Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2904:16e0 10:27:12.710 Starting server...
- 2904:16e0 10:27:12.736 Failed to write dbghelp.dll
- 2904:16e0 10:27:12.736 Initializing application...
- 2904:16e0 10:27:12.803 Loading ini files...
- 2904:16e0 10:27:12.808 Loading resource data 'RES_INI_X64'...
- 2904:16e0 10:27:12.866 Loading resource data finished, 569369 bytes
- 2904:16e0 10:27:12.866 Loading resource data 'RES_INI_X32X64'...
- 2904:16e0 10:27:12.870 Loading resource data finished, 2088563 bytes
- 2904:16e0 10:27:12.870 Parsing ini files data...
- 2904:16e0 10:27:12.925 Ini files data parsed, 103 files parsed
- 2904:16e0 10:27:12.926 Dumping data to files...
- 2904:16e0 10:27:12.967 Data dumped to files
- 2904:1204 10:27:13.723 SetUserEnvironment
- 2904:1204 10:27:13.723 Dumping current environment...
- 2904:1204 10:27:13.723 CreateFileA () failed, error 3
- 2904:1204 10:27:13.723 Set environment from string...
- 2904:1204 10:27:13.724 change_current_enviroment start
- 2904:1204 10:27:13.785 Server malloc
- 2904:1204 10:27:13.785 Server free
- 2904:1884 10:27:13.787 Detect products with no-detect=0, remove-all=0...
- 2904:1884 10:27:13.787 ShutdownDetector started watch thread (00000394)
- 2904:1884 10:27:13.789 Kaspersky Removal Tool 1.0.2686
- 2904:1884 10:27:13.789 KLeaner initialized
- 2904:1884 10:27:13.789 OS info...
- 2904:0830 10:27:13.789 Watch thread started
- 2904:1884 10:27:13.902 OS version = 10.0.19045, 64 bit
- 2904:1884 10:27:13.902 OS info = Майкрософт Windows 10 Pro, CSDVersion="", Version=10.0.19045, BuildNumber=19045
- 2904:1884 10:27:13.902 TraceSystemInfo: Time ticks=806562 ticks64=806562 idle=2757.7500000 kernel=2998.6875000 user=227.3906250
- 2904:1884 10:27:13.902 TraceSystemInfo: System oemId=00000009 pageSize=4096 MinAppAddress=00010000 MaxAppAddress=FFFEFFFF ActiveProcessorMask=0000000F NumberOfProcessors=4 ProcessorType=8664 AllocationGranularity=65536 ProcessorLevel=6 ProcessorRevision=40458
- 2904:1884 10:27:13.902 TraceSystemInfo: Memory Load=56 Phys=1807126528/4161114112 PageFile=2646114304/4899311616 Virtual=2064248832/2147352576 AvailExtendedVirtual=0
- 2904:1884 10:27:13.903 TraceSystemInfo: Performance commit(total=550097,limit=1196121,peak=553504 phis(total=1015897,avail=441192) syscache=460579 kernel(total=91987,paged=53326,nonpaged=38661) page=4096 handles=49571 processes=138 threads=1270
- 2904:1884 10:27:13.903 TraceTokenInformation: class=1(User) length=20 [User[Sid=S-1-5-18,Attributes=0]]
- 2904:1884 10:27:13.903 TraceTokenInformation: class=2(Groups) length=88 [GroupCount=4,[Sid=S-1-5-32-544,Attributes=E],[Sid=S-1-1-0,Attributes=7],[Sid=S-1-5-11,Attributes=7],[Sid=S-1-16-16384,Attributes=60]]
- 2904:1884 10:27:13.905 TraceTokenInformation: class=3(Privileges) length=340 [PrivilegeCount=28,[Luid=SeAssignPrimaryTokenPrivilege,Attributes=0],[Luid=SeLockMemoryPrivilege,Attributes=3],[Luid=SeIncreaseQuotaPrivilege,Attributes=0],[Luid=SeTcbPrivilege,Attributes=3],[Luid=SeSecurityPrivilege,Attributes=0],[Luid=SeTakeOwnershipPrivilege,Attributes=0],[Luid=SeLoadDriverPrivilege,Attributes=0],[Luid=SeSystemProfilePrivilege,Attributes=3],[Luid=SeSystemtimePrivilege,Attributes=0],[Luid=SeProfileSingleProcessPrivilege,Attributes=3],[Luid=SeIncreaseBasePriorityPrivilege,Attributes=3],[Luid=SeCreatePagefilePrivilege,Attributes=3],[Luid=SeCreatePermanentPrivilege,Attributes=3],[Luid=SeBackupPrivilege,Attributes=0],[Luid=SeRestorePrivilege,Attributes=0],[Luid=SeShutdownPrivilege,Attributes=0],[Luid=SeDebugPrivilege,Attributes=3],[Luid=SeAuditPrivilege,Attributes=3],[Luid=SeSystemEnvironmentPrivilege,Attributes=0],[Luid=SeChangeNotifyPrivilege,Attributes=3],[Luid=SeUndockPrivilege,Attributes=0],[Luid=SeManageVolumePrivilege,Attributes=0],[Luid=SeImpersonatePrivilege,Attributes=3],[Luid=SeCreateGlobalPrivilege,Attributes=3],[Luid=SeIncreaseWorkingSetPrivilege,Attributes=3],[Luid=SeTimeZonePrivilege,Attributes=3],[Luid=SeCreateSymbolicLinkPrivilege,Attributes=3],[Luid=SeDelegateSessionUserImpersonatePrivilege,Attributes=3]]
- 2904:1884 10:27:13.906 TraceTokenInformation: class=4(Owner) length=20 [Owner=S-1-5-32-544]
- 2904:1884 10:27:13.906 TraceTokenInformation: class=5(PrimaryGroup) length=16 [PrimaryGroup=S-1-5-18]
- 2904:1884 10:27:13.906 TraceTokenInformation: class=11(RestrictedSids) length=4 [GroupCount=0]
- 2904:1884 10:27:13.906 TraceTokenInformation: class=12(SessionId) length=4 [0(00000000)]
- 2904:1884 10:27:13.906 TraceTokenInformation: class=14(SessionReference) length=1 GetInfo fail error=87
- 2904:1884 10:27:13.906 TraceTokenInformation: class=15(SandBoxInert) length=4 [0(00000000)]
- 2904:1884 10:27:13.906 TraceTokenInformation: class=16(AuditPolicy) length=1 GetInfo fail error=1314
- 2904:1884 10:27:13.906 KLeaner is looking in C:\Users\User\AppData\Local\Temp\{688085E2-798F-4A79-A05A-50B50F778617}\jkbasuy1\xsxfr\ for *.ini...
- 2904:1884 10:27:13.907 file found: df0.ini
- 2904:1884 10:27:13.914 no detect
- 2904:1884 10:27:13.914 file found: df1.ini
- 2904:1884 10:27:13.921 no detect
- 2904:1884 10:27:13.922 file found: df10.ini
- 2904:1884 10:27:13.927 no detect
- 2904:1884 10:27:13.927 file found: df100.ini
- 2904:1884 10:27:13.935 no detect
- 2904:1884 10:27:13.935 file found: df101.ini
- 2904:1884 10:27:13.942 no detect
- 2904:1884 10:27:13.942 file found: df102.ini
- 2904:1884 10:27:13.945 This OS is not supported
- 2904:1884 10:27:13.945 no detect
- 2904:1884 10:27:13.945 file found: df11.ini
- 2904:1884 10:27:13.955 This OS is not supported
- 2904:1884 10:27:13.955 no detect
- 2904:1884 10:27:13.955 file found: df12.ini
- 2904:1884 10:27:13.964 This OS is not supported
- 2904:1884 10:27:13.964 no detect
- 2904:1884 10:27:13.964 file found: df13.ini
- 2904:1884 10:27:13.976 no detect
- 2904:1884 10:27:13.976 file found: df14.ini
- 2904:1884 10:27:13.982 This OS is not supported
- 2904:1884 10:27:13.982 no detect
- 2904:1884 10:27:13.982 file found: df15.ini
- 2904:1884 10:27:13.989 This OS is not supported
- 2904:1884 10:27:13.989 no detect
- 2904:1884 10:27:13.989 file found: df16.ini
- 2904:1884 10:27:13.995 This OS is not supported
- 2904:1884 10:27:13.995 no detect
- 2904:1884 10:27:13.995 file found: df17.ini
- 2904:1884 10:27:14.001 This OS is not supported
- 2904:1884 10:27:14.001 no detect
- 2904:1884 10:27:14.001 file found: df18.ini
- 2904:1884 10:27:14.007 This OS is not supported
- 2904:1884 10:27:14.007 no detect
- 2904:1884 10:27:14.007 file found: df19.ini
- 2904:1884 10:27:14.013 no detect
- 2904:1884 10:27:14.013 file found: df2.ini
- 2904:1884 10:27:14.025 no detect
- 2904:1884 10:27:14.025 file found: df20.ini
- 2904:1884 10:27:14.031 no detect
- 2904:1884 10:27:14.031 file found: df21.ini
- 2904:1884 10:27:14.039 no detect
- 2904:1884 10:27:14.040 file found: df22.ini
- 2904:1884 10:27:14.046 no detect
- 2904:1884 10:27:14.046 file found: df23.ini
- 2904:1884 10:27:14.054 no detect
- 2904:1884 10:27:14.054 file found: df24.ini
- 2904:1884 10:27:14.085 no detect
- 2904:1884 10:27:14.085 file found: df25.ini
- 2904:1884 10:27:14.092 no detect
- 2904:1884 10:27:14.092 file found: df26.ini
- 2904:1884 10:27:14.169 no detect
- 2904:1884 10:27:14.169 file found: df27.ini
- 2904:1884 10:27:14.182 no detect
- 2904:1884 10:27:14.182 file found: df28.ini
- 2904:1884 10:27:14.190 no detect
- 2904:1884 10:27:14.190 file found: df29.ini
- 2904:1884 10:27:14.197 no detect
- 2904:1884 10:27:14.197 file found: df3.ini
- 2904:1884 10:27:14.203 no detect
- 2904:1884 10:27:14.204 file found: df30.ini
- 2904:1884 10:27:14.217 no detect
- 2904:1884 10:27:14.217 file found: df31.ini
- 2904:1884 10:27:14.232 no detect
- 2904:1884 10:27:14.232 file found: df32.ini
- 2904:1884 10:27:14.240 no detect
- 2904:1884 10:27:14.240 file found: df33.ini
- 2904:1884 10:27:14.660 no detect
- 2904:1884 10:27:14.661 file found: df34.ini
- 2904:1884 10:27:14.674 no detect
- 2904:1884 10:27:14.674 file found: df35.ini
- 2904:1884 10:27:14.684 no detect
- 2904:1884 10:27:14.684 file found: df36.ini
- 2904:1884 10:27:14.691 no detect
- 2904:1884 10:27:14.691 file found: df37.ini
- 2904:1884 10:27:14.701 no detect
- 2904:1884 10:27:14.701 file found: df38.ini
- 2904:1884 10:27:14.709 no detect
- 2904:1884 10:27:14.709 file found: df39.ini
- 2904:1884 10:27:14.717 found Kaspersky Endpoint Security 11.11 for Windows
- 2904:1884 10:27:14.717 Processing section env_before_removing...
