Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen25.23757

Добавлен в вирусную базу Dr.Web: 2024-02-02

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Модифицирует следующие ключи реестра
  • [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kxesc' = '"%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe" -autorun'
Устанавливает следующие настройки сервисов
  • [HKLM\System\CurrentControlSet\Services\kxescore] 'Start' = '00000002'
  • [HKLM\System\CurrentControlSet\Services\kxescore] 'ImagePath' = '"%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe" /service kxescore'
  • [HKLM\System\CurrentControlSet\Services\KDHacker] 'Start' = '00000001'
  • [HKLM\System\CurrentControlSet\Services\KDHacker] 'ImagePath' = '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kdhacker64.sys'
  • [HKLM\System\CurrentControlSet\Services\kisknl] 'Start' = '00000002'
  • [HKLM\System\CurrentControlSet\Services\kisknl] 'ImagePath' = '<DRIVERS>\kisknl.sys'
  • [HKLM\SYSTEM\ControlSet001\services\kisknl] 'ImagePath' = '<DRIVERS>\kisknl.sys'
  • [HKLM\SYSTEM\ControlSet001\services\kisknl] 'Start' = '00000002'
  • [HKLM\SYSTEM\ControlSet002\services\kisknl] 'ImagePath' = '<DRIVERS>\kisknl.sys'
  • [HKLM\SYSTEM\ControlSet002\services\kisknl] 'Start' = '00000002'
  • [HKLM\System\CurrentControlSet\Services\kisnetm] 'Start' = '00000001'
  • [HKLM\System\CurrentControlSet\Services\kisnetm] 'ImagePath' = '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm64.sys'
  • [HKLM\System\CurrentControlSet\Services\ksapi64] 'ImagePath' = '<DRIVERS>\ksapi64.sys'
Создает следующие сервисы
  • 'kxescore' "%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe" /service kxescore
  • 'KDHacker' %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kdhacker64.sys
  • 'kisknl' <DRIVERS>\kisknl.sys
  • 'kisnetm' %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm64.sys
  • 'ksapi64' <DRIVERS>\ksapi64.sys
Вредоносные функции
Запускает на исполнение
  • '%WINDIR%\syswow64\net.exe' stop winmgmt /y
Регистрирует фильтр файловой системы
  • [HKLM\System\CurrentControlSet\Services\kisknl] 'Group' = 'FSFilter Anti-Virus'
Изменения в файловой системе
Создает следующие файлы
  • %TEMP%\kantivirus\kavsetup.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\15shyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\16shyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\17ltyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\18_263yx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\01vs.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\02haofang.png
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdle460.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze664.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcfileinfo.che
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1038-53e237a5-65bd81e7-3a4.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\14yeahyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\03zhanwang.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\07duowan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\08_178.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\09txyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\11tpyyxw.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\kxetray.exe.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\12shengda.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\13dipanw.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\14_91com.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\15sjtc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\04_4399.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\06_17173.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-e326aaa2-65bd81e7-366.ich
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze421.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\17jinshan.png
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdldea2.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze0d5.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\30bhw.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\32qidian.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\33_115wp.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\34jstp.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\35adb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\02_126yx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\03qqyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\04gmailyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\05yahooyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\06hotmail.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\07xlyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_commonfast\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_commonfast\index.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\08_139yx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\09tomyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\10_21cnyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\11sgyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\12_139yx.png
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdle1df.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\16wangyi.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\26gjw.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\13eyouyx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\02youa.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\18jjbs.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\14fengxing.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\15bfyy.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\16xluc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_khackfix.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\17jstp.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\18wps.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\19duba.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\742-afc98596-65bd81ea-19b.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\742-8dee3fe-65bd81ea-19b.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\742-22aabd25-65bd81ea-19b.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\742-89efaa57-65bd81ea-19b.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\99bill.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\alibaba.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\330-b72e0c6f-65bd81ea-1ab.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\alipay.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\330-b72e0c6f-65bd81eb-350.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\330-b72e0c6f-65bd81eb-35f.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\330-b72e0c6f-65bd81eb-36f.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kxesetting.dat
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1287-aa1eddf6-65bd81eb-52.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\beijing.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\chinapay.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\ips.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\13kugou.png
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze036.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\27_58tc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\12xunyou.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\baifubao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\beibao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\caifutong.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\kuaiqian.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\option.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\shengfutong.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\shouxinyi.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\xinfutong1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\xinfutong2.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\yibao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\yinlian.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\zhifubao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\02xunlei.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\03pptv.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\04pps.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\05feixin.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\06alww.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\07msn.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\08youku.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\09aitudou.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\10baiduyy.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\poplog.db-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\11yy.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\poplog.db
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\19di9cs.png
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdlde61.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\25zhw.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\514-cef36ffe-65bd81e6-30a.ich
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfc487.tmp
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfc87e.tmp
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\ksbw_apptype_cfg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_dps.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_dps.dat
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbw_wib.fsg
  • %WINDIR%\temp\uddc93a.tmp
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfc92b.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kfloatwin.log
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfcb2e.tmp
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\katcb4f.tmp
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1942-538418b3-65bd81e1-39e.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\2103-f8b2c123-65bd81e1-3bd.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\switch.dat
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1942-624db45-65bd81e2-3bc.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1942-9807060-65bd81e2-3bc.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_dsu.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_dsu.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kctrl.zip
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_hfsu.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_hfsu.dat
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsgc11c.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcwsign.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\data.fsg
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\742-b2eee6a6-65bd81eb-36f.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksecachecfg.ini
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcbase.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\kmctrl_trace.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\defmsg.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\urlmon.cfg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\autoflux.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\procinfo.dat
  • %WINDIR%\temp\udda6bc.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_common.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_common.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa1.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa1.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\ksdecs_trace.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\fluxcache.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe.0.log
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwlog.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwlog.dat
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwlog3.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwlog3.dat
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwfile.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwfile.dat
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwbase.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwbase.dat
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcbase.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\fluxstastic.dat
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcwsign.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_khackfix.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_common\index.dat
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\ksgd2fd.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\taobao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\taobaomall.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\vancl.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\zhuoyue.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\03yidong.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\04liantong.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\05dianxin.png
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdldc3d.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\softreport.ini
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuzde21.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\06baidu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\07xinlang.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\09zhifubao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\11souhu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\12yahu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\15_51com.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\17tudou.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\18youku.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\19xlkk.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\20_56w.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\21fenghuang.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\24xcht.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_common\index.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\paipai.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\quarantine.count
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\jingdong.png
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\conf.ini
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1942-624db45-65bd81e3-30.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\netbuy_imgs.zip
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\klengine.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_commonfast.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_commonfast.txt
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\data.fsg
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\conf.ini
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1990-3c62b8e8-65bd81e4-1f2.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\gongshang.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\guangfa.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\jianshe.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\jiaotong.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\minsheng.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\nongye.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\pufa.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\xingye.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\zhaoshang.png
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdld9f9.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuzdc1c.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\zhongguo.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\zhongxin.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe.5.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\01yitao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\dangdang.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\nuomi.png
  • %ALLUSERSPROFILE%\kingsoft\kis\installtimecfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\paypal.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\hxb.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-1267a73c-65bd81f4-2e4.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-1f8172b6-65bd81f4-38f.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-5d9e1513-65bd81f4-38f.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-61473507-65bd81f4-38f.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\icbc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\nbcb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\njcb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\pingan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\hkbea.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\hsbc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\psbc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\standardchartered.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\tccb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\zjnx.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\krcmdmon\pack\tip_2016_0920.dat
  • %LOCALAPPDATA%\kingsoft\kis\kich9\1\628-11f4562d-65bd81f4-1c9.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-467e41c1-65bd81f4-1f8.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-9c1ffa8f-65bd81f4-1f8.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-bb208ad5-65bd81f4-1f8.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-1c40a351-65bd81f5-208.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\sdb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\spdb.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-3bb4d70c-65bd81f4-2e4.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\hccb.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\560-e594946d-65bd81f5-237.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\yihaodian.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\yintai.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\yougou.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_kvm2\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\abchina.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_kvm2\index.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\krcmdmon\imd5.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\bankcomm.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\bankofshanghai.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\boc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\ccb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\cebbank.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\cib.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\citibank.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\cmbc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\cmbchina.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\cscb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\ecitic.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\gdb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\gzcb.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\krcmdmon\pack\setask_rcmdinst_1.dat
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\560-4f850c62-65bd81f5-227.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\xijie.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-56fc702a-65bd81f4-2a5.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\742-5c6b8a3c-65bd81eb-13c.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\560-c7cc0029-65bd81f5-237.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kxeapp\index.txt
  • %WINDIR%\temp\cab3f40.tmp
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\60e31627fda0a46932b0e5948949f2a5
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\60e31627fda0a46932b0e5948949f2a5
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\816-5cfab7a7-65bd81ff-2f1.ich
  • %WINDIR%\temp\tar401b.tmp
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\647-fa9f54c3-65bd8203-387.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-8c6943ad-65bd8203-89.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-cfc96321-65bd8203-89.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-d06c6b8b-65bd8203-99.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-dc85146f-65bd8203-99.ich
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\7d266d9e1e69fa1eefb9699b009b34c8_0a9bfdd75b598c2110cbf610c078e6e6
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\7d266d9e1e69fa1eefb9699b009b34c8_0a9bfdd75b598c2110cbf610c078e6e6
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\8dfdf057024880d7a081afbf6d26b92f
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\8dfdf057024880d7a081afbf6d26b92f
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\62b5af9be9adc1085c3c56ec07a82bf6
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\62b5af9be9adc1085c3c56ec07a82bf6
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\7b8944ba8ad0efdf0e01a43ef62becd0_901c8e449a1c798bf22886d9157caef2
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\7b8944ba8ad0efdf0e01a43ef62becd0_901c8e449a1c798bf22886d9157caef2
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-1205d72c-65bd8208-12d.ich
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\872-bc20eb8c-65bd8209-2f1.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kxeapp\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\xifuquan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\xiu.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-2de91bc0-65bd81fb-3a3.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\560-ec133f1e-65bd81f5-246.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\560-d261a941-65bd81f5-246.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\560-7d37cab0-65bd81f5-246.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\561-6fe9ad78-65bd81f5-256.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\561-d82d986f-65bd81f5-265.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\561-80e8470d-65bd81f5-275.ich
  • %LOCALAPPDATA%\kingsoft\kis\kich9\1\607-4c8d4da8-65bd81f5-2b3.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_kwifitool.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_kwifitool.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\kusbcore.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\krcmdmon\data\method.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_kwifitool\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_kwifitool\index.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexksg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexksg.txt
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\d47dbd2f9e3365fbbe008d71fb06716f_d33192d58aa9ca2b9097e848e9fe86de
  • %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\d47dbd2f9e3365fbbe008d71fb06716f_d33192d58aa9ca2b9097e848e9fe86de
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\ksg\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\ksg\index.txt
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\647-35f33f96-65bd81fa-49.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkxeapp.dat
  • %WINDIR%\temp\fwtsqmfile01.sqm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkxeapp.txt
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-441de8f6-65bd81fb-113.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\560-823e06c2-65bd81f5-237.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\womai.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\wine9.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\w1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwrcmd.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\duba.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\e-lining.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\elong.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\etpass.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\fclub.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\flowercn.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\ftuan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\ganji.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\gaopeng.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\gouxie.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\guomei.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\htjz.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kclearak.dat_t
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\icson.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\idaphne.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\ihush.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\jumei.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\justonline.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\jxdyf.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\kadang.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\645-609b0bfb-65bd81ed-2f.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\dazhe.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\do93.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\np_xinfutong1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\kuxun.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\d1.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\sina.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\tenpay.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\yeepay.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\24juan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\360buy.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\51youpin.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\55tuan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\58tuan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\aimer.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\amazon.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\shengpay.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\camel.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\ktrashmon.dll.log
  • %LOCALAPPDATA%\kingsoft\kis\kich9\1\606-1e7e3472-65bd81ed-2c0.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_khackfix\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\caomeipai.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\deflist.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\chicr.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\cnfse.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\coo8.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\2199-1c911714-65bd81ed-6e.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\ctrip.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktrashud.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\dhc.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa0.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_kvm2.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\lashou.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\qmango.png
  • %ALLUSERSPROFILE%\kingsoft\shoujikong\devicecache\devices.db
