I have NO Kaspersky software installed om this machine, never had. However, I used their ONLINE SCANNER once for a while ago, and is now experiancing an array of problems ever since. Most noticeable is a significant drop in transfer speed, unexpected delays, 5-10 seconds long "black-outs" where the computer refuse to take input of any kind (including CTRL-ALT-DEL), and more. I have therefore good reason to suspect a malware infection of some kind. All security software running in this machine, as well as Windows Update, are upp to date.
What I tried: full scan (both in Failsafe-mode and in Windows) with everything I've got - Malwarebytes Premium, Zone Alarm ES, HitmanPro, Win Defender and Eset (onlinescanner), and they all came up clean, as usual. Next I checked the registry and found tons of Kaspersky related entries under HKLM, but most of them are impossible to remove/edit! (I am relactant to use external registry editors). Also - the files that some of these entries refer to are not present/visible on this system (KL1.inf, KLHK.inf, KLIF.inf, KLTDI.inf, KNEPS.inf, and a few more), not even with an extensive search for hidden files in Failsafe Mode. I suspect that they are produced dinamically while the the unknown software is running and then they disappear.
There is also an uninvited, and checked, "Kaspersky Anti-Virus NDIS 6 Filter" installed as a Service in the network connection setting. Unchecking it results in a warning for BSOD and potentionally "catastrofic consequencies". Indeed, when I unchecked it and tried to reboot, the computer stopped to respond and power-off was the only remaining option. However, next time the computer started as usual and is seemingly back to "normal" - including the problems mentioned above. Whether checked or unchecked, choosing the available Uninstall button below it results in a message telling me that I first need to terminate "KAVDSK 8 Level 3 for Windows". There is no such service running, but KAVDSK appeared as an argument in the registry, so I removed it pronto. New uninstall attempt results in the same message, but NO mention of KAVDSK this time! The namn space is left empty...
To make things more complicted - there are TWO computers connected to this small home LAN, both have similar suspect Kaspersky entries in the registry, but only one have the "Kaspersky Anti-Virus NDIS 6 Filter" service present in its network propreties. The OS's are legal retail Swedish Win7/64 in both, but reinstalling Windows is not an option at this time. Installable DVD is availlable, however.
Would greatly appreciate any advise. Thanks!
Edited by hamluis, 15 January 2018 - 03:47 PM.
Moved from Win 7 to Am I Infected - Hamluis.