- 2904:1884 10:27:14.717 setup_env: 'env-string-expand-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\KES.21.8\settings->ProductSettingsKeyPath'
- 2904:1884 10:27:14.717 environment string list
- 2904:1884 10:27:14.717 environment: 'ALLUSERSPROFILE=C:\ProgramData'
- 2904:1884 10:27:14.717 environment: 'APPDATA=C:\Users\User\AppData\Roaming'
- 2904:1884 10:27:14.717 environment: 'CommonProgramFiles=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:14.717 environment: 'CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:14.717 environment: 'CommonProgramW6432=C:\Program Files\Common Files'
- 2904:1884 10:27:14.717 environment: 'COMPUTERNAME=MCB-308-5'
- 2904:1884 10:27:14.717 environment: 'ComSpec=C:\WINDOWS\system32\cmd.exe'
- 2904:1884 10:27:14.717 environment: 'DriverData=C:\Windows\System32\Drivers\DriverData'
- 2904:1884 10:27:14.717 environment: 'HOMEDRIVE=C:'
- 2904:1884 10:27:14.717 environment: 'HOMEPATH=\Users\User'
- 2904:1884 10:27:14.717 environment: 'LOCALAPPDATA=C:\Users\User\AppData\Local'
- 2904:1884 10:27:14.717 environment: 'LOGONSERVER=\\MCB-308-5'
- 2904:1884 10:27:14.717 environment: 'MOZ_PLUGIN_PATH=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\'
- 2904:1884 10:27:14.717 environment: 'NUMBER_OF_PROCESSORS=4'
- 2904:1884 10:27:14.717 environment: 'OneDrive=C:\Users\User\OneDrive'
- 2904:1884 10:27:14.717 environment: 'OS=Windows_NT'
- 2904:1884 10:27:14.717 environment: 'ParentFolder=D:\'
- 2904:1884 10:27:14.717 environment: 'Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Users\User\AppData\Local\Microsoft\WindowsApps'
- 2904:1884 10:27:14.717 environment: 'PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC'
- 2904:1884 10:27:14.717 environment: 'PROCESSOR_ARCHITECTURE=x86'
- 2904:1884 10:27:14.717 environment: 'PROCESSOR_ARCHITEW6432=AMD64'
- 2904:1884 10:27:14.717 environment: 'PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 158 Stepping 10, GenuineIntel'
- 2904:1884 10:27:14.717 environment: 'PROCESSOR_LEVEL=6'
- 2904:1884 10:27:14.717 environment: 'PROCESSOR_REVISION=9e0a'
- 2904:1884 10:27:14.717 environment: 'ProductSettingsKeyPath=HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\KES.21.8\settings'
- 2904:1884 10:27:14.717 environment: 'ProgramData=C:\ProgramData'
- 2904:1884 10:27:14.717 environment: 'ProgramFiles=C:\Program Files (x86)'
- 2904:1884 10:27:14.717 environment: 'ProgramFiles(x86)=C:\Program Files (x86)'
- 2904:1884 10:27:14.717 environment: 'ProgramW6432=C:\Program Files'
- 2904:1884 10:27:14.717 environment: 'PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules'
- 2904:1884 10:27:14.717 environment: 'PUBLIC=C:\Users\Public'
- 2904:1884 10:27:14.717 environment: 'SystemDrive=C:'
- 2904:1884 10:27:14.717 environment: 'SystemRoot=C:\WINDOWS'
- 2904:1884 10:27:14.717 environment: 'TEMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:14.717 environment: 'TMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:14.717 environment: 'USERDOMAIN=MCB-308-5'
- 2904:1884 10:27:14.717 environment: 'USERDOMAIN_ROAMINGPROFILE=MCB-308-5'
- 2904:1884 10:27:14.717 environment: 'USERNAME=User'
- 2904:1884 10:27:14.717 environment: 'USERPROFILE=C:\Users\User'
- 2904:1884 10:27:14.717 environment: 'windir=C:\WINDOWS'
- 2904:1884 10:27:14.717 environment: '__COMPAT_LAYER=DetectorsAppHealth Installer'
- 2904:1884 10:27:14.717 Checking password in ProductSettingsKeyPath...
- 2904:1884 10:27:14.718 Password protection on uninstall enabled.
- 2904:1884 10:27:14.718 Password is set
- 2904:1884 10:27:14.718 file found: df4.ini
- 2904:1884 10:27:14.723 no detect
- 2904:1884 10:27:14.723 file found: df40.ini
- 2904:1884 10:27:14.729 no detect
- 2904:1884 10:27:14.729 file found: df41.ini
- 2904:1884 10:27:14.737 no detect
- 2904:1884 10:27:14.737 file found: df42.ini
- 2904:1884 10:27:14.743 no detect
- 2904:1884 10:27:14.743 file found: df43.ini
- 2904:1884 10:27:14.756 no detect
- 2904:1884 10:27:14.756 file found: df44.ini
- 2904:1884 10:27:14.762 no detect
- 2904:1884 10:27:14.762 file found: df45.ini
- 2904:1884 10:27:14.769 no detect
- 2904:1884 10:27:14.770 file found: df46.ini
- 2904:1884 10:27:14.775 no detect
- 2904:1884 10:27:14.775 file found: df47.ini
- 2904:1884 10:27:14.783 no detect
- 2904:1884 10:27:14.783 file found: df48.ini
- 2904:1884 10:27:14.792 no detect
- 2904:1884 10:27:14.792 file found: df49.ini
- 2904:1884 10:27:14.801 no detect
- 2904:1884 10:27:14.801 file found: df5.ini
- 2904:1884 10:27:14.807 no detect
- 2904:1884 10:27:14.807 file found: df50.ini
- 2904:1884 10:27:14.838 no detect
- 2904:1884 10:27:14.838 file found: df51.ini
- 2904:1884 10:27:14.845 no detect
- 2904:1884 10:27:14.845 file found: df52.ini
- 2904:1884 10:27:14.852 no detect
- 2904:1884 10:27:14.853 file found: df53.ini
- 2904:1884 10:27:14.859 no detect
- 2904:1884 10:27:14.860 file found: df54.ini
- 2904:1884 10:27:14.865 Detecting upgrade code 'A6317151A20E6524DB14F80340A3A183,MinVersion=0x00000000,MaxVersion=0xFFFFFFFF'
- 2904:1884 10:27:14.866 upgrade-code='A6317151A20E6524DB14F80340A3A183' MinVersion=true,0 MaxVersion=true,-1
- 2904:1884 10:27:14.866 RegOpenKeyEx(000003D0H\A6317151A20E6524DB14F80340A3A183) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:14.866 Fail! get upgrade code key error: err 2
- 2904:1884 10:27:14.866 no detect
- 2904:1884 10:27:14.866 file found: df55.ini
- 2904:1884 10:27:14.872 This OS is not supported
- 2904:1884 10:27:14.872 no detect
- 2904:1884 10:27:14.873 file found: df56.ini
- 2904:1884 10:27:14.879 This OS is not supported
- 2904:1884 10:27:14.879 no detect
- 2904:1884 10:27:14.879 file found: df57.ini
- 2904:1884 10:27:14.886 no detect
- 2904:1884 10:27:14.886 file found: df58.ini
- 2904:1884 10:27:14.893 no detect
- 2904:1884 10:27:14.894 file found: df59.ini
- 2904:1884 10:27:14.901 This OS is not supported
- 2904:1884 10:27:14.902 no detect
- 2904:1884 10:27:14.902 file found: df6.ini
- 2904:1884 10:27:15.667 no detect
- 2904:1884 10:27:15.667 file found: df60.ini
- 2904:1884 10:27:15.675 Detecting upgrade code 'C4C5F8868570986459B06B66D9B75386,MinVersion=0x00000000,MaxVersion=0xFFFFFFFF'
- 2904:1884 10:27:15.675 upgrade-code='C4C5F8868570986459B06B66D9B75386' MinVersion=true,0 MaxVersion=true,-1
- 2904:1884 10:27:15.675 RegOpenKeyEx(00000408H\C4C5F8868570986459B06B66D9B75386) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.675 Fail! get upgrade code key error: err 2