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\qqtuan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\krcmdmon\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\qunar.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\quwan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\redbaby.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\s.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\salala.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\shopin.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\suning.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\taobaolvxing.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\taobaotemai.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\taoxie.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\tiantian.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\tuan800.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\tuanqq.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\tuniu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\uiyi.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\uzai.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\vipshop.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\vjia.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\lafaso.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\pb89.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\lamiu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\paixie.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kcom_khackfix\index.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkcom_kvm2.txt
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\1877-da6c4ece-65bd81f0-24e.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\bdmisc.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\letao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\m18.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\maimaicha.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\mangocity.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\742-32a74660-65bd81f0-367.ich
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\330-50a0e16-65bd81f0-367.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\manzuo.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\masamaso.png
  • %ALLUSERSPROFILE%\kingsoft\shoujikong\devicecache\devices.db-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksysoptak47_tmp.dat_t
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\mbaobao.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\meituan.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\menglu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\miqi.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\softuse.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\moonbasa.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\mytenfu.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\nala.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\newegg.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\no5.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\olomo.png
  • %ALLUSERSPROFILE%\kingsoft\kis\kich\964-c5deb5cc-65bd81fb-113.ich
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kav\index.txt
  • %ALLUSERSPROFILE%\kingsoft\ksbw\kns2.che
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kvipfree.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kxeutilcfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\module.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\productidinfo.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\push_msg_city_list.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\quarantine.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\signs.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\sjkpopcfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\vinfo.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksscfgx.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kusb_config.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\weathertype.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\vplayer.cfg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\cloudctrl.config
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kpopcfg.config
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\liectrl.config
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\recommendctrl.config
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\npkws.crx
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\apdev.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\bredirect.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\config3.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\bro.cfg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\fdlocal.cfg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksrengcfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksecfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\defbro.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\weatherconfig.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\weatherterms.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_bbs.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_duba.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_main.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\web\kingsoft_weibo.htm
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\broplugver.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\deheurcfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\hmpgconfig.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecore.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kavcfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavstart.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kccprotocol_cfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kcommon.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kdehacker.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kdock.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfccfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\khackfix.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\khistory.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kismain.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksbwdt.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\config3a.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\speedtest.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksedset.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\duba123.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\defmisc.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwnp.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwpl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsadr.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsshop.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsu.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kxecomm.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\lpolicy.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\netbank.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\oem_config.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\office.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\office_add.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\progrule.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\protect.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\se.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\shoujizhushou\sjkkctrl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\shoujizhushou\sjkkfmt.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\softicon.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\system.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\system64.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\system64_add.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\system_add.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\themelist.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\trashfilerule.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kvipver.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\cloudpop\1.0.0\pop_cd_cleanrubbish2\setting_menu.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\cloudpop\1.0.0\pop_cd_cleanrubbish2\style.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksysoptlp.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\drivers.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\fnsign.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\gamesdb_dc.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\iglist.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kaccclear.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaearcha.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaearchb.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecore.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kae\karchive.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\operation\cas\kctrl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdh.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_hfps.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\khandler.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kplc.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kpld.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kpretend.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kqsccfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksais.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksdmalwarez.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\config\ksesysfiles.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksfilter.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksolec.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksoles.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksysoptpqpop.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\deswitch.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\scom.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\cloudpop\1.0.0\popcfg.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\neybuydescrip.xml
