Clear the Detected list: Detected > Active threats > right click > Disinfect all > right click > Clear list > then scan again > then post screenshot of Detected >
Active threats. With columns widened to show full name and object details.

How to take and post screenshot: PrtSc (Print screen) key (upper right part of keyboard)> open Paint (Start > All programs > Accessories) > Edit > Paste, File > Save as (jpeg or
png, Not bmp). When replying, Browse > click once to select file > Open > Upload > add reply.
xxmopar17xx
Okayy so I tried the full scan again and it still shuts off due to a malfunction....Quick Scan works and it seems to be updating alright
richbuff
Uninstall Kaspersky > reboot > re install Kaspersky > reboot.
xxmopar17xx
Okay I did that. Twice actually. First with the Cd version and then downloading directly from the site. Still have the same problem as before. Objects/Full Scan dont work. Seems to update alright except I noticed that the malicious scripts section hadnt been updated since 07/10/09 and that struck me as odd but I dont really know anything...
richbuff
The malicious script update is correct, but can't scan is not. Please contact Tech Support, link is at upper left of this page.
xxmopar17xx
Alright thanks for your help :]
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.