- 2904:1884 10:27:15.675 no detect
- 2904:1884 10:27:15.675 file found: df61.ini
- 2904:1884 10:27:15.681 This OS is not supported
- 2904:1884 10:27:15.681 no detect
- 2904:1884 10:27:15.681 file found: df62.ini
- 2904:1884 10:27:15.688 Detecting upgrade code '36C901A98B0374C4BA1F81D4D83648E1,MinVersion=0x00000000,MaxVersion=0xFFFFFFFF'
- 2904:1884 10:27:15.688 upgrade-code='36C901A98B0374C4BA1F81D4D83648E1' MinVersion=true,0 MaxVersion=true,-1
- 2904:1884 10:27:15.688 RegOpenKeyEx(00000458H\36C901A98B0374C4BA1F81D4D83648E1) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.688 Fail! get upgrade code key error: err 2
- 2904:1884 10:27:15.688 no detect
- 2904:1884 10:27:15.688 file found: df63.ini
- 2904:1884 10:27:15.769 no detect
- 2904:1884 10:27:15.769 file found: df64.ini
- 2904:1884 10:27:15.776 no detect
- 2904:1884 10:27:15.776 file found: df65.ini
- 2904:1884 10:27:15.808 no detect
- 2904:1884 10:27:15.808 file found: df66.ini
- 2904:1884 10:27:15.816 no detect
- 2904:1884 10:27:15.816 file found: df67.ini
- 2904:1884 10:27:15.823 no detect
- 2904:1884 10:27:15.823 file found: df68.ini
- 2904:1884 10:27:15.828 no detect
- 2904:1884 10:27:15.828 file found: df69.ini
- 2904:1884 10:27:15.833 no detect
- 2904:1884 10:27:15.834 file found: df7.ini
- 2904:1884 10:27:15.839 RegOpenKeyEx(80000002H\SOFTWARE\KasperskyLab\AntiRansom4\Installer\shortcuts) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.839 RegOpenKeyEx(80000002H\SOFTWARE\KasperskyLab\AntiRansom4\Installer\shortcuts) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.839 RegOpenKeyEx(80000002H\SOFTWARE\KasperskyLab\AntiRansom4\Installer\shortcuts) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.839 RegOpenKeyEx(80000002H\SOFTWARE\KasperskyLab\AntiRansom4\Installer\shortcuts) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.839 no detect
- 2904:1884 10:27:15.839 file found: df70.ini
- 2904:1884 10:27:15.845 no detect
- 2904:1884 10:27:15.845 file found: df71.ini
- 2904:1884 10:27:15.849 no detect
- 2904:1884 10:27:15.849 file found: df72.ini
- 2904:1884 10:27:15.856 no detect
- 2904:1884 10:27:15.856 file found: df73.ini
- 2904:1884 10:27:15.860 no detect
- 2904:1884 10:27:15.861 file found: df74.ini
- 2904:1884 10:27:15.865 no detect
- 2904:1884 10:27:15.866 file found: df75.ini
- 2904:1884 10:27:15.872 no detect
- 2904:1884 10:27:15.872 file found: df76.ini
- 2904:1884 10:27:15.879 no detect
- 2904:1884 10:27:15.879 file found: df77.ini
- 2904:1884 10:27:15.885 RegOpenKeyEx(80000002H\SOFTWARE\KasperskyLab\AntiRansom4) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.885 RegOpenKeyEx(80000002H\SOFTWARE\KasperskyLab\AntiRansom4) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.885 no detect
- 2904:1884 10:27:15.886 file found: df78.ini
- 2904:1884 10:27:15.890 Detecting upgrade code 'EC4327A59EB71784E9300F4BA9C7E3A2,MinVersion=0x00000000,MaxVersion=0xFFFFFFFF'
- 2904:1884 10:27:15.890 upgrade-code='EC4327A59EB71784E9300F4BA9C7E3A2' MinVersion=true,0 MaxVersion=true,-1
- 2904:1884 10:27:15.890 RegOpenKeyEx(00000408H\EC4327A59EB71784E9300F4BA9C7E3A2) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.890 Fail! get upgrade code key error: err 2
- 2904:1884 10:27:15.890 no detect
- 2904:1884 10:27:15.890 file found: df79.ini
- 2904:1884 10:27:15.896 Detecting upgrade code 'C0D16C9919DE969458D3A48B6E8D97A2,MinVersion=0x00000000,MaxVersion=0xFFFFFFFF'
- 2904:1884 10:27:15.896 upgrade-code='C0D16C9919DE969458D3A48B6E8D97A2' MinVersion=true,0 MaxVersion=true,-1
- 2904:1884 10:27:15.896 RegOpenKeyEx(00000408H\C0D16C9919DE969458D3A48B6E8D97A2) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:15.896 Fail! get upgrade code key error: err 2
- 2904:1884 10:27:15.896 no detect
- 2904:1884 10:27:15.897 file found: df8.ini
- 2904:1884 10:27:15.904 no detect
- 2904:1884 10:27:15.905 file found: df80.ini
- 2904:1884 10:27:15.911 no detect
- 2904:1884 10:27:15.911 file found: df81.ini
- 2904:1884 10:27:15.917 no detect
- 2904:1884 10:27:15.917 file found: df82.ini
- 2904:1884 10:27:15.924 no detect
- 2904:1884 10:27:15.924 file found: df83.ini
- 2904:1884 10:27:15.931 no detect
- 2904:1884 10:27:15.931 file found: df84.ini
- 2904:1884 10:27:15.938 apply_local_context_command: 'local.x64' 'false'
- 2904:1884 10:27:15.938 no detect
- 2904:1884 10:27:15.938 file found: df85.ini
- 2904:1884 10:27:15.945 no detect
- 2904:1884 10:27:15.945 file found: df86.ini
- 2904:1884 10:27:15.951 no detect
- 2904:1884 10:27:15.952 file found: df87.ini
- 2904:1884 10:27:15.959 no detect
- 2904:1884 10:27:15.959 file found: df88.ini
- 2904:1884 10:27:15.965 no detect
- 2904:1884 10:27:15.966 file found: df89.ini
- 2904:1884 10:27:15.973 no detect
- 2904:1884 10:27:15.973 file found: df9.ini
- 2904:1884 10:27:16.103 no detect
- 2904:1884 10:27:16.103 file found: df90.ini
- 2904:1884 10:27:16.111 no detect
- 2904:1884 10:27:16.111 file found: df91.ini
- 2904:1884 10:27:16.123 no detect
- 2904:1884 10:27:16.123 file found: df92.ini
- 2904:1884 10:27:16.130 no detect
- 2904:1884 10:27:16.130 file found: df93.ini
- 2904:1884 10:27:16.137 no detect
- 2904:1884 10:27:16.137 file found: df94.ini
- 2904:1884 10:27:16.144 no detect
- 2904:1884 10:27:16.144 file found: df95.ini
- 2904:1884 10:27:16.151 no detect
- 2904:1884 10:27:16.151 file found: df96.ini
- 2904:1884 10:27:16.158 no detect
- 2904:1884 10:27:16.158 file found: df97.ini
- 2904:1884 10:27:16.165 no detect
- 2904:1884 10:27:16.165 file found: df98.ini
- 2904:1884 10:27:16.173 no detect
- 2904:1884 10:27:16.173 file found: df99.ini
- 2904:1884 10:27:16.215 RegOpenKeyEx(80000002H\SOFTWARE\Kaspersky Lab\Thread Feed Service\DataPath) failed. Error 2: Не удается найти указанный файл.
- 2904:1884 10:27:16.215 no detect
- 2904:1884 10:27:16.215 Searching finished, product detected.
- 2904:1884 10:27:16.215 Server malloc
- 2904:1884 10:27:16.215 Save detected products succ.
- 2904:1884 10:27:16.215 KLeaner deinitialized
- 2904:1884 10:27:16.215 Stopping shutdown detector...
- 2904:1884 10:27:16.215 Waiting for watch thread stop...
- 2904:0830 10:27:16.215 Watch thread finished
- 2904:1884 10:27:16.215 Watch thread was stopped
- 2904:1884 10:27:16.215 Server free
- 2904:1884 10:27:57.959 Server malloc
- 2904:1884 10:27:57.959 Removing selected products...
- 2904:1884 10:27:57.959 Removing selected product: Kaspersky Endpoint Security 11.11 for Windows.
