本帖最后由 日渐颓废的我们 于 2014-1-21 13:46 编辑
晓de朱雀_鼬 发表于 2014-1-21 13:32
哈?安全模式下也不行?不至于吧!安全模式都不加载驱动了,卡巴没这么牛吧
其实我觉得很有可能是系统的问题……我用的是windows 8.1……
因为我看kavremover的错误报告
02:04:42.697 This OS is not supported failed. Error 2: 系统找不到指定的文件。 - 1748:06d8 00:20:15.402 KAVRemover tool version 1.0.603
- 1748:06d8 00:20:15.402 System language detected: langID=9, sublangID=1
- 1748:06d8 00:20:15.402 User language detected: langID=4, sublangID=2
- 1748:06d8 00:20:15.402 Setting UI language: langID=9, sublangID=2
- 1748:06d8 00:20:15.402 Locale successfully set
- 1748:06d8 00:20:15.465 dbghelp.dll dumped OK
- 1748:06d8 00:20:17.137 Initializing application...
- 1748:06d8 00:20:17.277 Loading ini files...
- 1748:06d8 00:20:17.340 Loading resource data 'RES_INI_X64'...
- 1748:06d8 00:20:17.356 Loading resource data finished, 582623 bytes
- 1748:06d8 00:20:17.356 Loading resource data 'RES_INI_X32X64'...
- 1748:06d8 00:20:17.356 Loading resource data finished, 164734 bytes
- 1748:06d8 00:20:17.356 Parsing ini files data...
- 1748:06d8 00:20:17.402 Ini files data parsed, 28 files parsed
- 1748:06d8 00:20:17.402 Dumping data to files...
- 1748:06d8 00:20:17.402 Data dumped to files
- 1748:0708 00:20:17.481 Searching for installed products...
- 1748:0708 00:20:17.481 ShutdownDetector started watch thread (000002dc)
- 1748:070c 00:20:17.481 Watch thread started
- 1748:0708 00:20:17.496 Kaspersky Removal Tool 1.0.603
- 1748:0708 00:20:17.496 KLeaner initialized
- 1748:0708 00:20:17.496 OS Platform = NT, version = 6.3.9600, 64 bit
- 1748:0708 00:20:17.496 OS version ext PlatformId=2 CSDVersion="" SP=0.0 Suite=00000300 ProductType=1 Reserved=0
- 1748:0708 00:20:17.527 TraceSystemInfo: Time ticks=83265 ticks64=83265 idle=654.7187500 kernel=662.1562500 user=2.1093750
- 1748:0708 00:20:17.527 TraceSystemInfo: System oemId=00000009 pageSize=4096 MinAppAddress=00010000 MaxAppAddress=FFFEFFFF ActiveProcessorMask=000000FF NumberOfProcessors=8 ProcessorType=8664 AllocationGranularity=65536 ProcessorLevel=6 ProcessorRevision=15363
- 1748:0708 00:20:17.527 TraceSystemInfo: Memory Load=13 Phys=7204401152/8296615936 PageFile=7245656064/8296615936 Virtual=2016784384/2147352576 AvailExtendedVirtual=0
- 1748:0708 00:20:17.559 TraceSystemInfo: Performance commit(total=256578,limit=2025541,peak=259272 phis(total=2025541,avail=1758893) syscache=79207 kernel(total=50288,paged=29224,nonpaged=21064) page=4096 handles=5333 processes=22 threads=328
- 1748:0708 00:20:17.559 TraceTokenInformation: class=1(User) length=36 [User[Sid=S-1-5-21-4063754582-3048442541-3029454900-1002,Attributes=0]]
- 1748:0708 00:20:17.559 TraceTokenInformation: class=2(Groups) length=344 [GroupCount=14,[Sid=S-1-16-12288,Attributes=60],[Sid=S-1-1-0,Attributes=7],[Sid=S-1-5-114,Attributes=7],[Sid=S-1-5-32-544,Attributes=F],[Sid=S-1-5-32-545,Attributes=7],[Sid=S-1-5-4,Attributes=7],[Sid=S-1-2-1,Attributes=7],[Sid=S-1-5-11,Attributes=7],[Sid=S-1-5-15,Attributes=7],[Sid=S-1-11-96-3623454863-58364-18864-2661722203-1597581903-3005979970-2001990645-2405958475-1199014264-1064271294,Attributes=7],[Sid=S-1-5-113,Attributes=7],[Sid=S-1-5-5-0-125816,Attributes=C0000007],[Sid=S-1-2-0,Attributes=7],[Sid=S-1-5-64-32,Attributes=7]]
- 1748:0708 00:20:17.574 TraceTokenInformation: class=3(Privileges) length=280 [PrivilegeCount=23,[Luid=SeIncreaseQuotaPrivilege,Attributes=0],[Luid=SeSecurityPrivilege,Attributes=0],[Luid=SeTakeOwnershipPrivilege,Attributes=0],[Luid=SeLoadDriverPrivilege,Attributes=0],[Luid=SeSystemProfilePrivilege,Attributes=0],[Luid=SeSystemtimePrivilege,Attributes=0],[Luid=SeProfileSingleProcessPrivilege,Attributes=0],[Luid=SeIncreaseBasePriorityPrivilege,Attributes=0],[Luid=SeCreatePagefilePrivilege,Attributes=0],[Luid=SeBackupPrivilege,Attributes=0],[Luid=SeRestorePrivilege,Attributes=0],[Luid=SeShutdownPrivilege,Attributes=0],[Luid=SeDebugPrivilege,Attributes=0],[Luid=SeSystemEnvironmentPrivilege,Attributes=0],[Luid=SeChangeNotifyPrivilege,Attributes=3],[Luid=SeRemoteShutdownPrivilege,Attributes=0],[Luid=SeUndockPrivilege,Attributes=0],[Luid=SeManageVolumePrivilege,Attributes=0],[Luid=SeImpersonatePrivilege,Attributes=3],[Luid=SeCreateGlobalPrivilege,Attributes=3],[Luid=SeIncreaseWorkingSetPrivilege,Attributes=0],[Luid=SeTimeZonePrivilege,Attributes=0],[Luid=SeCreateSymbolicLinkPrivilege,Attributes=0]]
- 1748:0708 00:20:17.574 TraceTokenInformation: class=4(Owner) length=20 [Owner=S-1-5-32-544]
- 1748:0708 00:20:17.574 TraceTokenInformation: class=5(PrimaryGroup) length=32 [PrimaryGroup=S-1-5-21-4063754582-3048442541-3029454900-1002]
- 1748:0708 00:20:17.574 TraceTokenInformation: class=11(RestrictedSids) length=4 [GroupCount=0]
- 1748:0708 00:20:17.574 TraceTokenInformation: class=12(SessionId) length=4 [1(00000001)]
- 1748:0708 00:20:17.574 TraceTokenInformation: class=14(SessionReference) length=1 GetInfo fail error=87
- 1748:0708 00:20:17.574 TraceTokenInformation: class=15(SandBoxInert) length=4 [0(00000000)]
- 1748:0708 00:20:17.574 TraceTokenInformation: class=16(AuditPolicy) length=1 GetInfo fail error=1314
- 1748:0708 00:20:17.574 KLeaner is looking in C:\Users\user~1\AppData\Local\Temp\jkbasuy1\xsxfr\ for *.ini...
- 1748:0708 00:20:17.574 file found: df0.ini
- 1748:0708 00:20:17.590 msiParams=''
- 1748:0708 00:20:17.590 hexUninstallPassword=''
- 1748:0708 00:20:17.590 This OS is not supported
- 1748:0708 00:20:17.590 no detect
- 1748:0708 00:20:17.590 file found: df1.ini
- 1748:0708 00:20:17.606 msiParams=''
- 1748:0708 00:20:17.606 hexUninstallPassword=''
- 1748:0708 00:20:17.606 This OS is not supported
- 1748:0708 00:20:17.606 no detect
- 1748:0708 00:20:17.606 file found: df10.ini
- 1748:0708 00:20:17.606 msiParams=''
- 1748:0708 00:20:17.606 hexUninstallPassword=''
- 1748:0708 00:20:17.715 no detect
- 1748:0708 00:20:17.715 file found: df11.ini
- 1748:0708 00:20:17.715 msiParams=''
- 1748:0708 00:20:17.715 hexUninstallPassword=''
- 1748:0708 00:20:17.715 no detect
- 1748:0708 00:20:17.715 file found: df12.ini
- 1748:0708 00:20:17.731 msiParams=''
- 1748:0708 00:20:17.731 hexUninstallPassword=''
- 1748:0708 00:20:17.731 no detect
- 1748:0708 00:20:17.731 file found: df13.ini
- 1748:0708 00:20:17.731 msiParams=''
- 1748:0708 00:20:17.731 hexUninstallPassword=''
- 1748:0708 00:20:17.731 no detect
- 1748:0708 00:20:17.731 file found: df14.ini
- 1748:0708 00:20:17.731 msiParams=''
- 1748:0708 00:20:17.731 hexUninstallPassword=''
- 1748:0708 00:20:17.731 This OS is not supported
- 1748:0708 00:20:17.731 no detect
- 1748:0708 00:20:17.731 file found: df15.ini
- 1748:0708 00:20:17.746 msiParams=''
- 1748:0708 00:20:17.746 hexUninstallPassword=''
- 1748:0708 00:20:17.746 This OS is not supported
- 1748:0708 00:20:17.746 no detect
- 1748:0708 00:20:17.746 file found: df16.ini
- 1748:0708 00:20:17.746 msiParams=''
- 1748:0708 00:20:17.746 hexUninstallPassword=''
- 1748:0708 00:20:17.746 Detecting upgrade code '5278159B67B039744A906C974424BF05,MinVersion=0x08000000,MaxVersion=0x09FFFFFF'
- 1748:0708 00:20:17.746 upgrade-code='5278159B67B039744A906C974424BF05' MinVersion=true,134217728 MaxVersion=true,167772159
- 1748:0708 00:20:17.762 RegOpenKeyEx(0000033CH\5278159B67B039744A906C974424BF05) failed. Error 2: 系统找不到指定的文件。.
