Help - Search - Members
Full Version: mi antivirus no actualiza
Kaspersky Lab Forum > Forum para usuarios hispanohablantes > Protección para usuarios domésticos
junitodriver
holan como les comenté n puedo actualizr mi antivirus, aquli dejo el log

Attention !!! Database was last updated 21/08/09 it is necessary to update the database (via File - Database update)
AVZ Antiviral Toolkit log; AVZ version is 4.32
Scanning started at 01/12/09 10:55:46 a.m.
Database loaded: signatures - 237871, NN profile(s) - 2, malware removal microprograms - 56, signature database released 21.08.2009 14:23
Heuristic microprograms loaded: 374
PVS microprograms loaded: 9
Digital signatures of system files loaded: 135524
Heuristic analyzer mode: Medium heuristics mode
Malware removal mode: enabled
Windows version is: 5.1.2600, Service Pack 3 ; AVZ is run with administrator rights
System Restore: enabled
1. Searching for Rootkits and other software intercepting API functions
1.1 Searching for user-mode API hooks
Analysis: kernel32.dll, export table found in section .text
Analysis: ntdll.dll, export table found in section .text
Analysis: user32.dll, export table found in section .text
Analysis: advapi32.dll, export table found in section .text
Analysis: ws2_32.dll, export table found in section .text
Analysis: wininet.dll, export table found in section .text
Analysis: rasapi32.dll, export table found in section .text
Analysis: urlmon.dll, export table found in section .text
Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
Driver loaded successfully
SDT found (RVA=08B520)
Kernel ntoskrnl.exe found in memory at address 804D7000
SDT = 80562520
KiST = 804E48B0 (284)
Function NtAdjustPrivilegesToken (0B) intercepted (805E078F->B71485EE), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtClose (19) intercepted (8056FA48->B7148E6E), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtConnectPort (1F) intercepted (80585565->B7149984), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateEvent (23) intercepted (8057CD25->B7149EF6), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateFile (25) intercepted (8057C328->B7149150), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateKey (29) intercepted (8057791D->B7147498), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateMutant (2B) intercepted (8057F3B8->B7149DCE), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateNamedPipeFile (2C) intercepted (80588CAC->B71481F4), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreatePort (2E) intercepted (8059902A->B7149C8A), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateSection (32) intercepted (8056DB66->B71483B0), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateSemaphore (33) intercepted (8057A9DC->B714A028), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateSymbolicLinkObject (34) intercepted (805E6E5E->B714BC6A), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateThread (35) intercepted (80586C45->B7148B0C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtCreateWaitablePort (38) intercepted (805AA552->B7149D2C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtDebugActiveProcess (39) intercepted (80662551->B714B65C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtDeleteKey (3F) intercepted (80593334->B7147A5C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtDeleteValueKey (41) intercepted (80591F8B->B7147DEA), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtDeviceIoControlFile (42) intercepted (805889A8->B71495D8), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtDuplicateObject (44) intercepted (80581216->B714C62C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtEnumerateKey (47) intercepted (80578E14->B7147F2C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtEnumerateValueKey (49) intercepted (80587693->B7147FD6), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtFsControlFile (54) intercepted (805803EB->B71493E4), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtLoadDriver (61) intercepted (805A8F96->B714B6EE), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtLoadKey (62) intercepted (805CE7ED->B7147474), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtLoadKey2 (63) intercepted (805CE94C->B7147486), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtMapViewOfSection (6C) intercepted (8057E369->B714BD1E), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtNotifyChangeKey (6F) intercepted (805E2197->B7148122), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenEvent (72) intercepted (80589A51->B7149F98), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenFile (74) intercepted (8057C49C->B7148EF0), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenKey (77) intercepted (80572BF4->B714763E), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenMutant (78) intercepted (8057F466->B7149E66), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenProcess (7A) intercepted (80581702->B71487F4), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenSection (7D) intercepted (8057A8AD->B714BC94), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenSemaphore (7E) intercepted (805E71D2->B714A0CA), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtOpenThread (80) intercepted (805E1941->B7148718), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtQueryKey (A0) intercepted (80578A14->B7148080), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtQueryMultipleValueKey (A1) intercepted (8065570C->B7147CA8), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtQuerySection (A7) intercepted (80588048->B714C036), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtQueryValueKey (B1) intercepted (80573037->B71478F8), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtQueueApcThread (B4) intercepted (805E3B95->B714B984), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtRenameKey (C0) intercepted (80655B88->B7147B70), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtReplaceKey (C1) intercepted (806564E8->B7147312), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtReplyPort (C2) intercepted (80583142->B714A454), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtReplyWaitReceivePort (C3) intercepted (80575C24->B714A31A), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtRequestWaitReplyPort (C8) intercepted (80579485->B714B3FC), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtRestoreKey (CC) intercepted (8065607D->B714EE8E), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtResumeThread (CE) intercepted (805872BC->B714C50E), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSaveKey (CF) intercepted (8065617E->B71472AA), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSecureConnectPort (D2) intercepted (80590431->B71496BE), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSetContextThread (D5) intercepted (80635977->B7148D2A), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSetInformationToken (E6) intercepted (805A6174->B714ACAC), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSetSecurityObject (ED) intercepted (805D9CB7->B714B7E8), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSetSystemInformation (F0) intercepted (805AABC8->B714C176), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSetValueKey (F7) intercepted (8058228C->B7147780), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSuspendProcess (FD) intercepted (8063770F->B714C25A), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSuspendThread (FE) intercepted (8063762B->B714C382), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtSystemDebugControl (FF) intercepted (80650DC5->B714B588), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtTerminateProcess (101) intercepted (8058E695->B714896C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtTerminateThread (102) intercepted (805838E7->B71488C2), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtUnmapViewOfSection (10B) intercepted (8057DEF1->B714BEEC), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function NtWriteVirtualMemory (115) intercepted (805885C4->B7148A4C), hook C:\WINDOWS\system32\DRIVERS\klif.sys, driver recognized as trusted
Function FsRtlCheckLockForReadAccess (804F4593) - machine code modification Method of JmpTo. jmp B713D572 \SystemRoot\system32\DRIVERS\klif.sys, driver recognized as trusted
Function IoAllocateIrp (804EAF9D) - machine code modification Method not defined., embedding from byte 15
Function IoIsOperationSynchronous (804EAFAE) - machine code modification Method of JmpTo. jmp B713D94C \SystemRoot\system32\DRIVERS\klif.sys, driver recognized as trusted
Functions checked: 284, intercepted: 61, restored: 0
1.3 Checking IDT and SYSENTER
Analyzing CPU 1
Analyzing CPU 2
Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
Checking not performed: extended monitoring driver (AVZPM) is not installed
Driver loaded successfully
1.5 Checking IRP handlers
Checking - complete
2. Scanning RAM
Number of processes found: 25
Number of modules loaded: 383
Scanning RAM - complete
3. Scanning disks
4. Checking Winsock Layered Service Provider (SPI/LSP)
LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
C:\ARCHIV~1\KASPER~1\KASPER~2\mzvkbd3.dll --> Suspicion for Keylogger or Trojan DLL
C:\ARCHIV~1\KASPER~1\KASPER~2\mzvkbd3.dll>>> Behaviour analysis
Behaviour typical for keyloggers was not detected
Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs
6. Searching for opened TCP/UDP ports used by malicious software
Checking - disabled by user
7. Heuristic system check
Latent DLL loading through AppInit_DLLs suspected: "C:\ARCHIV~1\KASPER~1\KASPER~2\mzvkbd3.dll"
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: TermService (Servicios de Terminal Server)
>> Services: potentially dangerous service allowed: SSDPSRV (Servicio de descubrimientos SSDP)
>> Services: potentially dangerous service allowed: Schedule (Programador de tareas)
>> Services: potentially dangerous service allowed: RDSessMgr (Administrador de sesión de Ayuda de escritorio remoto)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
9. Troubleshooting wizard
>> Abnormal SCR files association
>> Service termination timeout is out of admissible values
>> HDD autorun is allowed
>> Network drives autorun is allowed
>> Removable media autorun is allowed
Checking - complete
Files scanned: 41891, extracted from archives: 20078, malicious software found 0, suspicions - 0
Scanning finished at 01/12/09 11:04:19 a.m.
Time of scanning: 00:08:35
If you have a suspicion on presence of viruses or questions on the suspected objects,
you can address http://virusinfo.info conference
Caos
Hola,

Te recomiendo que te revises las normas del foro, te serán de gran ayuda.

Postea toda la información que en ellas se pide (Versión y build de Kaspersky instalado, S.O. y servicepack instalados, postea tu getsysteminfo (gsi)
utilizando mejor la nueva versión que encontraras al final de mi post (en mi firma), postea tu avzlog para revisarlo, etc...) para que te podamos ayudar.

A primera vista, bonito regalito en tu sistema, revisa que tengas marcada en amenazas la opción otro(s) :
http://www.virustotal.com/analisis/800bdf0...7a9e-1256593645

Script de desinfección:

QUOTE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('C:\WINDOWS\system32\28463\svchost.exe','');
QuarantineFile('c:\windows\system32\28463\svchost.exe','');
DeleteFile('c:\windows\system32\28463\svchost.exe');
DeleteFile('C:\WINDOWS\system32\28463\svchost.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.


Saludos

Caos
Despues de ejecutar el script, postea tu combofix log:
Descargalo de aquí

Antes de guardar, por favor renombralo a algo parecido a 123.exe para parar al malware y que no pueda deshabilitarlo.

Ahora, por favor, asegurate de que no se están ejecutando otros programas, cierra todas las ventanas y pausa Kaspersky (Elije la opción de "reanudar
manualmente" si todavía esta activo) hasta que termine con el escaneado y el proceso de eliminación.

Por favor, haga doble clic en el archivo descargado. Siga las indicaciones en pantalla para iniciar la exploración/escaneado.
Una vez que el proceso de exploración/escaneado ha comenzado por favor NO haga clic en la ventana del combofix o intente utilizar su equipo ya que esto
puede causar problemas en el equipo. La exploracion/escaneado puede tomar bastante tiempo para completarse, esto es normal.

Su equipo se desconectara de Internet y los iconos del escritorio/barras de herramientas desaparecerán durante la exploración, no se preocupe, esto es
normal y apareceran en cuanto la exploración haya terminado.

Combofix creará un archivo de registro (log) y lo mostrara después de que su equipo se haya reiniciado. Por lo general, estara situado en
c:\combofix.txt, por favor, adjuntalo en tu siguiente post.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.