- 2904:1884 10:27:57.960 ShutdownDetector started watch thread (00000440)
- 2904:1884 10:27:57.961 Kaspersky Removal Tool 1.0.2686
- 2904:1884 10:27:57.961 KLeaner initialized
- 2904:0c90 10:27:57.961 Watch thread started
- 2904:1884 10:27:57.961 MsiparamsCount 0
- 2904:1884 10:27:57.961 OS version = 10.0.19045, 64 bit
- 2904:1884 10:27:57.961 OS info = Майкрософт Windows 10 Pro, CSDVersion="", Version=10.0.19045, BuildNumber=19045
- 2904:1884 10:27:57.961 TraceSystemInfo: Time ticks=850609 ticks64=850609 idle=2918.1093750 kernel=3169.9218750 user=232.3593750
- 2904:1884 10:27:57.961 TraceSystemInfo: System oemId=00000009 pageSize=4096 MinAppAddress=00010000 MaxAppAddress=FFFEFFFF ActiveProcessorMask=0000000F NumberOfProcessors=4 ProcessorType=8664 AllocationGranularity=65536 ProcessorLevel=6 ProcessorRevision=40458
- 2904:1884 10:27:57.961 TraceSystemInfo: Memory Load=56 Phys=1827196928/4161114112 PageFile=2654232576/4899311616 Virtual=2059661312/2147352576 AvailExtendedVirtual=0
- 2904:1884 10:27:57.962 TraceSystemInfo: Performance commit(total=548115,limit=1196121,peak=553504 phis(total=1015897,avail=446093) syscache=457999 kernel(total=91903,paged=53394,nonpaged=38509) page=4096 handles=49127 processes=137 threads=1193
- 2904:1884 10:27:57.963 TraceTokenInformation: class=1(User) length=20 [User[Sid=S-1-5-18,Attributes=0]]
- 2904:1884 10:27:57.963 TraceTokenInformation: class=2(Groups) length=88 [GroupCount=4,[Sid=S-1-5-32-544,Attributes=E],[Sid=S-1-1-0,Attributes=7],[Sid=S-1-5-11,Attributes=7],[Sid=S-1-16-16384,Attributes=60]]
- 2904:1884 10:27:57.967 TraceTokenInformation: class=3(Privileges) length=340 [PrivilegeCount=28,[Luid=SeAssignPrimaryTokenPrivilege,Attributes=0],[Luid=SeLockMemoryPrivilege,Attributes=3],[Luid=SeIncreaseQuotaPrivilege,Attributes=0],[Luid=SeTcbPrivilege,Attributes=3],[Luid=SeSecurityPrivilege,Attributes=0],[Luid=SeTakeOwnershipPrivilege,Attributes=0],[Luid=SeLoadDriverPrivilege,Attributes=0],[Luid=SeSystemProfilePrivilege,Attributes=3],[Luid=SeSystemtimePrivilege,Attributes=0],[Luid=SeProfileSingleProcessPrivilege,Attributes=3],[Luid=SeIncreaseBasePriorityPrivilege,Attributes=3],[Luid=SeCreatePagefilePrivilege,Attributes=3],[Luid=SeCreatePermanentPrivilege,Attributes=3],[Luid=SeBackupPrivilege,Attributes=0],[Luid=SeRestorePrivilege,Attributes=0],[Luid=SeShutdownPrivilege,Attributes=0],[Luid=SeDebugPrivilege,Attributes=3],[Luid=SeAuditPrivilege,Attributes=3],[Luid=SeSystemEnvironmentPrivilege,Attributes=0],[Luid=SeChangeNotifyPrivilege,Attributes=3],[Luid=SeUndockPrivilege,Attributes=0],[Luid=SeManageVolumePrivilege,Attributes=0],[Luid=SeImpersonatePrivilege,Attributes=3],[Luid=SeCreateGlobalPrivilege,Attributes=3],[Luid=SeIncreaseWorkingSetPrivilege,Attributes=3],[Luid=SeTimeZonePrivilege,Attributes=3],[Luid=SeCreateSymbolicLinkPrivilege,Attributes=3],[Luid=SeDelegateSessionUserImpersonatePrivilege,Attributes=3]]
- 2904:1884 10:27:57.967 TraceTokenInformation: class=4(Owner) length=20 [Owner=S-1-5-32-544]
- 2904:1884 10:27:57.967 TraceTokenInformation: class=5(PrimaryGroup) length=16 [PrimaryGroup=S-1-5-18]
- 2904:1884 10:27:57.967 TraceTokenInformation: class=11(RestrictedSids) length=4 [GroupCount=0]
- 2904:1884 10:27:57.967 TraceTokenInformation: class=12(SessionId) length=4 [0(00000000)]
- 2904:1884 10:27:57.967 TraceTokenInformation: class=14(SessionReference) length=1 GetInfo fail error=87
- 2904:1884 10:27:57.967 TraceTokenInformation: class=15(SandBoxInert) length=4 [0(00000000)]
- 2904:1884 10:27:57.967 TraceTokenInformation: class=16(AuditPolicy) length=1 GetInfo fail error=1314
- 2904:1884 10:27:57.967 KLeaner is looking in C:\Users\User\AppData\Local\Temp\{688085E2-798F-4A79-A05A-50B50F778617}\jkbasuy1\xsxfr\ for *.ini...
- 2904:1884 10:27:57.967 file found: df0.ini
- 2904:1884 10:27:57.969 no detect
- 2904:1884 10:27:57.969 file found: df1.ini
- 2904:1884 10:27:57.972 no detect
- 2904:1884 10:27:57.973 file found: df10.ini
- 2904:1884 10:27:57.974 no detect
- 2904:1884 10:27:57.974 file found: df100.ini
- 2904:1884 10:27:57.976 no detect
- 2904:1884 10:27:57.976 file found: df101.ini
- 2904:1884 10:27:57.978 no detect
- 2904:1884 10:27:57.978 file found: df102.ini
- 2904:1884 10:27:57.978 This OS is not supported
- 2904:1884 10:27:57.978 no detect
- 2904:1884 10:27:57.978 file found: df11.ini
- 2904:1884 10:27:57.980 This OS is not supported
- 2904:1884 10:27:57.980 no detect
- 2904:1884 10:27:57.980 file found: df12.ini
- 2904:1884 10:27:57.983 This OS is not supported
- 2904:1884 10:27:57.983 no detect
- 2904:1884 10:27:57.983 file found: df13.ini
- 2904:1884 10:27:57.985 no detect
- 2904:1884 10:27:57.985 file found: df14.ini
- 2904:1884 10:27:57.986 This OS is not supported
- 2904:1884 10:27:57.986 no detect
- 2904:1884 10:27:57.986 file found: df15.ini
- 2904:1884 10:27:57.989 This OS is not supported
- 2904:1884 10:27:57.989 no detect
- 2904:1884 10:27:57.989 file found: df16.ini
- 2904:1884 10:27:57.990 This OS is not supported
- 2904:1884 10:27:57.990 no detect
- 2904:1884 10:27:57.990 file found: df17.ini
- 2904:1884 10:27:57.992 This OS is not supported
- 2904:1884 10:27:57.992 no detect
- 2904:1884 10:27:57.992 file found: df18.ini
- 2904:1884 10:27:57.993 This OS is not supported
- 2904:1884 10:27:57.993 no detect
- 2904:1884 10:27:57.993 file found: df19.ini
- 2904:1884 10:27:57.995 no detect
- 2904:1884 10:27:57.995 file found: df2.ini
- 2904:1884 10:27:57.997 no detect
- 2904:1884 10:27:57.997 file found: df20.ini
- 2904:1884 10:27:58.000 no detect
- 2904:1884 10:27:58.000 file found: df21.ini
- 2904:1884 10:27:58.002 no detect
- 2904:1884 10:27:58.002 file found: df22.ini
- 2904:1884 10:27:58.005 no detect
- 2904:1884 10:27:58.005 file found: df23.ini
- 2904:1884 10:27:58.007 no detect
- 2904:1884 10:27:58.007 file found: df24.ini
- 2904:1884 10:27:58.010 no detect
- 2904:1884 10:27:58.010 file found: df25.ini
- 2904:1884 10:27:58.012 no detect
- 2904:1884 10:27:58.012 file found: df26.ini
- 2904:1884 10:27:58.014 no detect
- 2904:1884 10:27:58.014 file found: df27.ini
- 2904:1884 10:27:58.017 no detect
- 2904:1884 10:27:58.017 file found: df28.ini
- 2904:1884 10:27:58.020 no detect
- 2904:1884 10:27:58.020 file found: df29.ini
- 2904:1884 10:27:58.022 no detect
- 2904:1884 10:27:58.022 file found: df3.ini
- 2904:1884 10:27:58.023 no detect
- 2904:1884 10:27:58.023 file found: df30.ini
- 2904:1884 10:27:58.025 no detect
- 2904:1884 10:27:58.025 file found: df31.ini
- 2904:1884 10:27:58.028 no detect
- 2904:1884 10:27:58.028 file found: df32.ini
- 2904:1884 10:27:58.030 no detect
- 2904:1884 10:27:58.031 file found: df33.ini
- 2904:1884 10:27:58.031 no detect
- 2904:1884 10:27:58.032 file found: df34.ini
- 2904:1884 10:27:58.034 no detect
- 2904:1884 10:27:58.034 file found: df35.ini
- 2904:1884 10:27:58.036 no detect
- 2904:1884 10:27:58.036 file found: df36.ini
- 2904:1884 10:27:58.038 no detect
- 2904:1884 10:27:58.038 file found: df37.ini
- 2904:1884 10:27:58.042 no detect
- 2904:1884 10:27:58.042 file found: df38.ini
- 2904:1884 10:27:58.044 no detect
- 2904:1884 10:27:58.045 file found: df39.ini
- 2904:1884 10:27:58.047 found Kaspersky Endpoint Security 11.11 for Windows
- 2904:1884 10:27:58.047 Processing section env_before_removing...