- 1748:0708 00:20:17.762 Fail! get upgrade code key error: err 2
- 1748:0708 00:20:17.762 no detect
- 1748:0708 00:20:17.762 file found: df17.ini
- 1748:0708 00:20:17.762 msiParams=''
- 1748:0708 00:20:17.762 hexUninstallPassword=''
- 1748:0708 00:20:17.762 Detecting upgrade code '5278159B67B039744A906C974424BF05,MinVersion=0x0A000000,MaxVersion=0x0AFFFFFF'
- 1748:0708 00:20:17.762 upgrade-code='5278159B67B039744A906C974424BF05' MinVersion=true,167772160 MaxVersion=true,184549375
- 1748:0708 00:20:17.762 RegOpenKeyEx(0000033CH\5278159B67B039744A906C974424BF05) failed. Error 2: 系统找不到指定的文件。.
- 1748:0708 00:20:17.762 Fail! get upgrade code key error: err 2
- 1748:0708 00:20:17.762 no detect
- 1748:0708 00:20:17.762 file found: df18.ini
- 1748:0708 00:20:17.762 msiParams=''
- 1748:0708 00:20:17.762 hexUninstallPassword=''
- 1748:0708 00:20:17.762 no detect
- 1748:0708 00:20:17.762 file found: df19.ini
- 1748:0708 00:20:17.777 msiParams=''
- 1748:0708 00:20:17.777 hexUninstallPassword=''
- 1748:0708 00:20:17.777 found Kaspersky PURE 3.0 / CRYSTAL
- 1748:0708 00:20:17.777 file found: df2.ini
- 1748:0708 00:20:17.777 msiParams=''
- 1748:0708 00:20:17.777 hexUninstallPassword=''
- 1748:0708 00:20:17.777 no detect
- 1748:0708 00:20:17.777 file found: df20.ini
- 1748:0708 00:20:17.777 msiParams=''
- 1748:0708 00:20:17.777 hexUninstallPassword=''
- 1748:0708 00:20:17.777 This OS is not supported
- 1748:0708 00:20:17.777 no detect
- 1748:0708 00:20:17.777 file found: df21.ini
- 1748:0708 00:20:17.777 msiParams=''
- 1748:0708 00:20:17.777 hexUninstallPassword=''
- 1748:0708 00:20:17.777 This OS is not supported
- 1748:0708 00:20:17.777 no detect
- 1748:0708 00:20:17.777 file found: df22.ini
- 1748:0708 00:20:17.793 msiParams=''
- 1748:0708 00:20:17.793 hexUninstallPassword=''
- 1748:0708 00:20:17.793 no detect
- 1748:0708 00:20:17.793 file found: df23.ini
- 1748:0708 00:20:17.793 msiParams=''
- 1748:0708 00:20:17.793 hexUninstallPassword=''
- 1748:0708 00:20:17.793 no detect
- 1748:0708 00:20:17.793 file found: df24.ini
- 1748:0708 00:20:17.809 msiParams=''
- 1748:0708 00:20:17.809 hexUninstallPassword=''
- 1748:0708 00:20:17.809 no detect
- 1748:0708 00:20:17.809 file found: df25.ini
- 1748:0708 00:20:17.809 msiParams=''
- 1748:0708 00:20:17.809 hexUninstallPassword=''
- 1748:0708 00:20:17.809 no detect
- 1748:0708 00:20:17.809 file found: df26.ini
- 1748:0708 00:20:17.809 msiParams=''
- 1748:0708 00:20:17.809 hexUninstallPassword=''
- 1748:0708 00:20:17.809 no detect
- 1748:0708 00:20:17.809 file found: df27.ini
- 1748:0708 00:20:17.809 msiParams=''
- 1748:0708 00:20:17.809 hexUninstallPassword=''
- 1748:0708 00:20:17.809 This OS is not supported
- 1748:0708 00:20:17.809 no detect
- 1748:0708 00:20:17.809 file found: df3.ini
- 1748:0708 00:20:17.809 msiParams=''
- 1748:0708 00:20:17.809 hexUninstallPassword=''
- 1748:0708 00:20:17.809 This OS is not supported
- 1748:0708 00:20:17.809 no detect
- 1748:0708 00:20:17.809 file found: df4.ini
- 1748:0708 00:20:17.824 msiParams=''
- 1748:0708 00:20:17.824 hexUninstallPassword=''
- 1748:0708 00:20:17.824 This OS is not supported
- 1748:0708 00:20:17.824 no detect
- 1748:0708 00:20:17.824 file found: df5.ini
- 1748:0708 00:20:17.824 msiParams=''
- 1748:0708 00:20:17.824 hexUninstallPassword=''
- 1748:0708 00:20:17.824 This OS is not supported
- 1748:0708 00:20:17.824 no detect
- 1748:0708 00:20:17.824 file found: df6.ini
- 1748:0708 00:20:17.824 msiParams=''
- 1748:0708 00:20:17.824 hexUninstallPassword=''
- 1748:0708 00:20:17.824 This OS is not supported
- 1748:0708 00:20:17.824 no detect
- 1748:0708 00:20:17.824 file found: df7.ini
- 1748:0708 00:20:17.824 msiParams=''
- 1748:0708 00:20:17.824 hexUninstallPassword=''
- 1748:0708 00:20:17.824 no detect
- 1748:0708 00:20:17.824 file found: df8.ini
- 1748:0708 00:20:17.840 msiParams=''
- 1748:0708 00:20:17.840 hexUninstallPassword=''
- 1748:0708 00:20:17.840 This OS is not supported
- 1748:0708 00:20:17.840 no detect
- 1748:0708 00:20:17.840 file found: df9.ini
- 1748:0708 00:20:17.840 msiParams=''
- 1748:0708 00:20:17.840 hexUninstallPassword=''
- 1748:0708 00:20:17.840 no detect
- 1748:0708 00:20:17.856 Searching finished, product detected.
- 1748:0708 00:20:17.856 KLeaner deinitialized
- 1748:0708 00:20:17.856 Stopping shutdown detector...
- 1748:0708 00:20:17.856 Waiting for watch thread stop...
- 1748:070c 00:20:17.856 Watch thread finished
- 1748:0708 00:20:17.856 Watch thread was stopped
- 1748:0738 00:20:34.715 Removing selected product: Kaspersky PURE 3.0 / CRYSTAL.
- 1748:0738 00:20:34.715 ShutdownDetector started watch thread (00000358)
- 1748:073c 00:20:34.715 Watch thread started
- 1748:0738 00:20:34.715 Kaspersky Removal Tool 1.0.603
- 1748:0738 00:20:34.715 KLeaner initialized
- 1748:0738 00:20:34.715 OS Platform = NT, version = 6.3.9600, 64 bit
- 1748:0738 00:20:34.715 OS version ext PlatformId=2 CSDVersion="" SP=0.0 Suite=00000300 ProductType=1 Reserved=0
- 1748:0738 00:20:34.715 TraceSystemInfo: Time ticks=100484 ticks64=100484 idle=792.0625000 kernel=799.7187500 user=2.2968750
- 1748:0738 00:20:34.715 TraceSystemInfo: System oemId=00000009 pageSize=4096 MinAppAddress=00010000 MaxAppAddress=FFFEFFFF ActiveProcessorMask=000000FF NumberOfProcessors=8 ProcessorType=8664 AllocationGranularity=65536 ProcessorLevel=6 ProcessorRevision=15363
- 1748:0738 00:20:34.715 TraceSystemInfo: Memory Load=13 Phys=7198756864/8296615936 PageFile=7252299776/8296615936 Virtual=1961287680/2147352576 AvailExtendedVirtual=0
- 1748:0738 00:20:34.715 TraceSystemInfo: Performance commit(total=254960,limit=2025541,peak=259272 phis(total=2025541,avail=1757509) syscache=80347 kernel(total=50350,paged=29283,nonpaged=21067) page=4096 handles=5153 processes=21 threads=312
- 1748:0738 00:20:34.715 TraceTokenInformation: class=1(User) length=36 [User[Sid=S-1-5-21-4063754582-3048442541-3029454900-1002,Attributes=0]]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=2(Groups) length=344 [GroupCount=14,[Sid=S-1-16-12288,Attributes=60],[Sid=S-1-1-0,Attributes=7],[Sid=S-1-5-114,Attributes=7],[Sid=S-1-5-32-544,Attributes=F],[Sid=S-1-5-32-545,Attributes=7],[Sid=S-1-5-4,Attributes=7],[Sid=S-1-2-1,Attributes=7],[Sid=S-1-5-11,Attributes=7],[Sid=S-1-5-15,Attributes=7],[Sid=S-1-11-96-3623454863-58364-18864-2661722203-1597581903-3005979970-2001990645-2405958475-1199014264-1064271294,Attributes=7],[Sid=S-1-5-113,Attributes=7],[Sid=S-1-5-5-0-125816,Attributes=C0000007],[Sid=S-1-2-0,Attributes=7],[Sid=S-1-5-64-32,Attributes=7]]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=3(Privileges) length=280 [PrivilegeCount=23,[Luid=SeIncreaseQuotaPrivilege,Attributes=0],[Luid=SeSecurityPrivilege,Attributes=0],[Luid=SeTakeOwnershipPrivilege,Attributes=0],[Luid=SeLoadDriverPrivilege,Attributes=0],[Luid=SeSystemProfilePrivilege,Attributes=0],[Luid=SeSystemtimePrivilege,Attributes=0],[Luid=SeProfileSingleProcessPrivilege,Attributes=0],[Luid=SeIncreaseBasePriorityPrivilege,Attributes=0],[Luid=SeCreatePagefilePrivilege,Attributes=0],[Luid=SeBackupPrivilege,Attributes=0],[Luid=SeRestorePrivilege,Attributes=0],[Luid=SeShutdownPrivilege,Attributes=0],[Luid=SeDebugPrivilege,Attributes=0],[Luid=SeSystemEnvironmentPrivilege,Attributes=0],[Luid=SeChangeNotifyPrivilege,Attributes=3],[Luid=SeRemoteShutdownPrivilege,Attributes=0],[Luid=SeUndockPrivilege,Attributes=0],[Luid=SeManageVolumePrivilege,Attributes=0],[Luid=SeImpersonatePrivilege,Attributes=3],[Luid=SeCreateGlobalPrivilege,Attributes=3],[Luid=SeIncreaseWorkingSetPrivilege,Attributes=0],[Luid=SeTimeZonePrivilege,Attributes=0],[Luid=SeCreateSymbolicLinkPrivilege,Attributes=0]]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=4(Owner) length=20 [Owner=S-1-5-32-544]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=5(PrimaryGroup) length=32 [PrimaryGroup=S-1-5-21-4063754582-3048442541-3029454900-1002]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=11(RestrictedSids) length=4 [GroupCount=0]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=12(SessionId) length=4 [1(00000001)]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=14(SessionReference) length=1 GetInfo fail error=87
- 1748:0738 00:20:34.715 TraceTokenInformation: class=15(SandBoxInert) length=4 [0(00000000)]
- 1748:0738 00:20:34.715 TraceTokenInformation: class=16(AuditPolicy) length=1 GetInfo fail error=1314
- 1748:0738 00:20:34.715 KLeaner is looking in C:\Users\user~1\AppData\Local\Temp\jkbasuy1\xsxfr\ for *.ini...
- 1748:0738 00:20:34.715 file found: df0.ini
- 1748:0738 00:20:34.715 msiParams=''
- 1748:0738 00:20:34.715 hexUninstallPassword=''
- 1748:0738 00:20:34.715 This OS is not supported
- 1748:0738 00:20:34.715 no detect
- 1748:0738 00:20:34.715 file found: df1.ini
- 1748:0738 00:20:34.715 msiParams=''
- 1748:0738 00:20:34.715 hexUninstallPassword=''
- 1748:0738 00:20:34.715 This OS is not supported
- 1748:0738 00:20:34.715 no detect
- 1748:0738 00:20:34.715 file found: df10.ini
- 1748:0738 00:20:34.731 msiParams=''
- 1748:0738 00:20:34.731 hexUninstallPassword=''
- 1748:0738 00:20:34.731 no detect
- 1748:0738 00:20:34.731 file found: df11.ini
- 1748:0738 00:20:34.731 msiParams=''
- 1748:0738 00:20:34.731 hexUninstallPassword=''
- 1748:0738 00:20:34.731 no detect
- 1748:0738 00:20:34.731 file found: df12.ini
- 1748:0738 00:20:34.746 msiParams=''
- 1748:0738 00:20:34.746 hexUninstallPassword=''
- 1748:0738 00:20:34.746 no detect
- 1748:0738 00:20:34.746 file found: df13.ini
- 1748:0738 00:20:34.746 msiParams=''
- 1748:0738 00:20:34.746 hexUninstallPassword=''
- 1748:0738 00:20:34.746 no detect
- 1748:0738 00:20:34.746 file found: df14.ini
- 1748:0738 00:20:34.746 msiParams=''
- 1748:0738 00:20:34.746 hexUninstallPassword=''
- 1748:0738 00:20:34.746 This OS is not supported
- 1748:0738 00:20:34.746 no detect
- 1748:0738 00:20:34.746 file found: df15.ini
- 1748:0738 00:20:34.762 msiParams=''
- 1748:0738 00:20:34.762 hexUninstallPassword=''
- 1748:0738 00:20:34.762 This OS is not supported
- 1748:0738 00:20:34.762 no detect
- 1748:0738 00:20:34.762 file found: df16.ini
- 1748:0738 00:20:34.762 msiParams=''
- 1748:0738 00:20:34.762 hexUninstallPassword=''
- 1748:0738 00:20:34.762 Detecting upgrade code '5278159B67B039744A906C974424BF05,MinVersion=0x08000000,MaxVersion=0x09FFFFFF'
- 1748:0738 00:20:34.762 upgrade-code='5278159B67B039744A906C974424BF05' MinVersion=true,134217728 MaxVersion=true,167772159
- 1748:0738 00:20:34.762 RegOpenKeyEx(00000370H\5278159B67B039744A906C974424BF05) failed. Error 2: 系统找不到指定的文件。.
- 1748:0738 00:20:34.762 Fail! get upgrade code key error: err 2
- 1748:0738 00:20:34.762 no detect
- 1748:0738 00:20:34.762 file found: df17.ini
- 1748:0738 00:20:34.762 msiParams=''
- 1748:0738 00:20:34.762 hexUninstallPassword=''
- 1748:0738 00:20:34.762 Detecting upgrade code '5278159B67B039744A906C974424BF05,MinVersion=0x0A000000,MaxVersion=0x0AFFFFFF'
- 1748:0738 00:20:34.762 upgrade-code='5278159B67B039744A906C974424BF05' MinVersion=true,167772160 MaxVersion=true,184549375
- 1748:0738 00:20:34.762 RegOpenKeyEx(00000370H\5278159B67B039744A906C974424BF05) failed. Error 2: 系统找不到指定的文件。.
- 1748:0738 00:20:34.762 Fail! get upgrade code key error: err 2
- 1748:0738 00:20:34.762 no detect
- 1748:0738 00:20:34.762 file found: df18.ini
- 1748:0738 00:20:34.778 msiParams=''
- 1748:0738 00:20:34.778 hexUninstallPassword=''
- 1748:0738 00:20:34.778 no detect
- 1748:0738 00:20:34.778 file found: df19.ini
- 1748:0738 00:20:34.778 msiParams=''
- 1748:0738 00:20:34.778 hexUninstallPassword=''
- 1748:0738 00:20:34.778 found Kaspersky PURE 3.0 / CRYSTAL
- 1748:0738 00:20:34.778 AllowRemove:Invalid CAPTCHA entered
- 1748:0738 00:20:34.778 file found: df2.ini
- 1748:0738 00:20:34.778 msiParams=''
- 1748:0738 00:20:34.778 hexUninstallPassword=''
- 1748:0738 00:20:34.778 no detect
- 1748:0738 00:20:34.778 file found: df20.ini
- 1748:0738 00:20:34.793 msiParams=''
- 1748:0738 00:20:34.793 hexUninstallPassword=''
- 1748:0738 00:20:34.793 This OS is not supported
- 1748:0738 00:20:34.793 no detect
- 1748:0738 00:20:34.793 file found: df21.ini
- 1748:0738 00:20:34.793 msiParams=''
- 1748:0738 00:20:34.793 hexUninstallPassword=''
- 1748:0738 00:20:34.793 This OS is not supported
- 1748:0738 00:20:34.793 no detect
- 1748:0738 00:20:34.793 file found: df22.ini
- 1748:0738 00:20:34.793 msiParams=''
- 1748:0738 00:20:34.793 hexUninstallPassword=''
- 1748:0738 00:20:34.793 no detect
- 1748:0738 00:20:34.793 file found: df23.ini
- 1748:0738 00:20:34.809 msiParams=''
- 1748:0738 00:20:34.809 hexUninstallPassword=''
- 1748:0738 00:20:34.809 no detect
- 1748:0738 00:20:34.809 file found: df24.ini
- 1748:0738 00:20:34.809 msiParams=''
- 1748:0738 00:20:34.809 hexUninstallPassword=''
- 1748:0738 00:20:34.809 no detect
- 1748:0738 00:20:34.809 file found: df25.ini
- 1748:0738 00:20:34.809 msiParams=''
- 1748:0738 00:20:34.809 hexUninstallPassword=''
- 1748:0738 00:20:34.809 no detect
- 1748:0738 00:20:34.809 file found: df26.ini
- 1748:0738 00:20:34.824 msiParams=''
- 1748:0738 00:20:34.824 hexUninstallPassword=''
- 1748:0738 00:20:34.824 no detect
- 1748:0738 00:20:34.824 file found: df27.ini
- 1748:0738 00:20:34.824 msiParams=''
- 1748:0738 00:20:34.824 hexUninstallPassword=''
- 1748:0738 00:20:34.824 This OS is not supported
- 1748:0738 00:20:34.824 no detect
- 1748:0738 00:20:34.824 file found: df3.ini
- 1748:0738 00:20:34.824 msiParams=''
- 1748:0738 00:20:34.824 hexUninstallPassword=''
- 1748:0738 00:20:34.824 This OS is not supported
- 1748:0738 00:20:34.824 no detect
- 1748:0738 00:20:34.824 file found: df4.ini
- 1748:0738 00:20:34.824 msiParams=''
- 1748:0738 00:20:34.824 hexUninstallPassword=''
- 1748:0738 00:20:34.824 This OS is not supported
- 1748:0738 00:20:34.824 no detect
- 1748:0738 00:20:34.824 file found: df5.ini
- 1748:0738 00:20:34.824 msiParams=''
- 1748:0738 00:20:34.824 hexUninstallPassword=''
- 1748:0738 00:20:34.824 This OS is not supported
- 1748:0738 00:20:34.824 no detect
- 1748:0738 00:20:34.824 file found: df6.ini
- 1748:0738 00:20:34.840 msiParams=''
- 1748:0738 00:20:34.840 hexUninstallPassword=''
- 1748:0738 00:20:34.840 This OS is not supported
- 1748:0738 00:20:34.840 no detect
- 1748:0738 00:20:34.840 file found: df7.ini
- 1748:0738 00:20:34.840 msiParams=''
- 1748:0738 00:20:34.840 hexUninstallPassword=''
- 1748:0738 00:20:34.840 no detect
- 1748:0738 00:20:34.840 file found: df8.ini
- 1748:0738 00:20:34.840 msiParams=''
- 1748:0738 00:20:34.840 hexUninstallPassword=''
- 1748:0738 00:20:34.840 This OS is not supported
- 1748:0738 00:20:34.840 no detect
- 1748:0738 00:20:34.840 file found: df9.ini
- 1748:0738 00:20:34.840 msiParams=''
- 1748:0738 00:20:34.840 hexUninstallPassword=''
- 1748:0738 00:20:34.840 no detect
- 1748:0738 00:20:34.840 Remove failed
- 1748:0738 00:20:34.840 KLeaner deinitialized
- 1748:0738 00:20:34.840 Stopping shutdown detector...
- 1748:0738 00:20:34.840 Waiting for watch thread stop...
- 1748:073c 00:20:34.840 Watch thread finished
- 1748:0738 00:20:34.840 Watch thread was stopped
- 1748:0740 00:20:46.903 Removing selected product: Kaspersky PURE 3.0 / CRYSTAL.
- 1748:0740 00:20:46.903 ShutdownDetector started watch thread (00000370)
- 1748:0744 00:20:46.903 Watch thread started
- 1748:0740 00:20:46.903 Kaspersky Removal Tool 1.0.603
- 1748:0740 00:20:46.903 KLeaner initialized
- 1748:0740 00:20:46.903 OS Platform = NT, version = 6.3.9600, 64 bit
- 1748:0740 00:20:46.903 OS version ext PlatformId=2 CSDVersion="" SP=0.0 Suite=00000300 ProductType=1 Reserved=0
- 1748:0740 00:20:46.903 TraceSystemInfo: Time ticks=112671 ticks64=112671 idle=889.2187500 kernel=897.0937500 user=2.4218750
- 1748:0740 00:20:46.903 TraceSystemInfo: System oemId=00000009 pageSize=4096 MinAppAddress=00010000 MaxAppAddress=FFFEFFFF ActiveProcessorMask=000000FF NumberOfProcessors=8 ProcessorType=8664 AllocationGranularity=65536 ProcessorLevel=6 ProcessorRevision=15363
- 1748:0740 00:20:46.903 TraceSystemInfo: Memory Load=13 Phys=7199051776/8296615936 PageFile=7253139456/8296615936 Virtual=1961287680/2147352576 AvailExtendedVirtual=0
- 1748:0740 00:20:46.903 TraceSystemInfo: Performance commit(total=254755,limit=2025541,peak=259272 phis(total=2025541,avail=1757581) syscache=80357 kernel(total=50350,paged=29283,nonpaged=21067) page=4096 handles=5045 processes=21 threads=296
- 1748:0740 00:20:46.903 TraceTokenInformation: class=1(User) length=36 [User[Sid=S-1-5-21-4063754582-3048442541-3029454900-1002,Attributes=0]]
- 1748:0740 00:20:46.903 TraceTokenInformation: class=2(Groups) length=344 [GroupCount=14,[Sid=S-1-16-12288,Attributes=60],[Sid=S-1-1-0,Attributes=7],[Sid=S-1-5-114,Attributes=7],[Sid=S-1-5-32-544,Attributes=F],[Sid=S-1-5-32-545,Attributes=7],[Sid=S-1-5-4,Attributes=7],[Sid=S-1-2-1,Attributes=7],[Sid=S-1-5-11,Attributes=7],[Sid=S-1-5-15,Attributes=7],[Sid=S-1-11-96-3623454863-58364-18864-2661722203-1597581903-3005979970-2001990645-2405958475-1199014264-1064271294,Attributes=7],[Sid=S-1-5-113,Attributes=7],[Sid=S-1-5-5-0-125816,Attributes=C0000007],[Sid=S-1-2-0,Attributes=7],[Sid=S-1-5-64-32,Attributes=7]]
- 1748:0740 00:20:46.918 TraceTokenInformation: class=3(Privileges) length=280 [PrivilegeCount=23,[Luid=SeIncreaseQuotaPrivilege,Attributes=0],[Luid=SeSecurityPrivilege,Attributes=0],[Luid=SeTakeOwnershipPrivilege,Attributes=0],[Luid=SeLoadDriverPrivilege,Attributes=0],[Luid=SeSystemProfilePrivilege,Attributes=0],[Luid=SeSystemtimePrivilege,Attributes=0],[Luid=SeProfileSingleProcessPrivilege,Attributes=0],[Luid=SeIncreaseBasePriorityPrivilege,Attributes=0],[Luid=SeCreatePagefilePrivilege,Attributes=0],[Luid=SeBackupPrivilege,Attributes=0],[Luid=SeRestorePrivilege,Attributes=0],[Luid=SeShutdownPrivilege,Attributes=0],[Luid=SeDebugPrivilege,Attributes=0],[Luid=SeSystemEnvironmentPrivilege,Attributes=0],[Luid=SeChangeNotifyPrivilege,Attributes=3],[Luid=SeRemoteShutdownPrivilege,Attributes=0],[Luid=SeUndockPrivilege,Attributes=0],[Luid=SeManageVolumePrivilege,Attributes=0],[Luid=SeImpersonatePrivilege,Attributes=3],[Luid=SeCreateGlobalPrivilege,Attributes=3],[Luid=SeIncreaseWorkingSetPrivilege,Attributes=0],[Luid=SeTimeZonePrivilege,Attributes=0],[Luid=SeCreateSymbolicLinkPrivilege,Attributes=0]]
- 1748:0740 00:20:46.918 TraceTokenInformation: class=4(Owner) length=20 [Owner=S-1-5-32-544]
- 1748:0740 00:20:46.918 TraceTokenInformation: class=5(PrimaryGroup) length=32 [PrimaryGroup=S-1-5-21-4063754582-3048442541-3029454900-1002]
- 1748:0740 00:20:46.918 TraceTokenInformation: class=11(RestrictedSids) length=4 [GroupCount=0]
- 1748:0740 00:20:46.918 TraceTokenInformation: class=12(SessionId) length=4 [1(00000001)]
- 1748:0740 00:20:46.918 TraceTokenInformation: class=14(SessionReference) length=1 GetInfo fail error=87
- 1748:0740 00:20:46.918 TraceTokenInformation: class=15(SandBoxInert) length=4 [0(00000000)]
- 1748:0740 00:20:46.918 TraceTokenInformation: class=16(AuditPolicy) length=1 GetInfo fail error=1314
- 1748:0740 00:20:46.918 KLeaner is looking in C:\Users\user~1\AppData\Local\Temp\jkbasuy1\xsxfr\ for *.ini...
- 1748:0740 00:20:46.918 file found: df0.ini
- 1748:0740 00:20:46.934 msiParams=''
- 1748:0740 00:20:46.934 hexUninstallPassword=''
- 1748:0740 00:20:46.934 This OS is not supported
- 1748:0740 00:20:46.934 no detect
- 1748:0740 00:20:46.934 file found: df1.ini
- 1748:0740 00:20:46.934 msiParams=''
- 1748:0740 00:20:46.934 hexUninstallPassword=''
- 1748:0740 00:20:46.934 This OS is not supported
- 1748:0740 00:20:46.934 no detect
- 1748:0740 00:20:46.934 file found: df10.ini
- 1748:0740 00:20:46.934 msiParams=''
- 1748:0740 00:20:46.934 hexUninstallPassword=''
- 1748:0740 00:20:46.934 no detect
- 1748:0740 00:20:46.934 file found: df11.ini
- 1748:0740 00:20:46.950 msiParams=''
- 1748:0740 00:20:46.950 hexUninstallPassword=''
- 1748:0740 00:20:46.950 no detect
- 1748:0740 00:20:46.950 file found: df12.ini
- 1748:0740 00:20:46.950 msiParams=''
- 1748:0740 00:20:46.950 hexUninstallPassword=''
- 1748:0740 00:20:46.950 no detect
- 1748:0740 00:20:46.950 file found: df13.ini
- 1748:0740 00:20:46.965 msiParams=''
- 1748:0740 00:20:46.965 hexUninstallPassword=''
- 1748:0740 00:20:46.965 no detect
- 1748:0740 00:20:46.965 file found: df14.ini
- 1748:0740 00:20:46.965 msiParams=''
- 1748:0740 00:20:46.965 hexUninstallPassword=''
- 1748:0740 00:20:46.965 This OS is not supported
- 1748:0740 00:20:46.965 no detect
- 1748:0740 00:20:46.965 file found: df15.ini
- 1748:0740 00:20:46.965 msiParams=''
- 1748:0740 00:20:46.965 hexUninstallPassword=''
- 1748:0740 00:20:46.965 This OS is not supported
- 1748:0740 00:20:46.965 no detect
- 1748:0740 00:20:46.965 file found: df16.ini
- 1748:0740 00:20:46.965 msiParams=''
- 1748:0740 00:20:46.965 hexUninstallPassword=''
- 1748:0740 00:20:46.965 Detecting upgrade code '5278159B67B039744A906C974424BF05,MinVersion=0x08000000,MaxVersion=0x09FFFFFF'
- 1748:0740 00:20:46.965 upgrade-code='5278159B67B039744A906C974424BF05' MinVersion=true,134217728 MaxVersion=true,167772159
- 1748:0740 00:20:46.965 RegOpenKeyEx(0000031CH\5278159B67B039744A906C974424BF05) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:20:46.965 Fail! get upgrade code key error: err 2
- 1748:0740 00:20:46.965 no detect
- 1748:0740 00:20:46.965 file found: df17.ini
- 1748:0740 00:20:46.965 msiParams=''
- 1748:0740 00:20:46.965 hexUninstallPassword=''
- 1748:0740 00:20:46.981 Detecting upgrade code '5278159B67B039744A906C974424BF05,MinVersion=0x0A000000,MaxVersion=0x0AFFFFFF'
- 1748:0740 00:20:46.981 upgrade-code='5278159B67B039744A906C974424BF05' MinVersion=true,167772160 MaxVersion=true,184549375
- 1748:0740 00:20:46.981 RegOpenKeyEx(0000031CH\5278159B67B039744A906C974424BF05) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:20:46.981 Fail! get upgrade code key error: err 2
- 1748:0740 00:20:46.981 no detect
- 1748:0740 00:20:46.981 file found: df18.ini
- 1748:0740 00:20:46.981 msiParams=''
- 1748:0740 00:20:46.981 hexUninstallPassword=''
- 1748:0740 00:20:46.981 no detect
- 1748:0740 00:20:46.981 file found: df19.ini
- 1748:0740 00:20:46.981 msiParams=''
- 1748:0740 00:20:46.981 hexUninstallPassword=''
- 1748:0740 00:20:46.981 found Kaspersky PURE 3.0 / CRYSTAL
- 1748:0740 00:20:46.981 removing...
- 1748:0740 00:20:46.981 TraceSystemInfo: Time ticks=112750 ticks64=112750 idle=889.7343750 kernel=897.6718750 user=2.4687500
- 1748:0740 00:20:46.981 TraceSystemInfo: System oemId=00000009 pageSize=4096 MinAppAddress=00010000 MaxAppAddress=FFFEFFFF ActiveProcessorMask=000000FF NumberOfProcessors=8 ProcessorType=8664 AllocationGranularity=65536 ProcessorLevel=6 ProcessorRevision=15363
- 1748:0740 00:20:46.981 TraceSystemInfo: Memory Load=13 Phys=7198593024/8296615936 PageFile=7252692992/8296615936 Virtual=1961287680/2147352576 AvailExtendedVirtual=0
- 1748:0740 00:20:46.981 TraceSystemInfo: Performance commit(total=254864,limit=2025541,peak=259272 phis(total=2025541,avail=1757469) syscache=80345 kernel(total=50350,paged=29283,nonpaged=21067) page=4096 handles=5049 processes=21 threads=296
- 1748:0740 00:20:46.981 TraceTokenInformation: class=1(User) length=36 [User[Sid=S-1-5-21-4063754582-3048442541-3029454900-1002,Attributes=0]]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=2(Groups) length=344 [GroupCount=14,[Sid=S-1-16-12288,Attributes=60],[Sid=S-1-1-0,Attributes=7],[Sid=S-1-5-114,Attributes=7],[Sid=S-1-5-32-544,Attributes=F],[Sid=S-1-5-32-545,Attributes=7],[Sid=S-1-5-4,Attributes=7],[Sid=S-1-2-1,Attributes=7],[Sid=S-1-5-11,Attributes=7],[Sid=S-1-5-15,Attributes=7],[Sid=S-1-11-96-3623454863-58364-18864-2661722203-1597581903-3005979970-2001990645-2405958475-1199014264-1064271294,Attributes=7],[Sid=S-1-5-113,Attributes=7],[Sid=S-1-5-5-0-125816,Attributes=C0000007],[Sid=S-1-2-0,Attributes=7],[Sid=S-1-5-64-32,Attributes=7]]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=3(Privileges) length=280 [PrivilegeCount=23,[Luid=SeIncreaseQuotaPrivilege,Attributes=0],[Luid=SeSecurityPrivilege,Attributes=0],[Luid=SeTakeOwnershipPrivilege,Attributes=0],[Luid=SeLoadDriverPrivilege,Attributes=0],[Luid=SeSystemProfilePrivilege,Attributes=0],[Luid=SeSystemtimePrivilege,Attributes=0],[Luid=SeProfileSingleProcessPrivilege,Attributes=0],[Luid=SeIncreaseBasePriorityPrivilege,Attributes=0],[Luid=SeCreatePagefilePrivilege,Attributes=0],[Luid=SeBackupPrivilege,Attributes=0],[Luid=SeRestorePrivilege,Attributes=0],[Luid=SeShutdownPrivilege,Attributes=0],[Luid=SeDebugPrivilege,Attributes=0],[Luid=SeSystemEnvironmentPrivilege,Attributes=0],[Luid=SeChangeNotifyPrivilege,Attributes=3],[Luid=SeRemoteShutdownPrivilege,Attributes=0],[Luid=SeUndockPrivilege,Attributes=0],[Luid=SeManageVolumePrivilege,Attributes=0],[Luid=SeImpersonatePrivilege,Attributes=3],[Luid=SeCreateGlobalPrivilege,Attributes=3],[Luid=SeIncreaseWorkingSetPrivilege,Attributes=0],[Luid=SeTimeZonePrivilege,Attributes=0],[Luid=SeCreateSymbolicLinkPrivilege,Attributes=0]]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=4(Owner) length=20 [Owner=S-1-5-32-544]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=5(PrimaryGroup) length=32 [PrimaryGroup=S-1-5-21-4063754582-3048442541-3029454900-1002]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=11(RestrictedSids) length=4 [GroupCount=0]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=12(SessionId) length=4 [1(00000001)]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=14(SessionReference) length=1 GetInfo fail error=87
- 1748:0740 00:20:46.981 TraceTokenInformation: class=15(SandBoxInert) length=4 [0(00000000)]
- 1748:0740 00:20:46.981 TraceTokenInformation: class=16(AuditPolicy) length=1 GetInfo fail error=1314
- 1748:0740 00:20:46.981 adjust_privilege(SeRestorePrivilege)
- 1748:0740 00:20:46.981 adjust_privilege(SeBackupPrivilege)
- 1748:0740 00:20:46.981 adjusting privileges - OK
- 1748:0740 00:20:46.981 Processing section main...
- 1748:0740 00:20:46.981 The 'Kaspersky PURE 3.0 / CRYSTAL' has been detected
- 1748:0740 00:20:46.981 setup_env: 'name' 'Kaspersky PURE 3.0 / CRYSTAL'
- 1748:0740 00:20:46.981 setup_env: action handler not found
- 1748:0740 00:20:46.981 setup_env: 'fullname' 'Kaspersky PURE 3.0 / CRYSTAL'
- 1748:0740 00:20:46.981 setup_env: action handler not found
- 1748:0740 00:20:46.981 setup_env: 'detect-msi' '{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}'
- 1748:0740 00:20:46.981 setup_env: action handler not found
- 1748:0740 00:20:46.981 setup_env: 'type' 'uninstall'
- 1748:0740 00:20:46.981 setup_env: action handler not found
- 1748:0740 00:20:46.981 setup_env: 'os' 'winnt'
- 1748:0740 00:20:46.981 setup_env: action handler not found
- 1748:0740 00:20:46.981 setup_env: 'x64' 'by_os'
- 1748:0740 00:20:46.981 setup_env: action handler not found
- 1748:0740 00:20:46.981 environment string list
- 1748:0740 00:20:46.981 environment: 'ALLUSERSPROFILE=C:\ProgramData'
- 1748:0740 00:20:46.981 environment: 'APPDATA=C:\Users\user\AppData\Roaming'
- 1748:0740 00:20:46.981 environment: 'CommonProgramFiles=C:\Program Files (x86)\Common Files'
- 1748:0740 00:20:46.981 environment: 'CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files'
- 1748:0740 00:20:46.981 environment: 'CommonProgramW6432=C:\Program Files\Common Files'
- 1748:0740 00:20:46.981 environment: 'COMPUTERNAME=TAPEZONE'
- 1748:0740 00:20:46.981 environment: 'ComSpec=C:\WINDOWS\system32\cmd.exe'
- 1748:0740 00:20:46.981 environment: 'configsetroot=C:\WINDOWS\ConfigSetRoot'
- 1748:0740 00:20:46.981 environment: 'FP_NO_HOST_CHECK=NO'
- 1748:0740 00:20:46.981 environment: 'HOMEDRIVE=C:'
- 1748:0740 00:20:46.981 environment: 'HOMEPATH=\Users\user'
- 1748:0740 00:20:46.981 environment: 'LOCALAPPDATA=C:\Users\user\AppData\Local'
- 1748:0740 00:20:46.981 environment: 'LOGONSERVER=\\MicrosoftAccount'
- 1748:0740 00:20:46.981 environment: 'NUMBER_OF_PROCESSORS=8'
- 1748:0740 00:20:46.981 environment: 'OS=Windows_NT'
- 1748:0740 00:20:46.981 environment: 'Path=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\MacType'
- 1748:0740 00:20:46.981 environment: 'PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_ARCHITECTURE=x86'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_ARCHITEW6432=AMD64'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 60 Stepping 3, GenuineIntel'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_LEVEL=6'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_REVISION=3c03'
- 1748:0740 00:20:46.981 environment: 'ProgramData=C:\ProgramData'
- 1748:0740 00:20:46.981 environment: 'ProgramFiles=C:\Program Files (x86)'
- 1748:0740 00:20:46.981 environment: 'ProgramFiles(x86)=C:\Program Files (x86)'
- 1748:0740 00:20:46.981 environment: 'ProgramW6432=C:\Program Files'
- 1748:0740 00:20:46.981 environment: 'PSModulePath=C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\'
- 1748:0740 00:20:46.981 environment: 'PUBLIC=C:\Users\Public'
- 1748:0740 00:20:46.981 environment: 'SAFEBOOT_OPTION=MINIMAL'
- 1748:0740 00:20:46.981 environment: 'SESSIONNAME=Console'
- 1748:0740 00:20:46.981 environment: 'SystemDrive=C:'
- 1748:0740 00:20:46.981 environment: 'SystemRoot=C:\WINDOWS'
- 1748:0740 00:20:46.981 environment: 'TEMP=C:\Users\user~1\AppData\Local\Temp'
- 1748:0740 00:20:46.981 environment: 'TMP=C:\Users\user~1\AppData\Local\Temp'
- 1748:0740 00:20:46.981 environment: 'USERDOMAIN=TAPEZONE'
- 1748:0740 00:20:46.981 environment: 'USERDOMAIN_ROAMINGPROFILE=TAPEZONE'
- 1748:0740 00:20:46.981 environment: 'USERNAME=user'
- 1748:0740 00:20:46.981 environment: 'USERPROFILE=C:\Users\user'
- 1748:0740 00:20:46.981 environment: 'windir=C:\WINDOWS'
- 1748:0740 00:20:46.981 context: RemoveKLSelfDefense=1, x64=1, ProductIdX64=1, selfDefenseAction=0, extensionLevel=0
- 1748:0740 00:20:46.981 Processing section environment...
- 1748:0740 00:20:46.981 setup_env: 'env-string' 'Kaspersky PURE 3.0->DefaultProductName'
- 1748:0740 00:20:46.981 apply_local_context_command: 'local.x64' 'default'
- 1748:0740 00:20:46.981 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE2070D4ED9A914C9C674031B9C58AB\InstallProperties\InstallLocation->InstallerUserDataInstallLocation'
- 1748:0740 00:20:46.981 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9EE2070D4ED9A914C9C674031B9C58AB\ProductName->InstallerProductName'
- 1748:0740 00:20:46.981 apply_local_context_command: 'local.x64' 'false'
- 1748:0740 00:20:46.981 setup_env: 'env-string-expand-utf' '%ProgramFiles%\Kaspersky Lab\Kaspersky PURE 3.0->DefaultProductRoot'
- 1748:0740 00:20:46.981 setup_env: 'env-string-expand-utf' '%ProgramFiles%\Kaspersky Lab\Kaspersky CRYSTAL 3.0->Alt1DefaultProductRoot'
- 1748:0740 00:20:46.981 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData->CommonAppDataDir'
- 1748:0740 00:20:46.981 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData->AppDataFolder'
- 1748:0740 00:20:46.981 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\PURE13\environment\ProductRoot->ProductRootDir'
- 1748:0740 00:20:46.981 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\PURE13\environment\DataRoot->DataRootDir'
- 1748:0740 00:20:46.981 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\PURE13\environment\ProductName->ProductName'
- 1748:0740 00:20:46.981 setup_env: 'env-string-expand-utf' '%CommonProgramFiles%->Kleaner_CommonProgramFiles'
- 1748:0740 00:20:46.981 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE\Path->OutlookPath'
- 1748:0740 00:20:46.981 RegOpenKeyEx(80000002H\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:20:46.981 set_env_registry: query_regkey_value_ex_t fail error=2
- 1748:0740 00:20:46.981 environment string list
- 1748:0740 00:20:46.981 environment: 'ALLUSERSPROFILE=C:\ProgramData'
- 1748:0740 00:20:46.981 environment: 'Alt1DefaultProductRoot=C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0'
- 1748:0740 00:20:46.981 environment: 'APPDATA=C:\Users\user\AppData\Roaming'
- 1748:0740 00:20:46.981 environment: 'AppDataFolder=C:\ProgramData'
- 1748:0740 00:20:46.981 environment: 'CommonAppDataDir=C:\ProgramData'
- 1748:0740 00:20:46.981 environment: 'CommonProgramFiles=C:\Program Files (x86)\Common Files'
- 1748:0740 00:20:46.981 environment: 'CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files'
- 1748:0740 00:20:46.981 environment: 'CommonProgramW6432=C:\Program Files\Common Files'
- 1748:0740 00:20:46.981 environment: 'COMPUTERNAME=TAPEZONE'
- 1748:0740 00:20:46.981 environment: 'ComSpec=C:\WINDOWS\system32\cmd.exe'
- 1748:0740 00:20:46.981 environment: 'configsetroot=C:\WINDOWS\ConfigSetRoot'
- 1748:0740 00:20:46.981 environment: 'DataRootDir=C:\ProgramData\Kaspersky Lab\PURE13'
- 1748:0740 00:20:46.981 environment: 'DefaultProductName=Kaspersky PURE 3.0'
- 1748:0740 00:20:46.981 environment: 'DefaultProductRoot=C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0'
- 1748:0740 00:20:46.981 environment: 'FP_NO_HOST_CHECK=NO'
- 1748:0740 00:20:46.981 environment: 'HOMEDRIVE=C:'
- 1748:0740 00:20:46.981 environment: 'HOMEPATH=\Users\user'
- 1748:0740 00:20:46.981 environment: 'InstallerProductName=Kaspersky PURE 3.0'
- 1748:0740 00:20:46.981 environment: 'Kleaner_CommonProgramFiles=C:\Program Files (x86)\Common Files'
- 1748:0740 00:20:46.981 environment: 'LOCALAPPDATA=C:\Users\user\AppData\Local'
- 1748:0740 00:20:46.981 environment: 'LOGONSERVER=\\MicrosoftAccount'
- 1748:0740 00:20:46.981 environment: 'NUMBER_OF_PROCESSORS=8'
- 1748:0740 00:20:46.981 environment: 'OS=Windows_NT'
- 1748:0740 00:20:46.981 environment: 'Path=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\MacType'
- 1748:0740 00:20:46.981 environment: 'PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_ARCHITECTURE=x86'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_ARCHITEW6432=AMD64'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 60 Stepping 3, GenuineIntel'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_LEVEL=6'
- 1748:0740 00:20:46.981 environment: 'PROCESSOR_REVISION=3c03'
- 1748:0740 00:20:46.981 environment: 'ProductName=Kaspersky PURE 3.0'
- 1748:0740 00:20:46.981 environment: 'ProductRootDir=C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0'
- 1748:0740 00:20:46.981 environment: 'ProgramData=C:\ProgramData'
- 1748:0740 00:20:46.981 environment: 'ProgramFiles=C:\Program Files (x86)'
- 1748:0740 00:20:46.981 environment: 'ProgramFiles(x86)=C:\Program Files (x86)'
- 1748:0740 00:20:46.981 environment: 'ProgramW6432=C:\Program Files'
- 1748:0740 00:20:46.981 environment: 'PSModulePath=C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\'
- 1748:0740 00:20:46.981 environment: 'PUBLIC=C:\Users\Public'
- 1748:0740 00:20:46.981 environment: 'SAFEBOOT_OPTION=MINIMAL'
- 1748:0740 00:20:46.981 environment: 'SESSIONNAME=Console'
- 1748:0740 00:20:46.981 environment: 'SystemDrive=C:'
- 1748:0740 00:20:46.981 environment: 'SystemRoot=C:\WINDOWS'
- 1748:0740 00:20:46.981 environment: 'TEMP=C:\Users\user~1\AppData\Local\Temp'
- 1748:0740 00:20:46.981 environment: 'TMP=C:\Users\user~1\AppData\Local\Temp'
- 1748:0740 00:20:46.981 environment: 'USERDOMAIN=TAPEZONE'
- 1748:0740 00:20:46.981 environment: 'USERDOMAIN_ROAMINGPROFILE=TAPEZONE'
- 1748:0740 00:20:46.981 environment: 'USERNAME=user'
- 1748:0740 00:20:46.981 environment: 'USERPROFILE=C:\Users\user'
- 1748:0740 00:20:46.996 environment: 'windir=C:\WINDOWS'
- 1748:0740 00:20:46.996 Processing section remove...
- 1748:0740 00:20:46.996 remove_self_defence as_installer
- 1748:0740 00:20:46.996 remove_self_protection_as_installer
- 1748:0740 00:20:47.043 returns 0
- 1748:0740 00:20:47.043 remove_self_defence by_fssync
- 1748:0740 00:20:47.043 Loading key data...
- 1748:0740 00:20:47.043 key data (706 bytes) successfully loaded
- 1748:0740 00:20:47.043 removing self-protection using new scheme...
- 1748:0740 00:20:47.043 can't be done, err 0x80070002
- 1748:0740 00:20:47.043 removing self-protection using old scheme...
- 1748:0740 00:20:47.090 can't be done, err 0x80004005
- 1748:0740 00:20:47.090 removing self-protection failed
- 1748:0740 00:20:47.090 Processing section assassinate...
- 1748:0740 00:20:47.090 stopping service "avp"...
- 1748:0740 00:20:47.090 Loading key data...
- 1748:0740 00:20:47.090 key data (706 bytes) successfully loaded
- 1748:0740 00:20:47.090 removing self-protection using new scheme...
- 1748:0740 00:20:47.090 can't be done, err 0x80070002
- 1748:0740 00:20:47.090 removing self-protection using old scheme...
- 1748:0740 00:20:47.090 can't be done, err 0x80004005
- 1748:0740 00:20:47.090 removing self-protection failed
- 1748:0740 00:20:47.090 stopping service "avp"...
- 1748:0740 00:20:47.090 Loading key data...
- 1748:0740 00:20:47.090 key data (706 bytes) successfully loaded
- 1748:0740 00:20:47.090 removing self-protection using new scheme...
- 1748:0740 00:20:47.090 can't be done, err 0x80070002
- 1748:0740 00:20:47.090 removing self-protection using old scheme...
- 1748:0740 00:20:47.106 can't be done, err 0x80004005
- 1748:0740 00:20:47.106 removing self-protection failed
- 1748:0740 00:20:47.106 Processing section assassinate...
- 1748:0740 00:20:47.106 stopping service "avp"...
- 1748:0740 00:20:47.106 Loading key data...
- 1748:0740 00:20:47.106 key data (706 bytes) successfully loaded
- 1748:0740 00:20:47.106 removing self-protection using new scheme...
- 1748:0740 00:20:47.106 can't be done, err 0x80070002
- 1748:0740 00:20:47.106 removing self-protection using old scheme...
- 1748:0740 00:20:47.106 can't be done, err 0x80004005
- 1748:0740 00:20:47.106 removing self-protection failed
- 1748:0740 00:20:47.106 stopping service "avp"...
- 1748:0740 00:20:47.106 Loading key data...
- 1748:0740 00:20:47.106 key data (706 bytes) successfully loaded
- 1748:0740 00:20:47.106 removing self-protection using new scheme...
- 1748:0740 00:20:47.106 can't be done, err 0x80070002
- 1748:0740 00:20:47.106 removing self-protection using old scheme...
- 1748:0740 00:20:47.121 can't be done, err 0x80004005
- 1748:0740 00:20:47.121 removing self-protection failed
- 1748:0740 00:20:47.121 stopping process "avp" with method 0...
- 1748:0740 00:20:47.121 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:20:47.121 Process with name 'avp' not found
- 1748:0740 00:20:47.121 Processing section wait...
- 1748:0740 00:20:47.121 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:20:47.121 Process not found
- 1748:0740 00:20:52.137 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:20:52.137 Process not found
- 1748:0740 00:20:52.137 Processing section assassinate...
- 1748:0740 00:20:52.137 stopping process "avp" with method 0...
- 1748:0740 00:20:52.137 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:20:52.137 Process with name 'avp' not found
- 1748:0740 00:20:52.137 Processing section wait...
- 1748:0740 00:20:52.137 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:20:52.137 Process not found
- 1748:0740 00:20:57.153 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:20:57.153 Process not found
- 1748:0740 00:20:57.153 Processing section assassinate...
- 1748:0740 00:20:57.153 stopping process "avp" with method 0...
- 1748:0740 00:20:57.153 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:20:57.153 Process with name 'avp' not found
- 1748:0740 00:20:57.153 Processing section wait...
- 1748:0740 00:20:57.153 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:20:57.153 Process not found
- 1748:0740 00:21:02.168 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:02.168 Process not found
- 1748:0740 00:21:02.168 Processing section registry...
- 1748:0740 00:21:02.168 apply_local_context_command: 'local.x64' 'false'
- 1748:0740 00:21:02.168 apply_registry: 'local.x64' 'false'
- 1748:0740 00:21:02.168 apply_registry: action handler not found
- 1748:0740 00:21:02.168 apply_registry: 'key' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\PURE13\settings'
- 1748:0740 00:21:02.168 apply_registry: 'value' 'AllowServiceStop'
- 1748:0740 00:21:02.168 apply_registry: 'set-value-dword' '1'
- 1748:0740 00:21:02.168 registry_set_value_dword x64=0 '1'
- 1748:0740 00:21:02.168 registry_set_value_dword success
- 1748:0740 00:21:02.168 Processing section script...
- 1748:0740 00:21:02.168 start script::process
- 1748:0740 00:21:02.168 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 1748:0740 00:21:02.168 OriginalDLL: value missing, err 2
- 1748:0740 00:21:02.168 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 1748:0740 00:21:02.168 OriginalDLL: value missing, err 2
- 1748:0740 00:21:02.168 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 1748:0740 00:21:02.168 OriginalDLL: value missing, err 2
- 1748:0740 00:21:02.168 RegSvr32VbscriptDll
- 1748:0740 00:21:02.200 RegSvr32VbscriptDll CreateProcess ret=1 code=0
- 1748:0740 00:21:02.200 RegSvr32VbscriptDll WaitProcess h=0x000002BC pid=1996
- 1748:0740 00:21:02.325 RegSvr32VbscriptDll WaitProcess ret=0
- 1748:0740 00:21:02.325 extracting resource to 'C:\Users\user~1\AppData\Local\Temp\actF45E.tmp'...
- 1748:0740 00:21:02.637 Resource (396800 bytes) successfully dumped
- 1748:0740 00:21:02.637 cmdline: '"C:\Users\user~1\AppData\Local\Temp\actF45E.tmp" remove vbs "param"'
- 1748:0740 00:21:02.637 running utility...
- 1748:0740 00:21:02.934 utility finished with exit code: 2
- 1748:0740 00:21:02.934 ------Utility Stdout v ---
- 2004:07d8 00:21:02.872 64-bit utility started, params: 'remove vbs param'
- 2004:07d8 00:21:02.872 Command detected: restore original DLLs for VBS
- 2004:07d8 00:21:02.872 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 2004:07d8 00:21:02.872 OriginalDLL: value missing, err 2
- 2004:07d8 00:21:02.872 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 2004:07d8 00:21:02.872 OriginalDLL: value missing, err 2
- 2004:07d8 00:21:02.872 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 2004:07d8 00:21:02.872 OriginalDLL: value missing, err 2
- 2004:07d8 00:21:02.872 RegSvr32VbscriptDll
- 2004:07d8 00:21:02.903 RegSvr32VbscriptDll CreateProcess ret=1 code=0
- 2004:07d8 00:21:02.903 RegSvr32VbscriptDll WaitProcess h=0x000000D8 pid=2028
- 2004:07d8 00:21:02.934 RegSvr32VbscriptDll WaitProcess ret=0
- 2004:07d8 00:21:02.934 64-bit utility finished, return code = 2
- 1748:0740 00:21:02.934 ------Utility Stdout ^ ---
- 1748:0740 00:21:02.934 Utility Stderr is empty
- 1748:0740 00:21:02.934 Module.Init(cleanapi.dll=00000000)
- 1748:0740 00:21:02.934 creating kleaner host object...
- 1748:0740 00:21:02.981 creating ActiveScriptSite...
- 1748:0740 00:21:03.106 parsing script...
- 1748:0740 00:21:03.106 execute script...
- 1748:0740 00:21:03.184 Check InstallLocation
- 1748:0740 00:21:03.184 Try use ProductRootDir='C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0'
- 1748:0740 00:21:03.184 InstallLocation: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0
- 1748:0740 00:21:03.247 AVPRunner: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
- 1748:0740 00:21:03.247 script execution finished
- 1748:0740 00:21:03.247 end script::process
- 1748:0740 00:21:03.247 Processing section execute...
- 1748:0740 00:21:03.247 apply_local_context_command: 'local.x64' 'false'
- 1748:0740 00:21:03.247 undefined run command
- 1748:0740 00:21:03.247 executing command line: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe -e
- 1748:0740 00:21:03.434 executed successfully, return code 0
- 1748:0740 00:21:03.434 Processing section wait...
- 1748:0740 00:21:03.434 waiting process-close "runner_avp.exe" 120 seconds...
- 1748:0740 00:21:03.434 Process not found
- 1748:0740 00:21:08.450 waiting process-close "runner_avp.exe" 120 seconds...
- 1748:0740 00:21:08.450 Process not found
- 1748:0740 00:21:08.450 Processing section assassinate...
- 1748:0740 00:21:08.450 stopping service "avp"...
- 1748:0740 00:21:08.450 Loading key data...
- 1748:0740 00:21:08.450 key data (706 bytes) successfully loaded
- 1748:0740 00:21:08.450 removing self-protection using new scheme...
- 1748:0740 00:21:08.481 can't be done, err 0x80070002
- 1748:0740 00:21:08.481 removing self-protection using old scheme...
- 1748:0740 00:21:08.481 can't be done, err 0x80004005
- 1748:0740 00:21:08.481 removing self-protection failed
- 1748:0740 00:21:08.481 stopping service "avp"...
- 1748:0740 00:21:08.481 Loading key data...
- 1748:0740 00:21:08.481 key data (706 bytes) successfully loaded
- 1748:0740 00:21:08.481 removing self-protection using new scheme...
- 1748:0740 00:21:08.481 can't be done, err 0x80070002
- 1748:0740 00:21:08.481 removing self-protection using old scheme...
- 1748:0740 00:21:08.481 can't be done, err 0x80004005
- 1748:0740 00:21:08.497 removing self-protection failed
- 1748:0740 00:21:08.497 stopping process "avp" with method 0...
- 1748:0740 00:21:08.497 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:21:08.497 Process with name 'avp' not found
- 1748:0740 00:21:08.497 Processing section wait...
- 1748:0740 00:21:08.497 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:08.497 Process not found
- 1748:0740 00:21:13.512 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:13.512 Process not found
- 1748:0740 00:21:13.512 Processing section assassinate...
- 1748:0740 00:21:13.512 stopping process "avp" with method 0...
- 1748:0740 00:21:13.512 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:21:13.512 Process with name 'avp' not found
- 1748:0740 00:21:13.512 Processing section wait...
- 1748:0740 00:21:13.512 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:13.512 Process not found
- 1748:0740 00:21:18.528 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:18.528 Process not found
- 1748:0740 00:21:18.528 Processing section assassinate...
- 1748:0740 00:21:18.528 stopping process "avp" with method 0...
- 1748:0740 00:21:18.528 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:21:18.528 Process with name 'avp' not found
- 1748:0740 00:21:18.528 Processing section wait...
- 1748:0740 00:21:18.528 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:18.528 Process not found
- 1748:0740 00:21:23.544 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:23.544 Process not found
- 1748:0740 00:21:23.544 Processing section script...
- 1748:0740 00:21:23.544 start script::process
- 1748:0740 00:21:23.544 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 1748:0740 00:21:23.544 OriginalDLL: value missing, err 2
- 1748:0740 00:21:23.544 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 1748:0740 00:21:23.544 OriginalDLL: value missing, err 2
- 1748:0740 00:21:23.544 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 1748:0740 00:21:23.544 OriginalDLL: value missing, err 2
- 1748:0740 00:21:23.544 RegSvr32VbscriptDll
- 1748:0740 00:21:23.544 RegSvr32VbscriptDll CreateProcess ret=1 code=0
- 1748:0740 00:21:23.544 RegSvr32VbscriptDll WaitProcess h=0x00000418 pid=1004
- 1748:0740 00:21:23.544 RegSvr32VbscriptDll WaitProcess ret=0
- 1748:0740 00:21:23.544 cmdline: '"C:\Users\u~1\AppData\Local\Temp\actF45E.tmp" remove vbs "param"'
- 1748:0740 00:21:23.544 running utility...
- 1748:0740 00:21:23.559 utility finished with exit code: 2
- 1748:0740 00:21:23.559 ------Utility Stdout v ---
- 384:0184 00:21:23.559 64-bit utility started, params: 'remove vbs param'
- 384:0184 00:21:23.559 Command detected: restore original DLLs for VBS
- 384:0184 00:21:23.559 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 384:0184 00:21:23.559 OriginalDLL: value missing, err 2
- 384:0184 00:21:23.559 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 384:0184 00:21:23.559 OriginalDLL: value missing, err 2
- 384:0184 00:21:23.559 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 384:0184 00:21:23.559 OriginalDLL: value missing, err 2
- 384:0184 00:21:23.559 RegSvr32VbscriptDll
- 384:0184 00:21:23.559 RegSvr32VbscriptDll CreateProcess ret=1 code=0
- 384:0184 00:21:23.559 RegSvr32VbscriptDll WaitProcess h=0x000000C4 pid=836
- 384:0184 00:21:23.559 RegSvr32VbscriptDll WaitProcess ret=0
- 384:0184 00:21:23.559 64-bit utility finished, return code = 2
- 1748:0740 00:21:23.559 ------Utility Stdout ^ ---
- 1748:0740 00:21:23.559 Utility Stderr is empty
- 1748:0740 00:21:23.559 creating kleaner host object...
- 1748:0740 00:21:23.559 creating ActiveScriptSite...
- 1748:0740 00:21:23.575 parsing script...
- 1748:0740 00:21:23.575 execute script...
- 1748:0740 00:21:23.997 ->Script Begin
- 1748:0740 00:21:23.997 (+) SEARCHING NECESSARY DIRECTORIES
- 1748:0740 00:21:24.012 RootFolder: C:\Program Files (x86)\Kaspersky Lab
- 1748:0740 00:21:24.012 Bases: C:\ProgramData\Kaspersky Lab\PURE13
- 1748:0740 00:21:24.012 BasesRoot: C:\ProgramData\Kaspersky Lab
- 1748:0740 00:21:24.012 MainExePath: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
- 1748:0740 00:21:24.012 ProductName: Kaspersky PURE 3.0
- 1748:0740 00:21:24.012 CommonProgs: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
- 1748:0740 00:21:24.012 ProgramsFolder: C:\Users\u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
- 1748:0740 00:21:24.247 FirefoxLocation: F:\Sequence 1\firefox
- 1748:0740 00:21:24.247 FirefoxPlugin: F:\Sequence 1\firefox\extensions\linkfilter@kaspersky.ru
- 1748:0740 00:21:24.247 Password Manager Location: C:\Users\u\AppData\Roaming\Kaspersky Lab
- 1748:0740 00:21:24.247 Crypto Storage location: C:\Program Files\Common Files\InfoWatch\CryptoStorage
- 1748:0740 00:21:24.247 Crypto Storage Root location: C:\Program Files\Common Files\InfoWatch
- 1748:0740 00:21:24.247 (+) SEARCH KLIM
- 1748:0740 00:21:24.247 Klim6 found
- 1748:0740 00:21:24.247 +++++ KAVREMOVER IN PROCESS +++++
- 1748:0740 00:21:24.247 ->> Try to write to AllowServiceStop
- 1748:0740 00:21:24.262 NOW!!! SOFTWARE\KasperskyLab\protected\PURE13\settings contain: 1
- 1748:0740 00:21:24.262 ->> Try to create environment variable with path to avp.exe
- 1748:0740 00:21:24.262 ->> Create environment variable exec_avp=
- 1748:0740 00:21:24.262 ->> Execute ../avp.exe -e
- 1748:0740 00:21:24.262 Processing section execute_avp...
- 1748:0740 00:21:24.262 Calling 64-bit util for 'run' '%exec_avp% -e' action...
- 1748:0740 00:21:24.262 cmdline: '"C:\Users\u~1\AppData\Local\Temp\actF45E.tmp" run run-cmd "%exec_avp% -e"'
- 1748:0740 00:21:24.262 running utility...
- 1748:0740 00:21:24.262 utility finished with exit code: 2
- 1748:0740 00:21:24.262 ------Utility Stdout v ---
- 400:05ac 00:21:24.262 64-bit utility started, params: 'run run-cmd %exec_avp% -e'
- 400:05ac 00:21:24.262 Command detected: run-cmd '%exec_avp% -e'
- 400:05ac 00:21:24.262 executing command line: %exec_avp% -e
- 400:05ac 00:21:24.262 failed to execute, error = 2
- 400:05ac 00:21:24.262 64-bit utility finished, return code = 2
- 1748:0740 00:21:24.262 ------Utility Stdout ^ ---
- 1748:0740 00:21:24.262 Utility Stderr is empty
- 1748:0740 00:21:24.262 Command was not executed
- 1748:0740 00:21:24.262 Processing section runner_avp_wait...
- 1748:0740 00:21:24.262 waiting process-close "runner_avp.exe" 120 seconds...
- 1748:0740 00:21:24.262 Process not found
- 1748:0740 00:21:29.278 waiting process-close "runner_avp.exe" 120 seconds...
- 1748:0740 00:21:29.278 Process not found
- 1748:0740 00:21:29.278 ->> Stopping processes and service avp
- 1748:0740 00:21:29.278 Processing section assassinate_termavp...
- 1748:0740 00:21:29.278 stopping service "avp"...
- 1748:0740 00:21:29.278 Loading key data...
- 1748:0740 00:21:29.278 key data (706 bytes) successfully loaded
- 1748:0740 00:21:29.278 removing self-protection using new scheme...
- 1748:0740 00:21:29.278 can't be done, err 0x80070002
- 1748:0740 00:21:29.278 removing self-protection using old scheme...
- 1748:0740 00:21:29.278 can't be done, err 0x80004005
- 1748:0740 00:21:29.278 removing self-protection failed
- 1748:0740 00:21:29.278 stopping service "avp"...
- 1748:0740 00:21:29.278 Loading key data...
- 1748:0740 00:21:29.278 key data (706 bytes) successfully loaded
- 1748:0740 00:21:29.278 removing self-protection using new scheme...
- 1748:0740 00:21:29.294 can't be done, err 0x80070002
- 1748:0740 00:21:29.294 removing self-protection using old scheme...
- 1748:0740 00:21:29.294 can't be done, err 0x80004005
- 1748:0740 00:21:29.294 removing self-protection failed
- 1748:0740 00:21:29.294 stopping process "runner_avp" with method 0...
- 1748:0740 00:21:29.294 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:21:29.294 Process with name 'runner_avp' not found
- 1748:0740 00:21:29.294 stopping process "avp" with method 0...
- 1748:0740 00:21:29.294 adjust_privilege(SeDebugPrivilege)
- 1748:0740 00:21:29.294 Process with name 'avp' not found
- 1748:0740 00:21:29.294 Processing section assassinate_termavp_wait...
- 1748:0740 00:21:29.294 waiting process-close "runner_avp.exe" 120 seconds...
- 1748:0740 00:21:29.294 Process not found
- 1748:0740 00:21:29.294 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:29.294 Process not found
- 1748:0740 00:21:34.309 waiting process-close "runner_avp.exe" 120 seconds...
- 1748:0740 00:21:34.309 Process not found
- 1748:0740 00:21:34.309 waiting process-close "avp.exe" 120 seconds...
- 1748:0740 00:21:34.309 Process not found
- 1748:0740 00:21:34.309 Processing section preuninstall_clean_users...
- 1748:0740 00:21:34.309 [reg_users] begin
- 1748:0740 00:21:34.309 Adding hive: .DEFAULT
- 1748:0740 00:21:34.309 Adding hive: S-1-5-19
- 1748:0740 00:21:34.309 Adding hive: S-1-5-20
- 1748:0740 00:21:34.309 Adding hive: S-1-5-21-4063754582-3048442541-3029454900-1002
- 1748:0740 00:21:34.309 Adding hive: S-1-5-18
- 1748:0740 00:21:34.403 RegLoadKey(C:\Users\All Users\ntuser.dat): ok
- 1748:0740 00:21:34.481 RegLoadKey(C:\Users\Default\ntuser.dat): ok
- 1748:0740 00:21:34.481 RegLoadKey(C:\Users\Default User\ntuser.dat): error 32
- 1748:0740 00:21:34.575 RegLoadKey(C:\Users\Default.migrated\ntuser.dat): ok
- 1748:0740 00:21:34.622 RegLoadKey(C:\Users\Public\ntuser.dat): ok
- 1748:0740 00:21:34.622 RegLoadKey(C:\Users\u\ntuser.dat): error 32
- 1748:0740 00:21:34.716 RegLoadKey(C:\Users\UpdatusUser\ntuser.dat): ok
- 1748:0740 00:21:34.716 remove_file_registry_link x64=1 'HKEY_USERS\.DEFAULT\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.716 RegOpenKeyEx(80000003H\.DEFAULT\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.716 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.716 remove_file_registry_link x64=1 'HKEY_USERS\S-1-5-19\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.716 RegOpenKeyEx(80000003H\S-1-5-19\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.716 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.716 remove_file_registry_link x64=1 'HKEY_USERS\S-1-5-20\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.716 RegOpenKeyEx(80000003H\S-1-5-20\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.716 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.716 remove_file_registry_link x64=1 'HKEY_USERS\S-1-5-21-4063754582-3048442541-3029454900-1002\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.716 value size=84 type=1
- 1748:0740 00:21:34.716 value 'C:\Users\u\Desktop\Safe Money.lnk'
- 1748:0740 00:21:34.716 delete filename 'C:\Users\u\Desktop\Safe Money.lnk'
- 1748:0740 00:21:34.716 warning: file 'C:\Users\u\Desktop\Safe Money.lnk' not exist
- 1748:0740 00:21:34.716 remove_file_registry_link x64=1 'HKEY_USERS\S-1-5-18\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.716 RegOpenKeyEx(80000003H\S-1-5-18\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.716 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.716 remove_file_registry_link x64=1 'HKEY_USERS\kleaner_0\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.716 RegOpenKeyEx(80000003H\kleaner_0\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.716 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.716 remove_file_registry_link x64=1 'HKEY_USERS\kleaner_1\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.716 RegOpenKeyEx(80000003H\kleaner_1\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.716 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.731 remove_file_registry_link x64=1 'HKEY_USERS\kleaner_2\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.731 RegOpenKeyEx(80000003H\kleaner_2\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.731 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.731 remove_file_registry_link x64=1 'HKEY_USERS\kleaner_3\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.731 RegOpenKeyEx(80000003H\kleaner_3\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.731 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.731 remove_file_registry_link x64=1 'HKEY_USERS\kleaner_4\Software\KasperskyLab\protected\PURE13\SafeBanking\LnkName'
- 1748:0740 00:21:34.731 RegOpenKeyEx(80000003H\kleaner_4\Software\KasperskyLab\protected\PURE13\SafeBanking) failed. Error 2: 系统找不到指定的文件。.
- 1748:0740 00:21:34.731 query_regkey_value_ex_w fail winerr=2
- 1748:0740 00:21:34.731 RegUnLoadKey(kleaner_0): 0
- 1748:0740 00:21:34.731 RegUnLoadKey(kleaner_1): 0
- 1748:0740 00:21:34.747 RegUnLoadKey(kleaner_2): 0
- 1748:0740 00:21:34.747 RegUnLoadKey(kleaner_3): 0
- 1748:0740 00:21:34.747 RegUnLoadKey(kleaner_4): 0
- 1748:0740 00:21:34.747 ->> Unregister dlls before msiexec
- 1748:0740 00:21:34.747 Processing section execute_before_msi...
- 1748:0740 00:21:34.747 Calling 64-bit util for 'run' 'regsvr32.exe /u /s "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\mcouas.dll"' action...
- 1748:0740 00:21:34.747 cmdline: '"C:\Users\u~1\AppData\Local\Temp\actF45E.tmp" run run-cmd "regsvr32.exe /u /s "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\mcouas.dll""'
- 1748:0740 00:21:34.747 running utility...
- 1748:0740 00:21:34.919 utility finished with exit code: 0
- 1748:0740 00:21:34.919 ------Utility Stdout v ---
- 1392:0584 00:21:34.763 64-bit utility started, params: 'run run-cmd regsvr32.exe /u /s "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\mcouas.dll"'
- 1392:0584 00:21:34.763 Command detected: run-cmd 'regsvr32.exe /u /s "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\mcouas.dll"'
- 1392:0584 00:21:34.763 executing command line: regsvr32.exe /u /s "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\mcouas.dll"
- 1392:0584 00:21:34.919 executed successfully, return code 0
- 1392:0584 00:21:34.919 64-bit utility finished, return code = 0
- 1748:0740 00:21:34.919 ------Utility Stdout ^ ---
- 1748:0740 00:21:34.919 Utility Stderr is empty
- 1748:0740 00:21:34.919 Command executed
- 1748:0740 00:21:34.919 Calling 64-bit util for 'run' '"C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\stpass.exe" /uninstall /removesettings' action...
- 1748:0740 00:21:34.919 cmdline: '"C:\Users\u~1\AppData\Local\Temp\actF45E.tmp" run run-cmd ""C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\stpass.exe" /uninstall /removesettings"'
- 1748:0740 00:21:34.919 running utility...
复制代码 |