  • %TEMP%\kantivirus\~c3e47\install_res\citys.xml
  • %TEMP%\kantivirus\~c3e47\clear_i.xml
  • %TEMP%\kantivirus\~c3e47\ksoft.xml
  • %TEMP%\kantivirus\~c3e47\product.xml
  • %TEMP%\kantivirus\~c3e47\setup.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\bkfilter.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\bkgrdx.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\bkplugin.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgadultltb.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgadultlts.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgadulttrb.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgadulttrs.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgdangerltb.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgdangerlts.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgdangertrb.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgdangertrs.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgsafeltb.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgsafelts.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgsafetrb.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgsafetrs.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgunkownltb.gif
  • %TEMP%\kantivirus\~c3e47\install_res\109.bmp
  • %TEMP%\kantivirus\~c3e47\install_res\9.png
  • %TEMP%\kantivirus\~c3e47\install_res\201.bmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\upcfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgunkownlts.gif
  • %TEMP%\kantivirus\~c3e47\install_res\76.png
  • %TEMP%\kantivirus\~c3e47\install_res\110.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\2.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\3.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\31.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\19.png
  • %TEMP%\kantivirus\~c3e47\install_res\20.png
  • %TEMP%\kantivirus\~c3e47\install_res\32.png
  • %TEMP%\kantivirus\~c3e47\install_res\34.png
  • %TEMP%\kantivirus\~c3e47\install_res\4.png
  • %TEMP%\kantivirus\~c3e47\install_res\5.png
  • %TEMP%\kantivirus\~c3e47\install_res\1.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\63.png
  • %TEMP%\kantivirus\~c3e47\install_res\65.png
  • %TEMP%\kantivirus\~c3e47\install_res\66.png
  • %TEMP%\kantivirus\~c3e47\install_res\67.png
  • %TEMP%\kantivirus\~c3e47\install_res\68.png
  • %TEMP%\kantivirus\~c3e47\install_res\69.png
  • %TEMP%\kantivirus\~c3e47\install_res\70.png
  • %TEMP%\kantivirus\~c3e47\install_res\72.png
  • %TEMP%\kantivirus\~c3e47\install_res\73.png
  • %TEMP%\kantivirus\~c3e47\install_res\74.png
  • %TEMP%\kantivirus\~c3e47\install_res\75.png
  • %TEMP%\kantivirus\~c3e47\install_res\64.png
  • %TEMP%\kantivirus\~c3e47\install_res\100.bmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kusbhwl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgunkowntrb.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\defpolicy.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\vduba\vduba.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\npkws.xpi
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\microsoft.vc80.crt.manifest
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\microsoft.vc80.mfc.manifest
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\cloudpop\1.0.0\pop_cd_cleanrubbish2\action.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\avrepair.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\citys.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\clear.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\fireeye.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\forecastmsg.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\game.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\holiday.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\hotspot.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ifrcfg.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\install.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavvipcfg.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kconfig.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kissuerepair.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksafetips.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksdoccfg.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksoft.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kswscxex_ser.xml
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbgunkowntrs.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\vduba\dubagame.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\commentbt.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\duba123ienew.ico
  • %TEMP%\kantivirus\~c3e47\install_res\200.bmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kwsdownicon.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kwsdownicon1.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kwsupicon.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kwsupicon1.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_adult.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_adult_no.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_danger.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_danger_no.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_safe.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_safe_no.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_unknown.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\kws_unknown_no.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\sfshare.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\binglanbeiji.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\default.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\default.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\xp_support.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\kws\icon\knet.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\metroimg\metro_blue.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\metroimg\metro_green.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\metroimg\metro_orange.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\metroimg\metro_red.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\xp_support_share.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\duba123ie.ico
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kseexf.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\wd.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kavbootc64.sys
  • <DRIVERS>\kavbootc64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys
  • <DRIVERS>\kdhacker.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kdhacker64.sys
  • <DRIVERS>\kdhacker64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kisknl.sys
  • <DRIVERS>\kisknl.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kisknl64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kavbootc.sys
  • <DRIVERS>\kavbootc.sys
  • <DRIVERS>\kisknl64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm64.sys
  • <DRIVERS>\kisnetm64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetmxp.sys
  • <DRIVERS>\kisnetmxp.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi.sys
  • <DRIVERS>\ksapi.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi64.sys
  • <DRIVERS>\ksapi64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksskrpr.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm.sys
  • <DRIVERS>\kisnetm.sys
  • <DRIVERS>\bc.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\zlib1.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kusbquery.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kvip.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kvipcore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwansvc.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwssp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsui.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsui64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxebase.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxebscsp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxecore\kxecore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxecore\kxelog.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxereg.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kxesansp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\lbhelper.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\lblocker.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\msvcp80.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\msvcr80.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyprot.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\npkws.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\scom.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\sqlite.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\wfs.dll