- 2904:1884 10:27:58.047 setup_env: 'env-string-expand-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\KES.21.8\settings->ProductSettingsKeyPath'
- 2904:1884 10:27:58.047 environment string list
- 2904:1884 10:27:58.048 environment: 'ALLUSERSPROFILE=C:\ProgramData'
- 2904:1884 10:27:58.048 environment: 'APPDATA=C:\Users\User\AppData\Roaming'
- 2904:1884 10:27:58.048 environment: 'CommonProgramFiles=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.048 environment: 'CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.048 environment: 'CommonProgramW6432=C:\Program Files\Common Files'
- 2904:1884 10:27:58.048 environment: 'COMPUTERNAME=MCB-308-5'
- 2904:1884 10:27:58.048 environment: 'ComSpec=C:\WINDOWS\system32\cmd.exe'
- 2904:1884 10:27:58.048 environment: 'DriverData=C:\Windows\System32\Drivers\DriverData'
- 2904:1884 10:27:58.048 environment: 'HOMEDRIVE=C:'
- 2904:1884 10:27:58.048 environment: 'HOMEPATH=\Users\User'
- 2904:1884 10:27:58.048 environment: 'LOCALAPPDATA=C:\Users\User\AppData\Local'
- 2904:1884 10:27:58.048 environment: 'LOGONSERVER=\\MCB-308-5'
- 2904:1884 10:27:58.048 environment: 'MOZ_PLUGIN_PATH=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\'
- 2904:1884 10:27:58.048 environment: 'NUMBER_OF_PROCESSORS=4'
- 2904:1884 10:27:58.048 environment: 'OneDrive=C:\Users\User\OneDrive'
- 2904:1884 10:27:58.048 environment: 'OS=Windows_NT'
- 2904:1884 10:27:58.048 environment: 'ParentFolder=D:\'
- 2904:1884 10:27:58.048 environment: 'Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Users\User\AppData\Local\Microsoft\WindowsApps'
- 2904:1884 10:27:58.048 environment: 'PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC'
- 2904:1884 10:27:58.048 environment: 'PROCESSOR_ARCHITECTURE=x86'
- 2904:1884 10:27:58.048 environment: 'PROCESSOR_ARCHITEW6432=AMD64'
- 2904:1884 10:27:58.048 environment: 'PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 158 Stepping 10, GenuineIntel'
- 2904:1884 10:27:58.048 environment: 'PROCESSOR_LEVEL=6'
- 2904:1884 10:27:58.048 environment: 'PROCESSOR_REVISION=9e0a'
- 2904:1884 10:27:58.048 environment: 'ProductSettingsKeyPath=HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\KES.21.8\settings'
- 2904:1884 10:27:58.048 environment: 'ProgramData=C:\ProgramData'
- 2904:1884 10:27:58.048 environment: 'ProgramFiles=C:\Program Files (x86)'
- 2904:1884 10:27:58.048 environment: 'ProgramFiles(x86)=C:\Program Files (x86)'
- 2904:1884 10:27:58.048 environment: 'ProgramW6432=C:\Program Files'
- 2904:1884 10:27:58.048 environment: 'PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules'
- 2904:1884 10:27:58.048 environment: 'PUBLIC=C:\Users\Public'
- 2904:1884 10:27:58.048 environment: 'SystemDrive=C:'
- 2904:1884 10:27:58.048 environment: 'SystemRoot=C:\WINDOWS'
- 2904:1884 10:27:58.048 environment: 'TEMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:58.048 environment: 'TMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:58.048 environment: 'USERDOMAIN=MCB-308-5'
- 2904:1884 10:27:58.048 environment: 'USERDOMAIN_ROAMINGPROFILE=MCB-308-5'
- 2904:1884 10:27:58.048 environment: 'USERNAME=User'
- 2904:1884 10:27:58.048 environment: 'USERPROFILE=C:\Users\User'
- 2904:1884 10:27:58.048 environment: 'windir=C:\WINDOWS'
- 2904:1884 10:27:58.048 environment: '__COMPAT_LAYER=DetectorsAppHealth Installer'
- 2904:1884 10:27:58.048 Checking password in ProductSettingsKeyPath...
- 2904:1884 10:27:58.048 Password protection on uninstall enabled.
- 2904:1884 10:27:58.048 Password is set
- 2904:1884 10:27:58.048 removing Kaspersky Endpoint Security 11.11 for Windows...
- 2904:1884 10:27:58.048 TraceSystemInfo: Time ticks=850703 ticks64=850703 idle=2918.3281250 kernel=3170.2031250 user=232.4531250
- 2904:1884 10:27:58.048 TraceSystemInfo: System oemId=00000009 pageSize=4096 MinAppAddress=00010000 MaxAppAddress=FFFEFFFF ActiveProcessorMask=0000000F NumberOfProcessors=4 ProcessorType=8664 AllocationGranularity=65536 ProcessorLevel=6 ProcessorRevision=40458
- 2904:1884 10:27:58.048 TraceSystemInfo: Memory Load=56 Phys=1826340864/4161114112 PageFile=2654265344/4899311616 Virtual=2059661312/2147352576 AvailExtendedVirtual=0
- 2904:1884 10:27:58.049 TraceSystemInfo: Performance commit(total=548107,limit=1196121,peak=553504 phis(total=1015897,avail=445884) syscache=457981 kernel(total=91903,paged=53394,nonpaged=38509) page=4096 handles=49124 processes=137 threads=1193
- 2904:1884 10:27:58.049 TraceTokenInformation: class=1(User) length=20 [User[Sid=S-1-5-18,Attributes=0]]
- 2904:1884 10:27:58.050 TraceTokenInformation: class=2(Groups) length=88 [GroupCount=4,[Sid=S-1-5-32-544,Attributes=E],[Sid=S-1-1-0,Attributes=7],[Sid=S-1-5-11,Attributes=7],[Sid=S-1-16-16384,Attributes=60]]
- 2904:1884 10:27:58.052 TraceTokenInformation: class=3(Privileges) length=340 [PrivilegeCount=28,[Luid=SeAssignPrimaryTokenPrivilege,Attributes=0],[Luid=SeLockMemoryPrivilege,Attributes=3],[Luid=SeIncreaseQuotaPrivilege,Attributes=0],[Luid=SeTcbPrivilege,Attributes=3],[Luid=SeSecurityPrivilege,Attributes=0],[Luid=SeTakeOwnershipPrivilege,Attributes=0],[Luid=SeLoadDriverPrivilege,Attributes=0],[Luid=SeSystemProfilePrivilege,Attributes=3],[Luid=SeSystemtimePrivilege,Attributes=0],[Luid=SeProfileSingleProcessPrivilege,Attributes=3],[Luid=SeIncreaseBasePriorityPrivilege,Attributes=3],[Luid=SeCreatePagefilePrivilege,Attributes=3],[Luid=SeCreatePermanentPrivilege,Attributes=3],[Luid=SeBackupPrivilege,Attributes=0],[Luid=SeRestorePrivilege,Attributes=0],[Luid=SeShutdownPrivilege,Attributes=0],[Luid=SeDebugPrivilege,Attributes=3],[Luid=SeAuditPrivilege,Attributes=3],[Luid=SeSystemEnvironmentPrivilege,Attributes=0],[Luid=SeChangeNotifyPrivilege,Attributes=3],[Luid=SeUndockPrivilege,Attributes=0],[Luid=SeManageVolumePrivilege,Attributes=0],[Luid=SeImpersonatePrivilege,Attributes=3],[Luid=SeCreateGlobalPrivilege,Attributes=3],[Luid=SeIncreaseWorkingSetPrivilege,Attributes=3],[Luid=SeTimeZonePrivilege,Attributes=3],[Luid=SeCreateSymbolicLinkPrivilege,Attributes=3],[Luid=SeDelegateSessionUserImpersonatePrivilege,Attributes=3]]
- 2904:1884 10:27:58.052 TraceTokenInformation: class=4(Owner) length=20 [Owner=S-1-5-32-544]
- 2904:1884 10:27:58.052 TraceTokenInformation: class=5(PrimaryGroup) length=16 [PrimaryGroup=S-1-5-18]
- 2904:1884 10:27:58.052 TraceTokenInformation: class=11(RestrictedSids) length=4 [GroupCount=0]
- 2904:1884 10:27:58.052 TraceTokenInformation: class=12(SessionId) length=4 [0(00000000)]
- 2904:1884 10:27:58.052 TraceTokenInformation: class=14(SessionReference) length=1 GetInfo fail error=87
- 2904:1884 10:27:58.052 TraceTokenInformation: class=15(SandBoxInert) length=4 [0(00000000)]
- 2904:1884 10:27:58.052 TraceTokenInformation: class=16(AuditPolicy) length=1 GetInfo fail error=1314
- 2904:1884 10:27:58.052 adjust_privilege(SeRestorePrivilege)
- 2904:1884 10:27:58.052 adjust_privilege(SeBackupPrivilege)
- 2904:1884 10:27:58.052 adjusting privileges - OK
- 2904:1884 10:27:58.052 Processing section main...
