Message "Need to restart" each 5mn

Since monday the 21 of June I get the message "Need to restart" each 5mn !!!!! This block the F-secure scan " F-secure get an error and a restart is needed".
The restart does nothing ! The same happen with VPN on or off.
I am using the version 25.5 where the correction implemented in version 25;4 must be ?
What shall I do ?
Answers
-
-
Hello @isla34
Thank you for bringing this to our attention.
Kindly generate an fsdiag and share it with us. We will check it for you and let you know our findings. Please share the fsdiag directly to us via private message.
Thank you and have a lovely day.
Firmy
Community Manager | F-Secure Community
🔐 Strengthening digital security through knowledge and collaboration
🌐 Explore our User Guides | Knowledge Base for self-help resources
💻 Empower yourself with Cybersecurity Insights and protect what matters -
-
Hello @Marmot
To protect your privacy, please avoid sharing your fsdiag file publicly in this forum. We have removed it for security reasons. If we need to review this information, we’ll reach out to you directly via private message.
You mentioned that you’ve already uninstalled and reinstalled the app. Could you please confirm if the issue still persists after the reinstallation? Are you still encountering the same error?
Thank you.
Firmy
Community Manager | F-Secure Community
🔐 Strengthening digital security through knowledge and collaboration
🌐 Explore our User Guides | Knowledge Base for self-help resources
💻 Empower yourself with Cybersecurity Insights and protect what matters -
Following re-installation there has been no recurrence of the 'restart' problem. I have also run 2 complete scans, yesterday and today with no issues found. So it looks like the problem is solved.
Just an aside which maybe relevant. I originally (15 years ago?) chose F-Secure because it was relatively light on processing demand compared to other virus protection. Over the period of the 'restart' problem I did notice that scanning significantly slowed down other software. This also now seems to have resolved itself.
fsdiag file: thank you for removing it, I wasn't sure how else to send it to you. Did you find anything useful to the problem - so that I don't repeat it in future e.g. software downloads.
Thank you.
-
Hello @isla34
Thank you for your cooperation. We have received the fsdiag and reviewed the findings.
It appears that Kaspersky Total Security was previously installed on the device, last seen in 2022. Could you please confirm if the application has been fully removed?
If Kaspersky still appears, we recommend using the Kaspersky Removal Tool to clean up any leftover components.
Additionally, we noticed that both F-Secure ID Protection and F-Secure Freedome are installed. Since F-Secure Total already includes the features of both, we suggest removing them to avoid duplication. Before doing so, please ensure that:
- Your passwords have been successfully synced with F-Secure Total.
- You export a password backup (recommended).
For the cleanest experience, you may use the F-Secure Uninstallation Tool to remove all F-Secure applications. Please note that this will require you to reinstall F-Secure Total afterwards, but it ensures a clean setup.
Kindly let us know once the steps are completed or if you need any assistance along the way.
Thank you again, and have a lovely day.
Firmy
Community Manager | F-Secure Community
🔐 Strengthening digital security through knowledge and collaboration
🌐 Explore our User Guides | Knowledge Base for self-help resources
💻 Empower yourself with Cybersecurity Insights and protect what matters -
Thanks for the procedure. I have not used Kaspersky since about 2008 and not on this machine. I can only think that it was a remnant 'junk' software provided when I bought this PC in 2022.
I have run the Kaspersky delete tool. As a result F-Secure quarantined Unkis.vbs (I understand this is a visual basic script file, probably introduced by Kaspersky) and vbs/KillAV.VPD (appears to be potentially more malicious).
Fully deleted F-Secure and re-installed. Did complete scan. Nothing nasty found and nothing in Quarantine. Is is reasonable to assume the vbs files are removed or is there anything else I should do?
Thanks for your help.
-
The F-secure msg is still there with the version 25.6:
By using the Powershell (Admin) :
displayName : Kaspersky Total Security
instanceGuid : {4F76F112-43EB-40E8-11D8-F7BD1853EA23}
pathToSignedProductExe : C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\wmiav.exe
pathToSignedReportingExe : C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe
productState : 266240
timestamp : Sat, 02 Apr 2022 18:43:26 GMT
PSComputerNameI run "Kavmvr" to remove the "remaining Kaspersky Sw" selecting "Kasperty …TotalSecurity 21MR3" but still the same output using Powershell(Admin)..
If you can help me to know how to remove correctly Kaspersky, it will be helpfull !
Thanks for your help
-
-
I have run the Kaspersky delete tool. As a result F-Secure quarantined Unkis.vbs (I understand this is a visual basic script file, probably introduced by Kaspersky) and vbs/KillAV.VPD (appears to be potentially more malicious).
Based on its name "Unkis.vbs" sounds as it is something like "Uninstall Kaspersky Internet Security"? And "vbs/KillAV.VPD" looks more like the name of some item detection.
Somehow F-Secure detected a part of dedicated security software removal tool as a tool to 'kill' AV or some kind of hack-tool. Perhaps reasonable.. if somewhere, sometime, it was used in such a way by malicious actors. Or this .vbs script contains something generic for such uninstall operations (unattached to certain security solution).
I think that the utility creates these files somewhere in temporary folders and it is interesting when they were detected (in other words, whether the uninstallion "process" that was intended was completed or was interrupted when creating/using scripts for the action). Likely they were intended to be 'temporarily' - so should not be longer in system unless some unexpected routine.
I run "Kavmvr" to remove the "remaining Kaspersky Sw" selecting "Kasperty …TotalSecurity 21MR3" but still the same output using Powershell(Admin)..
I tried to search this tool out of interest with other user's experience with detection.
For me, the tool is called as "kavremvr.exe" (/utilities/ConsumerUtilities/ in their official website in
"Removal tool for Kaspersky applications on Windows (kavremover)" article).when you use it, is there any report on the work done? For example, article says - you need to click "OK" when process is done and then restart system.
Thanks!