  • <DRIVERS>\ksskrpr.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kusbcore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\bc.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\vidlist.dat
  • <DRIVERS>\kusbquery.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\fdlocal.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\fdlocal.bak
  • %ALLUSERSPROFILE%\kingsoft\kis\kws\dfcache.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\webui\icon\btbg.gif
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\fdsdcache.db-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kdehuser.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\fdsdcache.db
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwctrl2.che
  • %WINDIR%\temp\udd8eb7.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexdata.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexdata.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\data\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\data\index.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkav.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\indexkav.txt
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\ksdectrl_trace.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rule.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\deconfig.ini
  • %WINDIR%\temp\udd9f1d.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kav\kav\index.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kseset.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\expand_rule.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksepnf.dat
  • %ALLUSERSPROFILE%\kingsoft\kis\kws\urlcache.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kupdatesp.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kusbscan.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kws_init.log
  • <DRIVERS>\kusbquery64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\1.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\2.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\3.jpg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\4.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\extendimg\5.png
  • C:\users\public\desktop\新毒霸.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\新毒霸.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\在线升级.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\卸载新毒霸.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\病毒隔离系统.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\日志查看器.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\访问金山公司网站\新毒霸官方微博.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\访问金山公司网站\新毒霸官方社区.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\访问金山公司网站\新毒霸网站.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\金山毒霸\访问金山公司网站\金山公司主页.lnk
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\desktop.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.log
  • %ALLUSERSPROFILE%\kingsoft\kis\hg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcdetect.dll.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\log\kxescore.exe.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcuploadinfo.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcuploadinfo.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksbwdet2.dll.log
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kusbquery64.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktrashscan.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktrashmon.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktoolupd.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kismain.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kphonewiz.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krecycle.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kscan.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksetupwiz.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kupdata.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kvipwiz.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kweibotool.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsprotect64.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\sjk_daemon.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\uni0nst.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\adbwinapi.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\adbwinapi2.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\adbwinusbapi.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\bittransport.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\defendmon.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\jsonv6.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kadbtool.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kanthack.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdownloader.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcleaner.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\vrulecfg.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kavdevc.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavlog2.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\whiteurl.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\operation\cas\kfmt.datx
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\duba_binglanbeiji.dubaskin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\skin\theme\binglanbeiji.dubatheme
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\data.fsg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\unknown.fsg
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavpid.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcommonpid.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\khackfix.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kvmpid2.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\wgsites.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwifitool.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\denyip.krf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\krmcdm.krf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\rule.krf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\cloudpop\1.0.0\pop_cd_cleanrubbish2\skin.ksfskin
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\npkws.mxaddon
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\sp3a.nlb
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\sougouext.sext
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\shoujizhushou\sjkuplive.svr
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ressrc\chs\uplive.svr
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore_sp.xcf
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxeksgpid.kid
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdf.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa0.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavevent.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kavquara.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\ksdecs.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksdectrl.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kseescan.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksesscan.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kseutil.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksextfix.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksgmerge.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kshmpg.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kshmpgext.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksinst.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kskinmgr.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksolescanner.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kspcore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kspupwnd.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksreng3.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksscore.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kstools.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kswbc.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kswebshield.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kswscxex.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksysopteng.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ktoastpop.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavmenu.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kscanner.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavmenu64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\ksbwdet2.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdrvmgr.exe