- 2904:1884 10:27:58.052 The 'Kaspersky Endpoint Security 11.11 for Windows' has been detected
- 2904:1884 10:27:58.052 setup_env: 'name' 'Kaspersky Endpoint Security 11.11 for Windows'
- 2904:1884 10:27:58.052 setup_env: action handler not found
- 2904:1884 10:27:58.052 setup_env: 'fullname' 'Kaspersky Endpoint Security 11.11 for Windows'
- 2904:1884 10:27:58.052 setup_env: action handler not found
- 2904:1884 10:27:58.053 setup_env: 'detect-msi' '{BF39B547-8E24-4E11-8179-183B2F7C83EB}'
- 2904:1884 10:27:58.053 setup_env: action handler not found
- 2904:1884 10:27:58.053 setup_env: 'type' 'uninstall'
- 2904:1884 10:27:58.053 setup_env: action handler not found
- 2904:1884 10:27:58.053 setup_env: 'uninstallmode' 'custom_support_password'
- 2904:1884 10:27:58.053 setup_env: action handler not found
- 2904:1884 10:27:58.053 setup_env: 'password-protection-type' 'login_password'
- 2904:1884 10:27:58.053 setup_env: action handler not found
- 2904:1884 10:27:58.053 setup_env: 'os' 'winnt'
- 2904:1884 10:27:58.053 setup_env: action handler not found
- 2904:1884 10:27:58.053 setup_env: 'x64' 'by_os'
- 2904:1884 10:27:58.053 setup_env: action handler not found
- 2904:1884 10:27:58.053 environment string list
- 2904:1884 10:27:58.053 environment: 'ALLUSERSPROFILE=C:\ProgramData'
- 2904:1884 10:27:58.053 environment: 'APPDATA=C:\Users\User\AppData\Roaming'
- 2904:1884 10:27:58.053 environment: 'CommonProgramFiles=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.053 environment: 'CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.053 environment: 'CommonProgramW6432=C:\Program Files\Common Files'
- 2904:1884 10:27:58.053 environment: 'COMPUTERNAME=MCB-308-5'
- 2904:1884 10:27:58.053 environment: 'ComSpec=C:\WINDOWS\system32\cmd.exe'
- 2904:1884 10:27:58.053 environment: 'DriverData=C:\Windows\System32\Drivers\DriverData'
- 2904:1884 10:27:58.053 environment: 'HOMEDRIVE=C:'
- 2904:1884 10:27:58.053 environment: 'HOMEPATH=\Users\User'
- 2904:1884 10:27:58.053 environment: 'LOCALAPPDATA=C:\Users\User\AppData\Local'
- 2904:1884 10:27:58.053 environment: 'LOGONSERVER=\\MCB-308-5'
- 2904:1884 10:27:58.053 environment: 'MOZ_PLUGIN_PATH=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\'
- 2904:1884 10:27:58.053 environment: 'NUMBER_OF_PROCESSORS=4'
- 2904:1884 10:27:58.053 environment: 'OneDrive=C:\Users\User\OneDrive'
- 2904:1884 10:27:58.053 environment: 'OS=Windows_NT'
- 2904:1884 10:27:58.053 environment: 'ParentFolder=D:\'
- 2904:1884 10:27:58.053 environment: 'Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Users\User\AppData\Local\Microsoft\WindowsApps'
- 2904:1884 10:27:58.053 environment: 'PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC'
- 2904:1884 10:27:58.053 environment: 'PROCESSOR_ARCHITECTURE=x86'
- 2904:1884 10:27:58.053 environment: 'PROCESSOR_ARCHITEW6432=AMD64'
- 2904:1884 10:27:58.053 environment: 'PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 158 Stepping 10, GenuineIntel'
- 2904:1884 10:27:58.053 environment: 'PROCESSOR_LEVEL=6'
- 2904:1884 10:27:58.053 environment: 'PROCESSOR_REVISION=9e0a'
- 2904:1884 10:27:58.053 environment: 'ProgramData=C:\ProgramData'
- 2904:1884 10:27:58.053 environment: 'ProgramFiles=C:\Program Files (x86)'
- 2904:1884 10:27:58.053 environment: 'ProgramFiles(x86)=C:\Program Files (x86)'
- 2904:1884 10:27:58.053 environment: 'ProgramW6432=C:\Program Files'
- 2904:1884 10:27:58.053 environment: 'PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules'
- 2904:1884 10:27:58.053 environment: 'PUBLIC=C:\Users\Public'
- 2904:1884 10:27:58.053 environment: 'SystemDrive=C:'
- 2904:1884 10:27:58.053 environment: 'SystemRoot=C:\WINDOWS'
- 2904:1884 10:27:58.053 environment: 'TEMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:58.053 environment: 'TMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:58.053 environment: 'USERDOMAIN=MCB-308-5'
- 2904:1884 10:27:58.053 environment: 'USERDOMAIN_ROAMINGPROFILE=MCB-308-5'
- 2904:1884 10:27:58.053 environment: 'USERNAME=User'
- 2904:1884 10:27:58.053 environment: 'USERPROFILE=C:\Users\User'
- 2904:1884 10:27:58.053 environment: 'windir=C:\WINDOWS'
- 2904:1884 10:27:58.053 environment: '__COMPAT_LAYER=DetectorsAppHealth Installer'
- 2904:1884 10:27:58.053 context: RemoveKLSelfDefense=1, x64=1, ProductIdX64=1, selfDefenseAction=0, extensionLevel=0
- 2904:1884 10:27:58.053 Processing section script...
- 2904:1884 10:27:58.053 start script::process
- 2904:1884 10:27:58.053 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.053 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.053 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.053 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.053 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.053 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.053 RegSvr32Dll
- 2904:1884 10:27:58.108 RegSvr32Dll CreateProcess ret=1 code=0
- 2904:1884 10:27:58.108 RegSvr32Dll WaitProcess h=0x00000398 pid=3384
- 2904:1884 10:27:58.195 RegSvr32Dll WaitProcess ret=0
- 2904:1884 10:27:58.195 RegSvr32Dll
- 2904:1884 10:27:58.201 RegSvr32Dll CreateProcess ret=1 code=0
- 2904:1884 10:27:58.201 RegSvr32Dll WaitProcess h=0x00000390 pid=5172
- 2904:1884 10:27:58.220 RegSvr32Dll WaitProcess ret=0
- 2904:1884 10:27:58.227 extracting resource to 'C:\Users\User\AppData\Local\Temp\actFBBB.tmp'...
- 2904:1884 10:27:58.228 Resource (404800 bytes) successfully dumped
- 2904:1884 10:27:58.228 cmdline: '"C:\Users\User\AppData\Local\Temp\actFBBB.tmp" remove vbs "param"'
- 2904:1884 10:27:58.228 running utility...
- 2904:1884 10:27:58.438 x64 utility run (exit code = 2), cmd: "C:\Users\User\AppData\Local\Temp\actFBBB.tmp" remove vbs "param"
- 2904:1884 10:27:58.438 ------Utility Stdout v ---
- 6792:0abc 10:27:58.329 64-bit utility started, params: 'remove vbs param'
- 6792:0abc 10:27:58.329 Command detected: restore original DLLs for VBS
- 6792:0abc 10:27:58.329 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 6792:0abc 10:27:58.329 OriginalDLL: value missing, err 2
- 6792:0abc 10:27:58.329 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 6792:0abc 10:27:58.329 OriginalDLL: value missing, err 2
- 6792:0abc 10:27:58.329 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 6792:0abc 10:27:58.329 OriginalDLL: value missing, err 2
- 6792:0abc 10:27:58.329 RegSvr32Dll
- 6792:0abc 10:27:58.348 RegSvr32Dll CreateProcess ret=1 code=0
- 6792:0abc 10:27:58.348 RegSvr32Dll WaitProcess h=0x00000184 pid=4320
- 6792:0abc 10:27:58.417 RegSvr32Dll WaitProcess ret=0
- 6792:0abc 10:27:58.417 RegSvr32Dll
- 6792:0abc 10:27:58.421 RegSvr32Dll CreateProcess ret=1 code=0
- 6792:0abc 10:27:58.421 RegSvr32Dll WaitProcess h=0x00000180 pid=4456
- 6792:0abc 10:27:58.436 RegSvr32Dll WaitProcess ret=0
- 6792:0abc 10:27:58.436 64-bit utility finished, return code = 2
- 2904:1884 10:27:58.438 ------Utility Stdout ^ ---
- 2904:1884 10:27:58.438 Utility Stderr is empty
- 2904:1884 10:27:58.438 Module.Init(cleanapi.dll=00000000)
- 2904:1884 10:27:58.438 creating kleaner host object...
- 2904:1884 10:27:58.490 creating ActiveScriptSite...
- 2904:1884 10:27:58.661 parsing script...
- 2904:1884 10:27:58.663 execute script...
- 2904:1884 10:27:58.663 detect FDE...
- 2904:1884 10:27:58.719 GetEncryptedDiskCountKES return 0. Continue processing.
- 2904:1884 10:27:58.731 script execution finished
- 2904:1884 10:27:58.731 end script::process
- 2904:1884 10:27:58.731 Processing section environment...
- 2904:1884 10:27:58.731 setup_env: 'env-string' 'Kaspersky Endpoint Security for Windows->DefaultProductName'
- 2904:1884 10:27:58.731 apply_local_context_command: 'local.x64' 'false'
- 2904:1884 10:27:58.731 setup_env: 'env-string-expand-utf' '%ProgramFiles%\Kaspersky Lab\Kaspersky Endpoint Security for Windows->DefaultProductRoot'
- 2904:1884 10:27:58.731 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\software\KasperskyLab\protected\KES.21.8\environment\ProductRoot->InstDir'
- 2904:1884 10:27:58.731 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\KES.21.8\environment\DataRoot->BasesDir'
- 2904:1884 10:27:58.731 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\protected\KES.21.8\environment\ProductName->ProductName'
- 2904:1884 10:27:58.731 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir->CommonFilesDir'
- 2904:1884 10:27:58.731 setup_env: 'env-string' '{BF39B547-8E24-4E11-8179-183B2F7C83EB}->InstallUid'
- 2904:1884 10:27:58.731 setup_env: 'env-registry-utf' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BF39B547-8E24-4E11-8179-183B2F7C83EB}\InstallLocation->InstallerUserDataInstallLocation'
- 2904:1884 10:27:58.731 setup_env: 'env-registry' 'HKEY_CLASSES_ROOT\Installer\Products\745B93FB42E811E4189781B3F2C738BE\ProductName->InstallerProductName'
- 2904:1884 10:27:58.732 setup_env: 'env-string' '745B93FB42E811E4189781B3F2C738BE->ProductId'
- 2904:1884 10:27:58.732 setup_env: 'env-string' '25EB107917D5AED46B14CA321C56A2DB->UpgradeCodeCompressed'
- 2904:1884 10:27:58.732 setup_env: 'env-string' '{9701BE52-5D71-4DEA-B641-AC23C1652ABD}->UpgradeCodeId'
- 2904:1884 10:27:58.732 apply_local_context_command: 'local.x64' 'default'
- 2904:1884 10:27:58.732 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE\Path->OutlookPathNative'
- 2904:1884 10:27:58.732 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir->CommonPrograms'
- 2904:1884 10:27:58.732 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)->CommonProgramsX86'
- 2904:1884 10:27:58.732 apply_local_context_command: 'local.x64' 'false'
- 2904:1884 10:27:58.732 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData->AppDataFolder'
- 2904:1884 10:27:58.732 setup_env: 'env-registry' 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE\Path->OutlookPathWow'
- 2904:1884 10:27:58.732 environment string list
- 2904:1884 10:27:58.732 environment: 'ALLUSERSPROFILE=C:\ProgramData'
- 2904:1884 10:27:58.732 environment: 'APPDATA=C:\Users\User\AppData\Roaming'
- 2904:1884 10:27:58.732 environment: 'AppDataFolder=C:\ProgramData'
- 2904:1884 10:27:58.732 environment: 'BasesDir=C:\ProgramData\Kaspersky Lab\KES.21.8'
- 2904:1884 10:27:58.732 environment: 'CommonFilesDir=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.732 environment: 'CommonProgramFiles=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.732 environment: 'CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.732 environment: 'CommonPrograms=C:\Program Files\Common Files'
- 2904:1884 10:27:58.732 environment: 'CommonProgramsX86=C:\Program Files (x86)\Common Files'
- 2904:1884 10:27:58.732 environment: 'CommonProgramW6432=C:\Program Files\Common Files'
- 2904:1884 10:27:58.732 environment: 'COMPUTERNAME=MCB-308-5'
- 2904:1884 10:27:58.732 environment: 'ComSpec=C:\WINDOWS\system32\cmd.exe'
- 2904:1884 10:27:58.732 environment: 'DefaultProductName=Kaspersky Endpoint Security for Windows'
- 2904:1884 10:27:58.732 environment: 'DefaultProductRoot=C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security for Windows'
- 2904:1884 10:27:58.732 environment: 'DriverData=C:\Windows\System32\Drivers\DriverData'
- 2904:1884 10:27:58.732 environment: 'HOMEDRIVE=C:'
- 2904:1884 10:27:58.732 environment: 'HOMEPATH=\Users\User'
- 2904:1884 10:27:58.732 environment: 'InstallerProductName=Kaspersky Endpoint Security для Windows'
- 2904:1884 10:27:58.732 environment: 'InstallerUserDataInstallLocation=C:\Program Files (x86)\Kaspersky Lab\KES.11.11.0\'
- 2904:1884 10:27:58.732 environment: 'InstallUid={BF39B547-8E24-4E11-8179-183B2F7C83EB}'
- 2904:1884 10:27:58.732 environment: 'InstDir=C:\Program Files (x86)\Kaspersky Lab\KES.11.11.0'
- 2904:1884 10:27:58.732 environment: 'LOCALAPPDATA=C:\Users\User\AppData\Local'
- 2904:1884 10:27:58.732 environment: 'LOGONSERVER=\\MCB-308-5'
- 2904:1884 10:27:58.732 environment: 'MOZ_PLUGIN_PATH=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\'
- 2904:1884 10:27:58.732 environment: 'NUMBER_OF_PROCESSORS=4'
- 2904:1884 10:27:58.732 environment: 'OneDrive=C:\Users\User\OneDrive'
- 2904:1884 10:27:58.732 environment: 'OS=Windows_NT'
- 2904:1884 10:27:58.732 environment: 'OutlookPathNative=C:\Program Files\Microsoft Office\Root\Office16\'
- 2904:1884 10:27:58.732 environment: 'OutlookPathWow=C:\Program Files\Microsoft Office\Root\Office16\'
- 2904:1884 10:27:58.732 environment: 'ParentFolder=D:\'
- 2904:1884 10:27:58.732 environment: 'Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Users\User\AppData\Local\Microsoft\WindowsApps'
- 2904:1884 10:27:58.732 environment: 'PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC'
- 2904:1884 10:27:58.732 environment: 'PROCESSOR_ARCHITECTURE=x86'
- 2904:1884 10:27:58.732 environment: 'PROCESSOR_ARCHITEW6432=AMD64'
- 2904:1884 10:27:58.732 environment: 'PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 158 Stepping 10, GenuineIntel'
- 2904:1884 10:27:58.732 environment: 'PROCESSOR_LEVEL=6'
- 2904:1884 10:27:58.732 environment: 'PROCESSOR_REVISION=9e0a'
- 2904:1884 10:27:58.732 environment: 'ProductId=745B93FB42E811E4189781B3F2C738BE'
- 2904:1884 10:27:58.732 environment: 'ProductName=Kaspersky Endpoint Security для Windows'
- 2904:1884 10:27:58.732 environment: 'ProgramData=C:\ProgramData'
- 2904:1884 10:27:58.732 environment: 'ProgramFiles=C:\Program Files (x86)'
- 2904:1884 10:27:58.732 environment: 'ProgramFiles(x86)=C:\Program Files (x86)'
- 2904:1884 10:27:58.732 environment: 'ProgramW6432=C:\Program Files'
- 2904:1884 10:27:58.732 environment: 'PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules'
- 2904:1884 10:27:58.732 environment: 'PUBLIC=C:\Users\Public'
- 2904:1884 10:27:58.732 environment: 'SystemDrive=C:'
- 2904:1884 10:27:58.732 environment: 'SystemRoot=C:\WINDOWS'
- 2904:1884 10:27:58.732 environment: 'TEMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:58.732 environment: 'TMP=C:\Users\User\AppData\Local\Temp'
- 2904:1884 10:27:58.732 environment: 'UpgradeCodeCompressed=25EB107917D5AED46B14CA321C56A2DB'
- 2904:1884 10:27:58.732 environment: 'UpgradeCodeId={9701BE52-5D71-4DEA-B641-AC23C1652ABD}'
- 2904:1884 10:27:58.732 environment: 'USERDOMAIN=MCB-308-5'
- 2904:1884 10:27:58.732 environment: 'USERDOMAIN_ROAMINGPROFILE=MCB-308-5'
- 2904:1884 10:27:58.732 environment: 'USERNAME=User'
- 2904:1884 10:27:58.732 environment: 'USERPROFILE=C:\Users\User'
- 2904:1884 10:27:58.732 environment: 'windir=C:\WINDOWS'
- 2904:1884 10:27:58.732 environment: '__COMPAT_LAYER=DetectorsAppHealth Installer'
- 2904:1884 10:27:58.732 Processing section script...
- 2904:1884 10:27:58.732 start script::process
- 2904:1884 10:27:58.732 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.733 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.733 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.733 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.733 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.733 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.733 RegSvr32Dll
- 2904:1884 10:27:58.738 RegSvr32Dll CreateProcess ret=1 code=0
- 2904:1884 10:27:58.738 RegSvr32Dll WaitProcess h=0x00000474 pid=5824
- 2904:1884 10:27:58.759 RegSvr32Dll WaitProcess ret=0
- 2904:1884 10:27:58.759 RegSvr32Dll
- 2904:1884 10:27:58.768 RegSvr32Dll CreateProcess ret=1 code=0
- 2904:1884 10:27:58.768 RegSvr32Dll WaitProcess h=0x000004D4 pid=3292
- 2904:1884 10:27:58.791 RegSvr32Dll WaitProcess ret=0
- 2904:1884 10:27:58.791 cmdline: '"C:\Users\User\AppData\Local\Temp\actFBBB.tmp" remove vbs "param"'
- 2904:1884 10:27:58.791 running utility...
