Help - Search - Members
Full Version: KIS 2010 is Unable to Update
Kaspersky Lab Forum > English User Forum > Virus-related issues
tecoip
Whether it's a local folder, or an online update, it doesn't matter: Update fails in the same moment it starts.

Uploaded my SYSTEM LOG

Be Advised: For a decent while the kaspersky wasn't set to auto-update, nor it did notify me of obsolete databases, nor it knew the date of it's current databases... blink.gif The last two disappeared after using a sort of cleaning tool which I used for fixing a messenger problem.

Lucian Bara
hello
C:\WINDOWS\system32\drivers\cdaudio.sys
C:\WINDOWS\system32\drivers\acernbm.sys

< send these file to the lab (don't delete them, don't rename them, leave the files on your hard drive where they are):
upload form: http://support.kaspersky.ru/virlab/helpdesk.html?LANG=en
post back what you hear from the lab.

also post an avz log using the standard avz tool: http://forum.kaspersky.com/index.php?showt...mp;#entry678334
tecoip

The lab reported back. They say that acernbm.sys is clean, but cdaudio.sys got a (Rootkit.Win32.Agent.ujv), which seems to be detected previously by them because they requested me that I update my databases. As if I could update...

AVZ Log Attached. Am I advised for a certain action against the hostile file? Kaspersky couldn't identify it yet.
Lucian Bara
run this script in AVZ (like you did with the one to create the log)
CODE
begin
SetAVZPMStatus(True);
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('C:\WINDOWS\System32\Drivers\Cdaudio.SYS','');
DeleteFile('C:\WINDOWS\System32\Drivers\Cdaudio.SYS');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.



-----------------
afterwards post a combofix log:
Download it here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe . Save the file to your desktop.

Now, please make sure no other programs are running, close all other windows and pause Kaspersky (Choose the option "resume manually" if still active) until after the scanning and removal process has taken place.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt , please attach it to your next post. Also, please don't forget to resume the Kaspersky that you paused.
tecoip

Script is run. ComboFix log is posted. Note that a previous ComboFix use was due before posting this thread but the log is unfortunately deleted.

Please also note: I forgot to say that the task manager shows two processes of avp.exe by default, and the number increases for each failed update attempt. e.g., 7 processes after 5 update attempts.
Lucian Bara
combofix log is not posted
tecoip
If it is of any use, I would like to tell that I've used this AVZ4 script (Through the Kaspersky) along with that previous ComboFix use:-

CODE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('c:\windows\ahnrpta.exe','');
QuarantineFile('C:\WINDOWS\system32\olhrwef.exe','');
QuarantineFile('C:\WINDOWS\system32\nmdfgds0.dll','');
QuarantineFile('C:\WINDOWS\system32\e8main0.dll','');
QuarantineFile('C:\autorun.inf','');
QuarantineFile('C:\uo10sn.cmd','');
QuarantineFile('D:\autorun.inf','');
QuarantineFile('D:\uo10sn.cmd','');
QuarantineFile('E:\autorun.inf','');
QuarantineFile('E:\uo10sn.cmd','');
QuarantineFile('F:\autorun.inf','');
QuarantineFile('F:\uo10sn.cmd','');
DeleteFile('F:\uo10sn.cmd');
DeleteFile('F:\autorun.inf');
DeleteFile('E:\uo10sn.cmd');
DeleteFile('E:\autorun.inf');
DeleteFile('D:\uo10sn.cmd');
DeleteFile('D:\autorun.inf');
DeleteFile('C:\uo10sn.cmd');
DeleteFile('C:\autorun.inf');
DeleteFile('C:\WINDOWS\system32\e8main0.dll');
DeleteFile('C:\WINDOWS\system32\nmdfgds0.dll');
DeleteFile('C:\WINDOWS\system32\olhrwef.exe');
DeleteFile('c:\windows\ahnrpta.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Lucian Bara
we didn't give you these instructions. where did you get them from?
tecoip

Oh, sorry for not posting the log, it's attached now. Regarding the previous ComboFix use and the AVZ4 code, it was... a friend's suggestion for solving "another problem", he's kind of a PC pro, and he told me about this forum when his own methods reached a dead end (i.e., didn't work). I hope what was executed doesn't affect your investigation or solution. Does it?
tecoip
If it is of any use, I remember that these symptoms ceased to exist upon the execution of both of the previous ComboFix use and the old AVZ4 code (The ones that you didn't instruct):-

- Clock and date restarts to Jan 2002 at a certain hour, upon each reboot.
- Could not unhide folders/files, neither through "Folder Options" in the Explorer nor by editing the appropriate registry values.
- Kaspersky didn't know that it's databases are obsolete.
- All drives in My Computer are not accessible by double-clicking, I needed to open them by the address bar.

There might be more, I'll post what I remember. Sorry for the inconvenience though.

EDIT: Just to remind, Kaspersky still fails to update locally and by internet, instantly saying "Task cannot be started. Module was not authenticated.", and for each failing attempt a new process in task manager spawns (avp.exe) aside from the main two.
DONE
Lucian Bara
run this script now
CODE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('C:\w9uxx92.exe','');
QuarantineFile('C:\2o1ajagt.exe','');
QuarantineFile('C:\ph.exe','');
DeleteFile('C:\w9uxx92.exe');
DeleteFile('C:\2o1ajagt.exe');
DeleteFile('C:\ph.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.


after that uninstall, reboot and reinstall kaspersky. attempt to update after this and report back
tecoip

Ok it's done. Right now kaspersky succeeds in update attempts, but unfortunately they end with "not all components were updated" and databases remain obsolete. I'm not sure if there's still damage in kaspersky or is it that my network permissions are limited. Any help?
Lucian Bara
post the update report please
tecoip
I hope this is what you are asking for: A full report, and a cropped copy including only the 2 last successful updates.

Just to know: Is my situation complicated??
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.