ده تقرير برنامج malware
لبارتيشين ال c بس
Malwarebytes' Anti-Malware
Database version:
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
04/07/2012 10:57:54 م
mbam-log-2012-07-04 (22-57-54).txt
Scan type: Full scan (C:\|)
Objects scanned: 246483
Time elapsed: 26 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AMSINT32 (Virus.Sality) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint32 (Virus.Sality) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (PUM.Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\sexfb.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\Oracle\middleware\jdk160_24\bin\java.exe (Worm.Rebhip) -> Quarantined and deleted successfully.
c:\Oracle\middleware\jdk160_24\jre\bin\java.exe (Worm.Rebhip) -> Quarantined and deleted successfully.
c:\program files\Adobe\adobe dreamweaver cs5\keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{e3450bf5-1887-421b-83a2-f9c091159c17}\RP30\A0017274.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.