- 2904:1884 10:27:58.927 x64 utility run (exit code = 2), cmd: "C:\Users\User\AppData\Local\Temp\actFBBB.tmp" remove vbs "param"
- 2904:1884 10:27:58.927 ------Utility Stdout v ---
- 2708:1238 10:27:58.883 64-bit utility started, params: 'remove vbs param'
- 2708:1238 10:27:58.883 Command detected: restore original DLLs for VBS
- 2708:1238 10:27:58.883 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 2708:1238 10:27:58.883 OriginalDLL: value missing, err 2
- 2708:1238 10:27:58.883 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 2708:1238 10:27:58.883 OriginalDLL: value missing, err 2
- 2708:1238 10:27:58.883 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 2708:1238 10:27:58.883 OriginalDLL: value missing, err 2
- 2708:1238 10:27:58.883 RegSvr32Dll
- 2708:1238 10:27:58.887 RegSvr32Dll CreateProcess ret=1 code=0
- 2708:1238 10:27:58.887 RegSvr32Dll WaitProcess h=0x00000180 pid=1040
- 2708:1238 10:27:58.901 RegSvr32Dll WaitProcess ret=0
- 2708:1238 10:27:58.901 RegSvr32Dll
- 2708:1238 10:27:58.906 RegSvr32Dll CreateProcess ret=1 code=0
- 2708:1238 10:27:58.906 RegSvr32Dll WaitProcess h=0x000000B4 pid=5432
- 2708:1238 10:27:58.924 RegSvr32Dll WaitProcess ret=0
- 2708:1238 10:27:58.924 64-bit utility finished, return code = 2
- 2904:1884 10:27:58.927 ------Utility Stdout ^ ---
- 2904:1884 10:27:58.927 Utility Stderr is empty
- 2904:1884 10:27:58.927 creating kleaner host object...
- 2904:1884 10:27:58.928 creating ActiveScriptSite...
- 2904:1884 10:27:58.933 parsing script...
- 2904:1884 10:27:58.933 execute script...
- 2904:1884 10:27:58.974 script execution finished
- 2904:1884 10:27:58.976 end script::process
- 2904:1884 10:27:58.976 Processing section script...
- 2904:1884 10:27:58.976 start script::process
- 2904:1884 10:27:58.976 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.976 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.976 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.976 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.976 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 2904:1884 10:27:58.976 OriginalDLL: value missing, err 2
- 2904:1884 10:27:58.976 RegSvr32Dll
- 2904:1884 10:27:58.986 RegSvr32Dll CreateProcess ret=1 code=0
- 2904:1884 10:27:58.986 RegSvr32Dll WaitProcess h=0x000004D8 pid=1380
- 2904:1884 10:27:59.012 RegSvr32Dll WaitProcess ret=0
- 2904:1884 10:27:59.012 RegSvr32Dll
- 2904:1884 10:27:59.018 RegSvr32Dll CreateProcess ret=1 code=0
- 2904:1884 10:27:59.019 RegSvr32Dll WaitProcess h=0x000004F8 pid=4384
- 2904:1884 10:27:59.041 RegSvr32Dll WaitProcess ret=0
- 2904:1884 10:27:59.041 cmdline: '"C:\Users\User\AppData\Local\Temp\actFBBB.tmp" remove vbs "param"'
- 2904:1884 10:27:59.041 running utility...
- 2904:1884 10:27:59.110 x64 utility run (exit code = 2), cmd: "C:\Users\User\AppData\Local\Temp\actFBBB.tmp" remove vbs "param"
- 2904:1884 10:27:59.110 ------Utility Stdout v ---
- 6360:00e4 10:27:59.066 64-bit utility started, params: 'remove vbs param'
- 6360:00e4 10:27:59.066 Command detected: restore original DLLs for VBS
- 6360:00e4 10:27:59.066 OriginalDLL: try restore {B54F3741-5B07-11cf-A4B0-00AA004A55E8}
- 6360:00e4 10:27:59.066 OriginalDLL: value missing, err 2
- 6360:00e4 10:27:59.066 OriginalDLL: try restore {B54F3742-5B07-11cf-A4B0-00AA004A55E8}
- 6360:00e4 10:27:59.066 OriginalDLL: value missing, err 2
- 6360:00e4 10:27:59.066 OriginalDLL: try restore {B54F3743-5B07-11cf-A4B0-00AA004A55E8}
- 6360:00e4 10:27:59.066 OriginalDLL: value missing, err 2
- 6360:00e4 10:27:59.066 RegSvr32Dll
- 6360:00e4 10:27:59.070 RegSvr32Dll CreateProcess ret=1 code=0
- 6360:00e4 10:27:59.070 RegSvr32Dll WaitProcess h=0x0000017C pid=6244
- 6360:00e4 10:27:59.085 RegSvr32Dll WaitProcess ret=0
- 6360:00e4 10:27:59.085 RegSvr32Dll
- 6360:00e4 10:27:59.091 RegSvr32Dll CreateProcess ret=1 code=0
- 6360:00e4 10:27:59.091 RegSvr32Dll WaitProcess h=0x00000178 pid=5256
- 6360:00e4 10:27:59.108 RegSvr32Dll WaitProcess ret=0
- 6360:00e4 10:27:59.108 64-bit utility finished, return code = 2
- 2904:1884 10:27:59.110 ------Utility Stdout ^ ---
- 2904:1884 10:27:59.110 Utility Stderr is empty
- 2904:1884 10:27:59.110 creating kleaner host object...
- 2904:1884 10:27:59.111 creating ActiveScriptSite...
- 2904:1884 10:27:59.114 parsing script...
- 2904:1884 10:27:59.115 execute script...
- 2904:1884 10:27:59.268 ->Script Begin
- 2904:1884 10:27:59.268 (+) SEARCHING NECESSARY DIRECTORIES
- 2904:1884 10:27:59.268 ->Check if previous version of KES installed
- 2904:1884 10:27:59.626 Bases: C:\ProgramData\Kaspersky Lab\KES.21.8
- 2904:1884 10:27:59.626 BasesRoot: C:\ProgramData\Kaspersky Lab
- 2904:1884 10:27:59.626 Check ProductName
- 2904:1884 10:27:59.626 ProductName: Kaspersky Endpoint Security для Windows
- 2904:1884 10:27:59.626 Check InstallLocation
- 2904:1884 10:27:59.626 Try use InstDir='C:\Program Files (x86)\Kaspersky Lab\KES.11.11.0'
- 2904:1884 10:27:59.626 InstallLocation: C:\Program Files (x86)\Kaspersky Lab\KES.11.11.0
- 2904:1884 10:27:59.627 RootFolder: C:\Program Files (x86)\Kaspersky Lab
- 2904:1884 10:27:59.627 MainExePath: C:\Program Files (x86)\Kaspersky Lab\KES.11.11.0\avp.exe
- 2904:1884 10:27:59.633 CommonProgs: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
- 2904:1884 10:27:59.641 ProgramsFolder:
- 2904:1884 10:27:59.641 (+) SEARCH KLIM
- 2904:1884 10:27:59.657 +++++ KAVREMOVER IN PROCESS +++++
- 2904:1884 10:27:59.657 ->> Unregister dlls before msiexec
- 2904:1884 10:27:59.657 Processing section execute_before_msi...
- 2904:1884 10:27:59.657 (+) TRY TO RUN MSIEXEC
- 2904:1884 10:27:59.657 (+) TRY TO RUN MSIEXEC
- 2904:1884 10:27:59.657 InstallUid:
- 2904:1884 10:27:59.658 InstallUid: {BF39B547-8E24-4E11-8179-183B2F7C83EB}
- 2904:1884 10:29:15.127 ->WrongPasswdDetected: Рстина
- 2904:1884 10:29:15.127 Removing canceled. Reason: 1002 ("wrong or empty MSI password").
- 2904:1884 10:29:15.127 CKLeanerHost::CancelProcessing
- 2904:1884 10:29:15.140 Ошибка выполнения Microsoft VBScript
- 2904:1884 10:29:15.140 Деление на 0
- 2904:1884 10:29:15.140 error: script error at line 215
- 2904:1884 10:29:15.140 script execution finished
- 2904:1884 10:29:15.140 end script::process
- 2904:1884 10:29:15.140 Removing cancelled
- 2904:1884 10:29:15.140 KLeaner deinitialized
- 2904:1884 10:29:15.140 Stopping shutdown detector...
- 2904:1884 10:29:15.140 Waiting for watch thread stop...
- 2904:0c90 10:29:15.140 Watch thread finished
- 2904:1884 10:29:15.141 Watch thread was stopped
- 2904:1884 10:29:15.141 RestoreSystemEnvironment
- 2904:1884 10:29:15.141 Set environment from string...
- 2904:1884 10:29:15.141 change_current_enviroment start
- 2904:1884 10:29:15.142 Server free
- 2904:1200 10:30:53.292 RestoreSystemEnvironment
- 2904:1200 10:30:53.292 It has no dumped system environment
- 2904:1b74 10:30:53.292 Removing ini files...
- 2904:16e0 10:30:53.577 Error = 0, return code = 1718
- 2904:16e0 10:30:53.577 Cannot register serviceCtrlHandler
- 2904:1b74 10:30:53.577 Stopping server...
Add Comment
Please, Sign In to add comment