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcctrl.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kcomponent.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdefendpop.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdgui2.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kdynmrey.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\keasyipcn.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcdetect.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kfloatmain.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kfloatwin.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\khandler.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\khistory.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\operation\cas\kinfoc.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kisfdpro64.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kismain.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\klengine.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksde\kmctrl.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kminitray.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\ksnetm\kmonstat.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpopclt.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kpopsvr.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krcmddown.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\krcmdmon.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksafevul.dll
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\ksapi64.dll
  • %TEMP%\kantivirus\kresult.log
Удаляет следующие файлы
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcuploadinfo.dat-journal
  • %TEMP%\kantivirus\~c3e47\install_res\31.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\3.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\201.bmp
  • %TEMP%\kantivirus\~c3e47\install_res\200.bmp
  • %TEMP%\kantivirus\~c3e47\install_res\20.png
  • %TEMP%\kantivirus\~c3e47\install_res\2.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\19.png
  • %TEMP%\kantivirus\~c3e47\install_res\110.jpg
  • %TEMP%\kantivirus\~c3e47\install_res\109.bmp
  • %TEMP%\kantivirus\~c3e47\install_res\100.bmp
  • %TEMP%\kantivirus\~c3e47\install_res\1.jpg
  • %TEMP%\kantivirus\~c3e47\clear_i.xml
  • %WINDIR%\temp\tar401b.tmp
  • %WINDIR%\temp\cab3f40.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\netbuyimgs\netbuy_imgs.zip
  • %TEMP%\kantivirus\~c3e47\install_res\32.png
  • %TEMP%\kantivirus\~c3e47\install_res\4.png
  • %TEMP%\kantivirus\~c3e47\ksoft.xml
  • %TEMP%\kantivirus\~c3e47\install_res\5.png
  • %TEMP%\kantivirus\~c3e47\install_res\citys.xml
  • %TEMP%\kantivirus\~c3e47\install_res\9.png
  • %TEMP%\kantivirus\~c3e47\install_res\76.png
  • %TEMP%\kantivirus\~c3e47\install_res\75.png
  • %TEMP%\kantivirus\~c3e47\install_res\74.png
  • %TEMP%\kantivirus\~c3e47\install_res\73.png
  • %TEMP%\kantivirus\~c3e47\install_res\72.png
  • %TEMP%\kantivirus\~c3e47\install_res\70.png
  • %TEMP%\kantivirus\~c3e47\install_res\69.png
  • %TEMP%\kantivirus\~c3e47\install_res\68.png
  • %TEMP%\kantivirus\~c3e47\install_res\67.png
  • %TEMP%\kantivirus\~c3e47\install_res\66.png
  • %TEMP%\kantivirus\~c3e47\install_res\65.png
  • %TEMP%\kantivirus\~c3e47\install_res\64.png
  • %TEMP%\kantivirus\~c3e47\install_res\63.png
  • %ALLUSERSPROFILE%\kingsoft\shoujikong\devicecache\devices.db-journal
  • %TEMP%\kantivirus\~c3e47\install_res\34.png
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\poplog.db-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_dps.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfc487.tmp
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\conf.ini
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsgc11c.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcwsign.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcbase.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwbase.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwfile.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwlog3.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwlog.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa1.dat-journal
  • %WINDIR%\temp\udda6bc.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa0.dat-journal
  • %WINDIR%\temp\udd9f1d.tmp
  • %WINDIR%\temp\udd8eb7.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\fdsdcache.db-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfc87e.tmp
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\ksbw_apptype_cfg
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze0d5.tmp
  • %WINDIR%\temp\uddc93a.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze421.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdle1df.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdldea2.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdlde61.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuzdc1c.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuzde21.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdldc3d.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdld9f9.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\ksgd2fd.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\conf.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_hfsu.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\update\kctrl.zip
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfc_dsu.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfcb2e.tmp
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\fsfc92b.tmp
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kdle460.tmp
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksysoptak47_tmp.dat
Перемещает следующие файлы
  • <DRIVERS>\kisknl.sys в <DRIVERS>\kisknl_del.sys
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\data.fsg в %ALLUSERSPROFILE%\kingsoft\ksbw\ksbw_wi.fsg
  • %ALLUSERSPROFILE%\kingsoft\ksbw\temp\katcb4f.tmp в %ALLUSERSPROFILE%\kingsoft\ksbw\ksbw_appt.che
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\data.fsg в %ALLUSERSPROFILE%\kingsoft\kfc\kfc_topw.ksg
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze036.tmp в %ALLUSERSPROFILE%\kingsoft\kfc\kfcdyncfg.ini
  • %ALLUSERSPROFILE%\kingsoft\kfc\temp\kuze664.tmp в %ALLUSERSPROFILE%\kingsoft\kfc\kfcdyncfg.ini
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kclearak.dat_t в %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\kclearak.dat
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksysoptak47_tmp.dat_t в %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksysoptak47_tmp.dat
Подменяет следующие файлы
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kfcuploadinfo.dat-journal
  • <DRIVERS>\kisknl.sys
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa0.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\security\kxescan\kse_wfsdata\01c45e18_wfsexa1.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwlog.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwfile.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\ksbw\ksbwbase.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcbase.dat-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\poplog.db-journal
  • %ALLUSERSPROFILE%\kingsoft\kfc\kfcwsign.dat-journal
  • %ALLUSERSPROFILE%\kingsoft\shoujikong\devicecache\devices.db-journal
  • %ProgramFiles(x86)%\kingsoft\kingsoft antivirus\data\ksysoptak47_tmp.dat
Сетевая активность
Подключается к
  • 'di#.##inshan.com':80
  • 'ct.#uba.net':80
  • '12#.#93.207.36':80
  • '11#.#12.67.221':80
  • '22#.#28.204.36':80
  • 'do####ad.duba.net':80
  • 'b.###.pc120.com':80
  • '23##.35go.net':80
  • 'rq.###.cloud.duba.net':80
  • 'f3.#uba.com':80
  • 'fs###s.duba.net':80
  • 'cu###.www.duba.net':80
  • 'tj.####n.ijinshan.com':80
  • 'v2.##3.duba.net':80
  • 'cv.#uba.net':80
  • '12#.#2.75.95':80
  • 'cl####q.duba.net':80
  • 'kn#.#uba.net':80
  • 'in###0.duba.net':80
  • 'in###2.duba.net':80
  • 'microsoft.com':80
TCP
Запросы HTTP GET
  • http://cl####q.duba.net/abc
  • http://cu###.www.duba.net/duba/2013/krcmdmon/pop/1335/kwrcmd.dat
  • http://cu###.www.duba.net/duba/tools/dubatools/kclearak.dat
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_kvm2/indexkcom_kvm2.dat
  • http://cu###.www.duba.net/duba/tools/dubatools/ksysoptak47.dat
  • http://cu###.www.duba.net/duba/2013/krcmdmon/pop/1335/index.dat
  • http://cu###.www.duba.net/duba/2013/krcmdmon/pop/1335/imd5.dat
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_kvm2/kcom_kvm2/10746cb9dbba2f1c1ef8374d85d408e2
  • http://fs###s.duba.net/dl/libs/180.a
  • http://cu###.www.duba.net/duba/2013/krcmdmon/pop/1335/pack/setask_rcmdinst_1.dat
  • http://cu###.www.duba.net/duba/2013/krcmdmon/pop/1335/pack/tip_2016_0920.dat
  • http://ct.#uba.net/s/ut/
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_kwifitool/kcom_kwifitool/9d42a2f0fdb82d5c5c4cecc5dd9cd781
  • http://cu###.www.duba.net/duba/kisengine/lib/8f2befbc.dat
  • http://cu###.www.duba.net/duba/kisengine/lib/ksg/301215df78401c15ea23636dcb946c60
  • http://cu###.www.duba.net/duba/kisengine/app/1335/8f20cdd5.dat
  • http://cu###.www.duba.net/duba/kisengine/app/1335/kxeapp/3008d51d11aef171d41451c73a2e266f
  • http://www.pc##0.com/api/adrules/check_subs/?c=##################################################################################################################################################...
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_khackfix/kcom_khackfix/3629787f17f94cc26440efee732e9c8e
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_khackfix/65b096a8.dat
  • http://b.###.pc120.com/utp/%20?p=########################################################################
  • http://cu###.www.duba.net/kcs/kfsg/config/kfcdyncfg
  • http://cu###.www.duba.net/duba/kisengine/data/895751a0.dat
  • http://cu###.www.duba.net/duba/kisengine/data/data/63817077085bbdc37e782c259bf71832
  • http://cu###.www.duba.net/duba/2010/bin/1335/8f2bf01d.dat
  • http://cu###.www.duba.net/duba/2010/bin/1335/kav/acfef1b8a288b006d0fe4f0b2dceab80
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_common/77a1c800.dat
  • http://cu###.www.duba.net/kcs/kfsg/config/ksbwdtnet
  • http://cu###.www.duba.net/kcs/kfsg/fsgs/kswfsign
  • http://12#.#2.75.95/
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_kwifitool/indexkcom_kwifitool.dat
  • http://fs###s.duba.net/dl/fs
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_common/kcom_common/34951e8bd03060a0083d4aed64b78a77
  • http://cu###.www.duba.net/kcs/kfsg/fsgs/kswfsign3
  • http://do####ad.duba.net/2011/netbuy/netbuy_imgs.zip
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_commonfast/8f1ea8e1.dat
  • http://cu###.www.duba.net/duba/2011/kcomponent/kcom_commonfast/kcom_commonfast/2d0d52422155038a7b8e1ba1b935de34
  • http://fs###s.duba.net/df/fm
  • http://fs###s.duba.net/df/libs/1.17.0
  • http://cv.#uba.net/cv?uu###################################################################
  • http://23##.35go.net/defend/l3b/kctrl/1509/kctrl.zip
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
Запросы HTTP POST
  • http://di#.##inshan.com/db/?v=######################################################################################################################################################
  • http://kn#.#uba.net/kns-query
  • http://in###0.duba.net/c/
  • http://v2.##3.duba.net/v/
  • http://tj.####n.ijinshan.com/c/
  • http://rq.###.cloud.duba.net/query?17########
  • http://f3.#uba.com/query3
  • http://in###2.duba.net/c/
UDP
  • DNS ASK wq.###ud.duba.net
  • DNS ASK ud#.##oud.duba.net
  • DNS ASK ct.#uba.net
  • DNS ASK cf.#uba.net
  • DNS ASK pc##0.com
  • DNS ASK do####ad.duba.net
  • DNS ASK b.###.pc120.com
  • DNS ASK 23##.35go.net
  • DNS ASK rq.###.cloud.duba.net
  • DNS ASK f3.#uba.com
  • DNS ASK fs###s.duba.net
  • DNS ASK cu###.www.duba.net
  • DNS ASK tj.####n.ijinshan.com
  • DNS ASK v2.##3.duba.net
  • DNS ASK cv.#uba.net
  • DNS ASK kn#.#uba.net
  • DNS ASK cl####q.duba.net
  • DNS ASK in###0.duba.net
  • DNS ASK di#.##inshan.com
  • DNS ASK in###2.duba.net
  • DNS ASK microsoft.com
  • 'ud#.##oud.duba.net':9011
Другое
Ищет следующие окна
  • ClassName: '' WindowName: '{677B9715-5692-49f6-979F-CD11EC963EFE}'
  • ClassName: '{677B9715-5692-49f6-979F-CD11EC963EFE}' WindowName: ''
  • ClassName: 'kingsoft antivirus package win' WindowName: '新毒霸-安装向导'
Создает и запускает на исполнение
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavlog2.exe' -install
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe' /autorun /hidefloatwin
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe' /start kxescore
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.exe' /autorun /std /skipcs3
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe' /service kxescore
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsprotect64.exe' (null)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kvipwiz.exe' -sv:1335 -exp -cid:10001 -c:7
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kavlog2.exe' -install' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxetray.exe' /autorun /hidefloatwin' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kxescore.exe' /start kxescore' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kislive.exe' /autorun /std /skipcs3' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c net stop winmgmt /y' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c net start winmgmt' (со скрытым окном)
  • '%ProgramFiles(x86)%\kingsoft\kingsoft antivirus\kwsprotect64.exe' (null)' (со скрытым окном)
Запускает на исполнение
  • '%WINDIR%\syswow64\cmd.exe' /c net stop winmgmt /y
  • '%WINDIR%\syswow64\cmd.exe' /c net start winmgmt
  • '%WINDIR%\syswow64\net1.exe' stop winmgmt /y
  • '%WINDIR%\syswow64\net.exe' start winmgmt
  • '%WINDIR%\syswow64\net1.exe' start winmgmt

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке