Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen9.57065

Добавлен в вирусную базу Dr.Web: 2020-07-07

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Модифицирует следующие ключи реестра
  • [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kxesc' = '"%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe" -autorun'
Создает следующие сервисы
  • [<HKLM>\System\CurrentControlSet\Services\kxescore] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\kxescore] 'ImagePath' = '"%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe" /service kxescore'
Изменения в файловой системе
Создает следующие файлы
  • %TEMP%\jcqgx.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2wsprotect64.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwhcommonpop.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kweibotool.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kupdata.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftpurifier.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftmgrproxy.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftmgr.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kslaunchex.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ks2launch.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksetupwiz.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kscan.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krecycle.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\knetbuysecuritydetector.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kismain.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kis2live.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kintercept.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kinst.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdrvmgr.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdf.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcmpp.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcleaner.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcddltool.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavlog2.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore_sp.xcf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kset.vdb
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\uplive.svr
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\wenduji.skin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\kongqizhiliang.skin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\tianshizhiyi.skin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxe2score.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxe2tray.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2isfdpro64.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\operation\cas\kinfoc.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\khistory.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\khandler.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kfloatwin.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kfloatmain.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcdetect.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\keasyipcn.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdgui2opt.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdgui2.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdefendpop.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcmppinvoker.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kclearpanel.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcctrl.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kismain.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kbootopt.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kbootacc.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kavquara.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavmenu64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavmenu.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavevent.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kadblock.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\jsonv6.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\defendmon.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\adintercore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\uni0nst.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\rcmdhelper64.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\rcmdhelper.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcleaner.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kislog.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\dudubao.skin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\jijian.skin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\lpolicy.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsu.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwnp.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kunioncfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kuefreq\kuehead.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kuefreq\kuefreq.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kswitch.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksoft_category.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksoftmgrun.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksm3rdex.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksfilter.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kseta.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\config\ksesysfiles.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\krcmdui.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krcmddb.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\krcmddata.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kqsccfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kpretend.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kpopdata.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kpld.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kplc.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kpersonacfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kguidcfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kexam_br_guard.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdh.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\operation\cas\kctrl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\netbank.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\kfxspring.skin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\clearplugin\plugin.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\productinfo.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\safepatch.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\clearplugin\plugin.nlb
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rule.krf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\krmcdm.krf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\denyip.krf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxeksgpid.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwifitool.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kvmpid2.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\khackfix.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcommonpid.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavpid.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\space.dubatheme
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\sea.dubatheme
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\newyear.dubatheme
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\merry.dubatheme
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\operation\cas\kfmt.datx
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\winesystem001.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\whiteurl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\config\userinterconf.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\upcfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\system64.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\system.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\spdupcfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\softpurify.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\softicon.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\se.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\safeurl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\sp3a.nlb
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\duba123ie.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\klengine.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksskrpr.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\zlib1.dll
  • <DRIVERS>\ksapi_ev.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi_ev.sys
  • <DRIVERS>\ksapi64_ev.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi64_ev.sys
  • <DRIVERS>\ksapi64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi64.sys
  • <DRIVERS>\ksapi.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi.sys
  • <DRIVERS>\kisnetm_ev.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm_ev.sys
  • <DRIVERS>\kisnetmxp.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetmxp.sys
  • <DRIVERS>\kisnetm64_ev.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm64_ev.sys
  • <DRIVERS>\kisnetm64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm64.sys
  • <DRIVERS>\kisnetm.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm.sys
  • <DRIVERS>\kisknl_ev.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kisknl_ev.sys
  • <DRIVERS>\kisknl64_ev.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kisknl64_ev.sys
  • <DRIVERS>\kisknl64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kisknl64.sys
  • <DRIVERS>\kisknl.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kisknl.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\1.jpg
  • <DRIVERS>\ksskrpr.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\3.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\wfs.dll
  • %PROGRAMDATA%\kingsoft\kis\kws\urlcache.dat
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020070620200707\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\desktop.ini
  • %PROGRAMDATA%\kingsoft\kis\kich\3954-728d3f04-5f03e633-37a.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatwinsetting.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.log
  • %PROGRAMDATA%\microsoft\windows\start menu\programs\金山毒霸\访问官方网站.lnk
  • %PROGRAMDATA%\microsoft\windows\start menu\programs\金山毒霸\卸载金山毒霸.lnk
  • %PROGRAMDATA%\microsoft\windows\start menu\programs\金山毒霸\金山毒霸.lnk
  • C:\users\public\desktop\软件管家.lnk
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kluaengine.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsui64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsui.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsprotect64.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kswebshield.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kshmpg.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ks3rdhmpg64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ks3rdhmpg32.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ks3rdhmpg.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kisfdpro64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\5.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\4.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\2.jpg
  • %PROGRAMDATA%\kingsoft\ksbw\kns2.che
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\sqlite.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\scom.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kshighvaluesp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksesscan.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kseescan.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksdectrl.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\ksdecs.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kscanner.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksbwdet2.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2s3rdhmpg64.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2s3rdhmpg32.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2s3rdhmpg.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krcmdutils.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krcmdui.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krcmdengine.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krcmdbase.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpopsvr.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpopinterengine.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpopclt.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpopcenter.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpersona.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpassport.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\knpescanner.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\knetworkpanel.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kmonstat.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kmctrl.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2shmpg.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kshmpgext.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kskinmgr.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kseutil.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftdefendpop.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\msvcr80.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyprot.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\msvcp80.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\lblocker.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\lbhelper.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kxesansp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxereg.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxecore\kxecore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxebscsp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxebase.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2wsui64.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2wsui.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwssp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\karchive.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\netmodeconfig.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwhrequestor.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktrashscanex.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktrashscan.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktoolupd.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksysopteng.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kswscxex.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2swebshield.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kstools.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksscore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksreng3.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kspupwnd.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftpurifyengine.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftmgrengine.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kupdatesp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kuidsrv.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecore.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaearchb.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaearcha.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\dynamicctrl\hotfuncentrance_sea.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_close_antivir.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_bobo_new.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_bobo.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_baofeng.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_baidushurufa.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2roundiconthemegameicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2roundiconthemecmnicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2roundiconthemecmnbtn.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2roundiconcheetan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\qq_pcmgr_rcmd_subicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\qq_pcmgr_rcmd.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\pps_rcmd_subicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\pps_rcmd_mainicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\pop.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\phonehelper_subicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\logo_player.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\lockpage.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\kongqizhiliang_skin_img.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\kfxspring_skin_imgex.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\kfxspring_skin_img.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\kdesk_logo.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\jijian_skin_img.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\img_data_revert.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\img_btn_rcmd_orange.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\img_btn_rcmd_green.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\dynamicctrl\hotfuncentrance_space.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\dynamicctrl\hotfuncentrance_merry.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_gamebox2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_gamepop_icon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_icon_sub_qqgame.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_juhuasuan_3_8.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_realtimeopt_green_btn.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_realtimeopt_gameicon_bird.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_qq_browser.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_qidou.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_panda_notes.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_taobao1212_test1_sub3.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_taobao1212_test1_sub2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_taobao1212_test1_sub1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_taobao1212_test1_main.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_qiangpiao_sub3.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_qiangpiao_sub2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_qiangpiao_sub1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_qiangpiao_main.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_loan_bootopt.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_happy_notes.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_calendar_subicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_normal_calendar_icon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_newwifi.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_kugou.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_kuaikuaikantu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_kspeeder.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_kphonehelper_small_icon_fun.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_kphonehelper_small_icon_app.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_kdesk.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_kcleaner_deep_clean.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_juhuasuan_3_8_boot.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_realtimeopt_green_btn2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\dynamicctrl\hotfuncentrance_newyear.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\dynamicctrl\hotfuncentrance_default.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\autorunkxetray_icon.png
  • %TEMP%\kantivirus\~12967b\install_res\511.png
  • %TEMP%\kantivirus\~12967b\install_res\510.png
  • %TEMP%\kantivirus\~12967b\install_res\509.png
  • %TEMP%\kantivirus\~12967b\install_res\508.png
  • %TEMP%\kantivirus\~12967b\install_res\507.png
  • %TEMP%\kantivirus\~12967b\install_res\506.png
  • %TEMP%\kantivirus\~12967b\install_res\504.png
  • %TEMP%\kantivirus\~12967b\install_res\503.png
  • %TEMP%\kantivirus\~12967b\install_res\502.png
  • %TEMP%\kantivirus\~12967b\install_res\501.png
  • %TEMP%\kantivirus\~12967b\install_res\5.png
  • %TEMP%\kantivirus\~12967b\install_res\4.png
  • %TEMP%\kantivirus\~12967b\install_res\110.png
  • %TEMP%\kantivirus\~12967b\install_res\3.jpg
  • %TEMP%\kantivirus\~12967b\install_res\2.jpg
  • %TEMP%\kantivirus\~12967b\install_res\1.jpg
  • %PROGRAMDATA%\kingsoft\kis\hg.dat
  • %TEMP%\kdb_semrjgj.dll
  • %TEMP%\kinst.log
  • %TEMP%\install_res\installconfig.ini
  • %TEMP%\install_res\6002.xml
  • %TEMP%\install_res\6001.xml
  • %TEMP%\install_res\6000.xml
  • %TEMP%\install_res\soft.ico
  • %TEMP%\install_res\110.png
  • %TEMP%\install_res\100.png
  • %TEMP%\kantivirus\~12967b\install_res\514.png
  • %TEMP%\kantivirus\~12967b\install_res\515.png
  • %TEMP%\kantivirus\~12967b\install_res\512.png
  • %TEMP%\kantivirus\~12967b\install_res\516.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\haohuojingxuan-taobao.png
  • %TEMP%\kantivirus\~12967b\install_res\517.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\forbidmobile.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\dudubao_skin_img.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\double11_sublogos2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\double11_sublogoh2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\double11_sublogoc2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\double11_speedpop3.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\double11_mainlogo1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\defaultshrink_skin_img.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\dbetm_skin_imgex.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\computer_doctor.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\computer_acc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\chaodijiage-taobao.png
  • %PROGRAMDATA%\kingsoft\kis\kws\dfcache.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_realtimeopt_orange_btn.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\share\kfxspring.gif
  • %PROGRAMDATA%\nmlist.ini
  • %TEMP%\kdbcihelper.exe
  • %PROGRAMDATA%\installrename.dat
  • %PROGRAMDATA%\dbazdk02.dat
  • %TEMP%\kantivirus\~12967b\installrename_def.dat
  • %TEMP%\kantivirus\~12967b\setup.xml
  • %TEMP%\kantivirus\~12967b\product.xml
  • %TEMP%\kantivirus\~12967b\ksoft.xml
  • %TEMP%\kantivirus\~12967b\clear_i.xml
  • %TEMP%\kantivirus\~12967b\install_res\201.bmp
  • %TEMP%\kantivirus\~12967b\install_res\200.bmp
  • %TEMP%\kantivirus\~12967b\install_res\518.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\autorunkxetray_subicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kslaunch.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_realtimeopt_tianmao_icon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\skin_merry.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_main.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\scanctrl.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\scancfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\quarantine.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\push_msg_city_list.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcdpt\scene\productcmpp.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\mempopscene.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcdpt\scene\loopp.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\litecommoncfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kswitchlist.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksscfgx.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksrengurl.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kshmpg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksedset.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksedset.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksecfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksbwdt.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kismain.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\khistory.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kdock.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kcommon.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecore.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\dynamicctrl\hotfuncentrance.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\gamemode\floatwingamemode.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\deheurcfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\config.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\broplugver.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\scriptconfig.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\config\adintercfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\shrink_skin_config.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\signs.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\bredirect.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kadblock\kadblockrule.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kaccclear.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\inject.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\softicon\softicon32\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\softicon\softicon48\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\gamesdb_dc_mini.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\fysign.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\fnsign.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\deswitch.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\delaydownloader.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\decommon.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\config3a.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\cleanlist.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\bdscancg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_gamebox1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\antilib.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\config\adinterrule.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\recommendctrl.config
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\liectrl.config
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\cloudctrl.config
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\bro.cfg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\vinfo.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninsthvuhs.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\uninstallcfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\stuptswarntp.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\skinconfig.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcdpt\selfdetect.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_weibo.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_duba.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_bbs.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\skin_newyear.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\scan_virus.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\reinstall_duba.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_youku.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_wifibaby.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_olympic_realtime.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_olympic_normal.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_olympic_2016.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_new_qq_music_sub.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_new_qq_music.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_liebao_subicon1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_liebaologo.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_kuwo.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_icon_sub.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_icon_common.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmd_guomei_online.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_yeyounewicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_tianmao_icon0415.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_tianmao_icon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_software_analyze.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_tianmao_icon0415.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_tianmao_icon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_taobao1212_test1_main.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_sysdoct.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_softpurifier.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_qiangpiao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_orange_btn.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\search.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\skin_sea.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\speedtest.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\start_acc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\weatherconfig.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\skin_space.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\scom.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\open_url_tool_cfg.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoft.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kcleanerselectallrisk.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\install.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\game.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\forecastmsg.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\clear.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\citys.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\microsoft.vc80.mfc.manifest
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\microsoft.vc80.crt.manifest
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_fullscan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\duba123new.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\duba123ienew.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\duba123.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\xianshifengqiang-taobao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\wifi_subicon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\wifi_icon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\wendujishrink_skin_img.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\weixin_rcmd_imgb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\weixin_index3.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\uninstall\trash_scan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\tianshizhiyi_skin_img.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\tengxunlive.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\stxmas_skin_imgex.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\floatskin\skinicon\stvltd_skin_imgex.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rcmdv2sp01\cfg\pic\rcmdv2_roundicon_avdr.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\btbg.gif
Удаляет следующие файлы
  • %TEMP%\jcqgx.ini
  • %TEMP%\kantivirus\~12967b\install_res\200.bmp
  • %TEMP%\kantivirus\~12967b\install_res\201.bmp
  • %TEMP%\kantivirus\~12967b\install_res\3.jpg
  • %TEMP%\kantivirus\~12967b\install_res\4.png
  • %TEMP%\kantivirus\~12967b\install_res\5.png
  • %TEMP%\kantivirus\~12967b\install_res\501.png
  • %TEMP%\kantivirus\~12967b\install_res\502.png
  • %TEMP%\kantivirus\~12967b\install_res\503.png
  • %TEMP%\kantivirus\~12967b\install_res\504.png
  • %TEMP%\kantivirus\~12967b\install_res\110.png
  • %TEMP%\kantivirus\~12967b\install_res\2.jpg
  • %TEMP%\kantivirus\~12967b\install_res\506.png
  • %TEMP%\kantivirus\~12967b\install_res\509.png
  • %TEMP%\kantivirus\~12967b\install_res\510.png
  • %TEMP%\kantivirus\~12967b\install_res\511.png
  • %TEMP%\kantivirus\~12967b\install_res\512.png
  • %TEMP%\kantivirus\~12967b\install_res\514.png
  • %TEMP%\kantivirus\~12967b\install_res\515.png
  • %TEMP%\kantivirus\~12967b\install_res\516.png
  • %TEMP%\kantivirus\~12967b\install_res\517.png
  • %TEMP%\kantivirus\~12967b\install_res\518.png
  • %TEMP%\kantivirus\~12967b\install_res\507.png
  • %TEMP%\kantivirus\~12967b\install_res\508.png
  • %TEMP%\kantivirus\~12967b\install_res\1.jpg
  • %TEMP%\kantivirus\~12967b\installrename_def.dat
  • %TEMP%\kantivirus\~12967b\clear_i.xml
  • %PROGRAMDATA%\dbazdk02.dat
  • %PROGRAMDATA%\installrename.dat
  • <DRIVERS>\kisknl_ev.sys
  • <DRIVERS>\kisknl64_ev.sys
  • <DRIVERS>\kisnetm_ev.sys
  • <DRIVERS>\kisnetm64_ev.sys
  • <DRIVERS>\ksapi_ev.sys
  • <DRIVERS>\ksapi64_ev.sys
  • <DRIVERS>\kisknl.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2isfdpro64.dll.bak
  • %TEMP%\install_res\100.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2s3rdhmpg.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2s3rdhmpg64.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2shmpg.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2swebshield.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2wsprotect64.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2wsui.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2wsui64.dll.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kis2live.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ks2launch.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxe2score.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxe2tray.exe.bak
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\k2s3rdhmpg32.dll.bak
  • %TEMP%\kantivirus\~12967b\ksoft.xml
  • %TEMP%\kdb_semrjgj.dll
Подменяет следующие файлы
  • %TEMP%\install_res\100.png
  • <DRIVERS>\kisknl.sys
Сетевая активность
TCP
Запросы HTTP GET
  • http://23##.35go.net/defend/o1/jcqgx.ini
  • http://du####n.cmcmcdn.com/sem/installer/0.png
  • http://co####.i.duba.net/seminstall/0/0.xml?ti#############
  • http://co####.i.duba.net/seminstall/0.xml
  • http://cd###.www.duba.net/duba/install/2011/ever/kavsetup170612_4_1.dat
  • http://23##.35go.net/defend/o1/dbazdk02.dat
  • http://23##.35go.net/defend/o1/installrename.dat
  • http://so####r.duba.net/big/index.htm
  • http://so####r.duba.net/big/css/common.css?ve################
  • http://so####r.duba.net/big/js/jquery-1.11.2.min.js
  • http://so####r.duba.net/big/js/tscrollbar.min.js
  • http://so####r.duba.net/big/js/softmgr.min.js?ve################
  • http://so####r.duba.net/big/js/index.min.js?ve################
Запросы HTTP POST
  • http://in###0.duba.net/c/
  • http://di#.##inshan.com/db/?v=############################################################################################################
  • http://in###0.duba.net/nep/v1/
  • http://ct.#uba.net/itid
UDP
  • DNS ASK 23##.35go.net
  • DNS ASK in###0.duba.net
  • DNS ASK du####n.cmcmcdn.com
  • DNS ASK co####.i.duba.net
  • DNS ASK cd###.www.duba.net
  • DNS ASK di#.##inshan.com
  • DNS ASK ct.#uba.net
  • DNS ASK so####r.duba.net
Другое
Ищет следующие окна
  • ClassName: '<Имя файла>_hiddenDpiAwarenessWindow' WindowName: ''
  • ClassName: '' WindowName: '{677B9715-5692-49f6-979F-CD11EC963EFE}'
  • ClassName: '{677B9715-5692-49f6-979F-CD11EC963EFE}' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''
  • ClassName: 'MS_WebCheckMonitor' WindowName: ''
Создает и запускает на исполнение
  • '%TEMP%\kdbcihelper.exe' -release
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavlog2.exe' -install
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftmgr.exe' -preload
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe' /autorun /hidefloatwin /silentinstrcmd
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe' /start kxescore
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.exe' /autorun /std /skipcs3
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe' /service kxescore
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\rcmdhelper.exe' -updateliebaowifi
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\rcmdhelper.exe' -updatetaguser
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\rcmdhelper.exe' -kdeskcanrcmd
  • '%TEMP%\kdbcihelper.exe' -release' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavlog2.exe' -install' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoftmgr.exe' -preload' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe' /autorun /hidefloatwin /silentinstrcmd' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe' /start kxescore' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.exe' /autorun /std /skipcs3' (со скрытым окном)

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке