Hello.
Yes, there are traces of previous infections in your log. To remove them, execute the script:
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\drivers\fips32cup.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\i386si.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\ksi32sk.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\netsik.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\nicsk32.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\port135sik.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\securentm.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\systemntmi.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\ws2_32sik.sys','');
QuarantineFile('C:\WINDOWS\system32\cpwmon2k.dll','');
QuarantineFile('C:\WINDOWS\system32\1025p.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\acpi32.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\amd64si.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\ati64si.sys','');
DeleteFile('C:\WINDOWS\system32\drivers\ati64si.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\ati64si.sys');
DeleteFile('C:\WINDOWS\system32\drivers\amd64si.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\amd64si.sys');
DeleteFile('C:\WINDOWS\system32\drivers\acpi32.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\acpi32.sys');
DeleteFile('C:\WINDOWS\system32\1025p.exe');
BC_DeleteFile('C:\WINDOWS\system32\1025p.exe');
DeleteFile('C:\WINDOWS\system32\drivers\ws2_32sik.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\ws2_32sik.sys');
DeleteFile('C:\WINDOWS\system32\drivers\systemntmi.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\systemntmi.sys');
DeleteFile('C:\WINDOWS\system32\drivers\securentm.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\securentm.sys');
DeleteFile('C:\WINDOWS\system32\drivers\port135sik.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\port135sik.sys');
DeleteFile('C:\WINDOWS\system32\drivers\nicsk32.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\nicsk32.sys');
DeleteFile('C:\WINDOWS\system32\drivers\netsik.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\netsik.sys');
DeleteFile('C:\WINDOWS\system32\drivers\ksi32sk.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\ksi32sk.sys');
DeleteFile('C:\WINDOWS\system32\drivers\i386si.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\i386si.sys');
DeleteFile('C:\WINDOWS\system32\drivers\fips32cup.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\fips32cup.sys');
DeleteService('ws2_32sik');
DeleteService('systemntmi');
DeleteService('securentm');
DeleteService('port135sik');
DeleteService('nicsk32');
DeleteService('netsik');
DeleteService('ksi32sk');
DeleteService('i386si');
DeleteService('fips32cup');
DeleteService('ati64si');
DeleteService('amd64si');
DeleteService('acpi32');
DeleteService('VSSRasAuto');
BC_Deletesvc('ws2_32sik');
BC_Deletesvc('systemntmi');
BC_Deletesvc('securentm');
BC_Deletesvc('port135sik');
BC_Deletesvc('nicsk32');
BC_Deletesvc('netsik');
BC_Deletesvc('ksi32sk');
BC_Deletesvc('i386si');
BC_Deletesvc('fips32cup');
BC_Deletesvc('ati64si');
BC_Deletesvc('amd64si');
BC_Deletesvc('acpi32');
BC_Deletesvc('VSSRasAuto');
BC_ImportquarantineList;
BC_Activate;
ExecuteSysClean;
executerepair(9);
RebootWindows(true);
end.
After restart, please, inform us if KAV starts correctly, and make new logs (you'd better make all the 3 logs as it's described in the rules of "Help me!" section).