طلال الساهر

زيزوومي جديد
إنضم
17 أبريل 2009
المشاركات
71
مستوى التفاعل
0
النقاط
80
الإقامة
المدينة
غير متصل
امس فرمت الجهاز عشان الفايروسات :mad: ونزلت التقرير وياليت مايكون فيه فايروسات


ComboFix 09-04-17.05 - xp 04/19/2009 19:28.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.446.219 [GMT 3:00]
Running from: c:\documents and settings\xp\سطح المكتب\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.
2009-04-19 15:56 . 2005-02-25 03:34 22752 ----a-w c:\windows\system32\spupdsvc.exe
2009-04-19 15:56 . 2009-04-19 16:06 -------- d--h--w c:\windows\$hf_mig$
2009-04-19 15:51 . 2008-10-16 11:08 23576 ----a-w c:\windows\system32\wuapi.dll.mui
2009-04-19 15:13 . 2009-04-19 15:13 -------- d-----w c:\documents and settings\xp\Application Data\Media Player Classic
2009-04-19 14:26 . 2001-08-17 19:36 8704 -c--a-w c:\windows\system32\dllcache\kbdjpn.dll
2009-04-19 14:26 . 2001-08-17 19:36 8704 ----a-w c:\windows\system32\kbdjpn.dll
2009-04-19 14:26 . 2001-08-17 19:36 8192 -c--a-w c:\windows\system32\dllcache\kbdkor.dll
2009-04-19 14:26 . 2001-08-17 19:36 8192 ----a-w c:\windows\system32\kbdkor.dll
2009-04-19 14:26 . 2001-08-17 11:55 6144 -c--a-w c:\windows\system32\dllcache\kbd106.dll
2009-04-19 14:26 . 2001-08-17 11:55 6144 -c--a-w c:\windows\system32\dllcache\kbd101c.dll
2009-04-19 14:26 . 2001-08-17 11:55 6144 -c--a-w c:\windows\system32\dllcache\kbd101b.dll
2009-04-19 14:26 . 2001-08-17 11:55 6144 ----a-w c:\windows\system32\kbd106.dll
2009-04-19 14:26 . 2001-08-17 11:55 6144 ----a-w c:\windows\system32\kbd101c.dll
2009-04-19 14:26 . 2001-08-17 11:55 6144 ----a-w c:\windows\system32\kbd101b.dll
2009-04-19 14:26 . 2001-08-17 11:55 5632 -c--a-w c:\windows\system32\dllcache\kbd103.dll
2009-04-19 14:26 . 2001-08-17 11:55 5632 ----a-w c:\windows\system32\kbd103.dll
2009-04-19 13:30 . 2009-04-19 13:30 -------- d-----w c:\documents and settings\xp\Local Settings\Application Data\Google
2009-04-19 10:26 . 2009-04-19 10:26 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-19 10:13 . 2009-04-19 10:13 -------- d-s---w c:\documents and settings\xp\UserData
2009-04-19 03:23 . 2009-04-19 03:23 -------- d-----w c:\windows\Sun
2009-04-18 22:45 . 2009-04-19 09:49 -------- d-----w c:\documents and settings\xp\Application Data\WIPE
2009-04-18 22:45 . 2007-06-22 00:08 139776 ----a-w c:\windows\system32\dhSQLite.dll
2009-04-18 22:45 . 2007-06-18 15:57 219136 ----a-w c:\windows\sqlite3_engine.dll
2009-04-18 22:45 . 2004-03-08 21:00 609824 ----a-w c:\windows\system32\Comctl32.ocx
2009-04-18 22:22 . 2009-04-18 22:22 -------- d-----w c:\windows\system32\AppData
2009-04-18 22:21 . 2006-03-14 11:00 544833 ----a-w c:\windows\system32\wbocx.ocx
2009-04-18 22:21 . 2004-12-07 07:11 258352 ----a-w c:\windows\system32\unicows.dll
2009-04-18 22:21 . 2002-03-01 14:58 50688 ----a-w c:\windows\system32\wbhelp2.dll
2009-04-18 22:21 . 2002-03-01 14:58 28160 ----a-w c:\windows\system32\anim.dll
2009-04-18 21:14 . 2009-04-18 21:15 -------- d-----w c:\documents and settings\xp\Contacts
2009-04-18 21:12 . 2009-04-18 21:12 -------- dc----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-18 21:04 . 2004-08-03 21:55 21504 -c--a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-18 21:04 . 2004-08-03 21:55 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-18 21:04 . 2004-08-03 21:45 14720 -c--a-w c:\windows\system32\dllcache\kbdhid.sys
2009-04-18 21:04 . 2004-08-03 21:45 14720 ----a-w c:\windows\system32\drivers\kbdhid.sys
2009-04-18 21:03 . 2004-08-03 20:08 31616 -c--a-w c:\windows\system32\dllcache\usbccgp.sys
2009-04-18 21:03 . 2004-08-03 20:08 31616 ----a-w c:\windows\system32\drivers\usbccgp.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-19 16:15 . 2001-09-19 11:00 40118 ----a-w c:\windows\system32\perfc001.dat
2009-04-19 16:15 . 2001-09-19 11:00 251674 ----a-w c:\windows\system32\perfh001.dat
2009-04-19 15:45 . 2009-04-18 17:17 -------- d-----w c:\program files\mpegable
2009-04-19 12:00 . 2009-04-19 12:00 -------- d-----w c:\program files\Common Files\xing shared
2009-04-19 12:00 . 2009-04-18 17:20 -------- d-----w c:\program files\Common Files\Real
2009-04-19 11:59 . 2009-04-18 17:18 -------- d-----w c:\program files\Google
2009-04-19 11:45 . 2009-04-18 16:40 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-18 22:45 . 2009-04-18 22:45 -------- d-----w c:\program files\Wipe
2009-04-18 22:05 . 2009-04-18 17:00 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-18 22:01 . 2009-04-18 17:03 -------- d-----w c:\program files\Common Files\ACD Systems
2009-04-18 17:24 . 2009-04-18 17:17 -------- d-----w c:\documents and settings\xp\Application Data\uTorrent
2009-04-18 17:20 . 2009-04-18 17:20 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-18 17:20 . 2009-04-18 17:19 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-18 17:20 . 2009-04-18 17:20 -------- d-----w c:\program files\Real
2009-04-18 17:19 . 2009-04-18 17:19 -------- d-----w c:\program files\Crystal Player
2009-04-18 17:19 . 2009-04-18 17:19 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-18 17:18 . 2009-04-18 17:18 -------- d-----w c:\program files\VideoLAN
2009-04-18 17:17 . 2009-04-18 17:17 47104 ------w c:\windows\AKDeInstall.exe
2009-04-18 17:17 . 2009-04-18 17:17 -------- d-----w c:\program files\uTorrent
2009-04-18 17:16 . 2009-04-18 17:16 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-18 17:15 . 2009-04-18 16:48 73208 ----a-w c:\documents and settings\xp\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-18 17:14 . 2009-04-18 17:14 -------- d-----w c:\program files\Windows Live
2009-04-18 17:14 . 2009-04-18 17:09 -------- d-----w c:\program files\Ares
2009-04-18 17:10 . 2009-04-18 17:09 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-04-18 17:09 . 2009-04-18 17:09 -------- d-----w c:\program files\Java
2009-04-18 17:09 . 2009-04-18 17:09 -------- d-----w c:\program files\Common Files\Java
2009-04-18 17:09 . 2009-04-18 17:09 172032 ------w c:\windows\Setup1.exe
2009-04-18 17:09 . 2009-04-18 17:09 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-18 17:09 . 2009-04-18 17:09 -------- dc----w c:\documents and settings\All Users\Application Data\Avira
2009-04-18 17:09 . 2009-04-18 17:09 -------- d-----w c:\program files\Avira
2009-04-18 17:07 . 2009-04-18 17:05 -------- d-----w c:\program files\Common Files\Adobe
2009-04-18 16:59 . 2009-04-18 16:59 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-18 16:51 . 2009-04-18 16:51 -------- d-----w c:\program files\Microsoft.NET
2009-04-18 16:41 . 2009-04-18 16:41 -------- d-----w c:\program files\microsoft frontpage
2009-04-18 16:37 . 2009-04-18 16:37 22144 ----a-w c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-19 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 262401]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-19 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\xp\çں‍ê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Wipe tray agent.lnk - c:\program files\Wipe\wipetray.exe [2009-4-19 191888]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VModes]
VModes AttachToDesktop [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
2008-11-26 07:23 881664 ----a-w c:\program files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-03 20:56 15360 ----a-w c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-18 17:09 155648 ----a-w c:\program files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-04-19 12:00 198160 ----a-w c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2005-03-07 03:33 53248 ----a-r c:\windows\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
2005-10-31 04:15 163840 ----a-r c:\windows\system32\VTTrayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\FTP\\LeapFTP1.exe"=
"f:\\All in one Cleaner\\SysCleaners4in1.exe"=
"f:\\All in one Cleaner\\ToolRegistryCleaner.exe"=
"c:\\Program Files\\Adobe\\Photoshop CS\\Photoshop.exe"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=
"c:\\Documents and Settings\\xp\\سطح المكتب\\ComboFix.exe"=
"c:\\Program Files\\Wipe\\wipetray.exe"=
S3 abp470n5;abp470n5; [x]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-04-19 19:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-19 19:30
ComboFix-quarantined-files.txt 2009-04-19 16:30
ComboFix2.txt 2009-04-19 16:17
Pre-Run: 15,000,166,400 bytes free
Post-Run: 15,060,123,648 bytes free
177 --- E O F --- 2009-04-19 16:06
 



اهلااا بك اخي
وعذرا بنقله للقسم المناسب للمتابعة
هذا القسم خاص بتحليل تقارير برامج الحماية ،، وباقي التقارير تكون عند الطلب فقط

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

 
توقيع : Demo-dashDemo-dash is verified member.
يبدولي سليم اخوي .. هل عندك اي مشاكل ؟
 
طيب ليش ماقدر افتح البرامج وبرنامج الافيرا مايشتغل:no:
 
حمل هذا البرنامج
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك القادم
 
التعديل الأخير بواسطة المشرف:
تفضل اخوي

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:44:25 م, on 19/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Wipe\wipetray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\DOCUME~1\xp\LOCALS~1\Temp\winpjrr.exe
C:\DOCUME~1\xp\LOCALS~1\Temp\winmdbym.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\xp\سطح المكتب\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Wipe tray agent.lnk = C:\Program Files\Wipe\wipetray.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 4645 bytes
 
حمل الاداة التالية

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


شغلها فتظهر لك واجهة الاداة
احتر خيار التنظيف فتظهر شاشة الدوس للفحص
اتركها حتى تنتهي ويظهر التقرير
انسخه والصقه بمشاركتك القادمة
 
كيف تعلق يابعدي شغل الاداة بدون ماتغير اسمها واحفضها على سطح المكتب
 
توقيع : KoNaMi
وييين النااااااااااااااااااااااس
 
حمل هذه الاداة

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي




بعد التحميل ،، دبل كلك وسيتم استخراج ملف الاداة الى مجلد بسطح المكتب لحظات وتبدأ الاداة بالعمل​


تابع الشرح لفحص الجهاز وتنظيفه وارفاق التقرير​



zyzoom-7ce8879e89.png


zyzoom-cdd75c8aa3.png


zyzoom-89156f000e.png


zyzoom-6d533c4f2e.png


zyzoom-f20f3644d0.png


ثم قم بضغط التقرير ورفعه هنا>>>>
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

 
تفضل


Scan
----
Scanned: 357223
Detected: 0
Untreated: 0
Start time: 25/04/1430 06:24:30 م
Duration: 01:42:18
Finish time: 25/04/1430 08:06:48 م

Detected
--------
Status Object
------ ------

Events
------
Time Name Status Reason
---- ---- ------ ------
25/04/1430 06:23:33 م Running module: smss.exe\smss.exe ok scanned
25/04/1430 06:23:37 م File: C:\WINDOWS\System32\smss.exe ok scanned
25/04/1430 06:23:38 م Running module: smss.exe\ntdll.dll ok scanned
25/04/1430 06:23:45 م File: C:\WINDOWS\system32\ntdll.dll ok scanned
25/04/1430 06:23:45 م Running module: csrss.exe\csrss.exe ok scanned
25/04/1430 06:23:45 م File: C:\WINDOWS\system32\csrss.exe ok scanned
25/04/1430 06:23:45 م Running module: csrss.exe\ntdll.dll ok scanned
25/04/1430 06:23:45 م File: C:\WINDOWS\system32\ntdll.dll ok scanned
25/04/1430 06:23:45 م Running module: csrss.exe\CSRSRV.dll ok scanned
25/04/1430 06:23:45 م File: C:\WINDOWS\system32\CSRSRV.dll ok scanned
25/04/1430 06:23:45 م Running module: csrss.exe\basesrv.dll ok scanned
25/04/1430 06:23:45 م File: C:\WINDOWS\system32\basesrv.dll ok scanned
25/04/1430 06:23:45 م Running module: csrss.exe\winsrv.dll ok scanned
25/04/1430 06:23:46 م File: C:\WINDOWS\system32\winsrv.dll ok scanned
25/04/1430 06:23:46 م Running module: csrss.exe\USER32.dll ok scanned
25/04/1430 06:23:48 م File: C:\WINDOWS\system32\USER32.dll ok scanned
25/04/1430 06:23:48 م Running module: csrss.exe\KERNEL32.dll ok scanned
25/04/1430 06:23:50 م File: C:\WINDOWS\system32\KERNEL32.dll ok scanned
25/04/1430 06:23:50 م Running module: csrss.exe\GDI32.dll ok scanned
25/04/1430 06:23:52 م File: C:\WINDOWS\system32\GDI32.dll ok scanned
25/04/1430 06:23:52 م Running module: csrss.exe\LPK.DLL ok scanned
25/04/1430 06:23:52 م File: C:\WINDOWS\system32\LPK.DLL ok scanned
25/04/1430 06:23:52 م Running module: csrss.exe\USP10.dll ok scanned
25/04/1430 06:23:52 م File: C:\WINDOWS\system32\USP10.dll ok scanned
25/04/1430 06:23:52 م Running module: csrss.exe\msvcrt.dll ok scanned
25/04/1430 06:23:53 م File: C:\WINDOWS\system32\msvcrt.dll ok scanned
25/04/1430 06:23:53 م Running module: csrss.exe\ADVAPI32.dll ok scanned
25/04/1430 06:23:53 م File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
25/04/1430 06:23:53 م Running module: csrss.exe\RPCRT4.dll ok scanned
25/04/1430 06:23:53 م File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
25/04/1430 06:23:53 م Running module: csrss.exe\sxs.dll ok scanned
25/04/1430 06:23:53 م File: C:\WINDOWS\system32\sxs.dll ok scanned
25/04/1430 06:23:53 م Running module: winlogon.exe\winlogon.exe ok scanned
25/04/1430 06:23:54 م File: C:\WINDOWS\system32\winlogon.exe ok scanned
25/04/1430 06:23:54 م Running module: winlogon.exe\ntdll.dll ok scanned
25/04/1430 06:23:54 م File: C:\WINDOWS\system32\ntdll.dll ok scanned
25/04/1430 06:23:54 م Running module: winlogon.exe\kernel32.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\kernel32.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\ADVAPI32.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\RPCRT4.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\AUTHZ.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\AUTHZ.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\msvcrt.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\msvcrt.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\CRYPT32.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\CRYPT32.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\USER32.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\USER32.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\GDI32.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\GDI32.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\MSASN1.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\MSASN1.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\NDdeApi.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\NDdeApi.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\PROFMAP.dll ok scanned
25/04/1430 06:23:55 م File: C:\WINDOWS\system32\PROFMAP.dll ok scanned
25/04/1430 06:23:55 م Running module: winlogon.exe\NETAPI32.dll ok scanned
25/04/1430 06:23:56 م File: C:\WINDOWS\system32\NETAPI32.dll ok scanned
25/04/1430 06:23:56 م Running module: winlogon.exe\USERENV.dll ok scanned
25/04/1430 06:23:56 م File: C:\WINDOWS\system32\USERENV.dll ok scanned
25/04/1430 06:23:56 م Running module: winlogon.exe\PSAPI.DLL ok scanned
25/04/1430 06:23:56 م File: C:\WINDOWS\system32\PSAPI.DLL ok scanned
25/04/1430 06:23:56 م Running module: winlogon.exe\REGAPI.dll ok scanned
25/04/1430 06:23:56 م File: C:\WINDOWS\system32\REGAPI.dll ok scanned
25/04/1430 06:23:56 م Running module: winlogon.exe\Secur32.dll ok scanned
25/04/1430 06:23:57 م File: C:\WINDOWS\system32\Secur32.dll ok scanned
25/04/1430 06:23:57 م Running module: winlogon.exe\SETUPAPI.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\VERSION.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\VERSION.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\WINSTA.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\WINSTA.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\WINTRUST.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\WINTRUST.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\IMAGEHLP.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\IMAGEHLP.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\WS2_32.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\WS2_32.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\WS2HELP.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\WS2HELP.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\LPK.DLL ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\LPK.DLL ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\USP10.dll ok scanned
25/04/1430 06:23:58 م File: C:\WINDOWS\system32\USP10.dll ok scanned
25/04/1430 06:23:58 م Running module: winlogon.exe\MSGINA.dll ok scanned
25/04/1430 06:23:59 م File: C:\WINDOWS\system32\MSGINA.dll ok scanned
25/04/1430 06:23:59 م Running module: winlogon.exe\SHELL32.dll ok scanned
25/04/1430 06:24:04 م File: C:\WINDOWS\system32\SHELL32.dll ok scanned
25/04/1430 06:24:04 م Running module: winlogon.exe\SHLWAPI.dll ok scanned
25/04/1430 06:24:04 م File: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
25/04/1430 06:24:04 م Running module: winlogon.exe\COMCTL32.dll ok scanned
25/04/1430 06:24:05 م File: C:\WINDOWS\system32\COMCTL32.dll ok scanned
25/04/1430 06:24:05 م Running module: winlogon.exe\ODBC32.dll ok scanned
25/04/1430 06:24:05 م File: C:\WINDOWS\system32\ODBC32.dll ok scanned
25/04/1430 06:24:05 م Running module: winlogon.exe\comdlg32.dll ok scanned
25/04/1430 06:24:06 م File: C:\WINDOWS\system32\comdlg32.dll ok scanned
25/04/1430 06:24:06 م Running module: winlogon.exe\comctl32.dll ok scanned
25/04/1430 06:24:09 م File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll ok scanned
25/04/1430 06:24:09 م Running module: winlogon.exe\odbcint.dll ok scanned
25/04/1430 06:24:09 م File: C:\WINDOWS\system32\odbcint.dll ok scanned
25/04/1430 06:24:09 م Running module: winlogon.exe\SHSVCS.dll ok scanned
25/04/1430 06:24:10 م File: C:\WINDOWS\system32\SHSVCS.dll ok scanned
25/04/1430 06:24:10 م Running module: winlogon.exe\sfc.dll ok scanned
25/04/1430 06:24:10 م File: C:\WINDOWS\system32\sfc.dll ok scanned
25/04/1430 06:24:10 م Running module: winlogon.exe\sfc_os.dll ok scanned
25/04/1430 06:24:11 م File: C:\WINDOWS\system32\sfc_os.dll ok scanned
25/04/1430 06:24:11 م Running module: winlogon.exe\ole32.dll ok scanned
25/04/1430 06:24:11 م File: C:\WINDOWS\system32\ole32.dll ok scanned
25/04/1430 06:24:11 م Running module: winlogon.exe\Apphelp.dll ok scanned
25/04/1430 06:24:12 م File: C:\WINDOWS\system32\Apphelp.dll ok scanned
25/04/1430 06:24:12 م Running module: winlogon.exe\WINSCARD.DLL ok scanned
25/04/1430 06:24:12 م File: C:\WINDOWS\system32\WINSCARD.DLL ok scanned
25/04/1430 06:24:12 م Running module: winlogon.exe\WTSAPI32.dll ok scanned
25/04/1430 06:24:12 م File: C:\WINDOWS\system32\WTSAPI32.dll ok scanned
25/04/1430 06:24:12 م Running module: winlogon.exe\sxs.dll ok scanned
25/04/1430 06:24:12 م File: C:\WINDOWS\system32\sxs.dll ok scanned
25/04/1430 06:24:12 م Running module: winlogon.exe\uxtheme.dll ok scanned
25/04/1430 06:24:12 م File: C:\WINDOWS\system32\uxtheme.dll ok scanned
25/04/1430 06:24:12 م Running module: winlogon.exe\WINMM.dll ok scanned
25/04/1430 06:24:13 م File: C:\WINDOWS\system32\WINMM.dll ok scanned
25/04/1430 06:24:13 م Running module: winlogon.exe\cscdll.dll ok scanned
25/04/1430 06:24:13 م File: C:\WINDOWS\system32\cscdll.dll ok scanned
25/04/1430 06:24:13 م Running module: winlogon.exe\WlNotify.dll ok scanned
25/04/1430 06:24:13 م File: C:\WINDOWS\system32\WlNotify.dll ok scanned
25/04/1430 06:24:13 م Running module: winlogon.exe\WINSPOOL.DRV ok scanned
25/04/1430 06:24:14 م File: C:\WINDOWS\system32\WINSPOOL.DRV ok scanned
25/04/1430 06:24:14 م Running module: winlogon.exe\MPR.dll ok scanned
25/04/1430 06:24:14 م File: C:\WINDOWS\system32\MPR.dll skipped processing stopped
25/04/1430 06:24:51 م Running module: smss.exe\smss.exe ok scanned

Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------

Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes

Quarantine
----------
Status Object Size Added
------ ------ ---- -----

Backup
------
Status Object Size
------ ------ ----
 
حمل الاداة التالية

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


شغلها فتظهر لك واجهة الاداة
احتر خيار التنظيف فتظهر شاشة الدوس للفحص
اتركها حتى تنتهي ويظهر التقرير
انسخه والصقه بمشاركتك القادمة
اعد تحميل هذه الاداة وافحص بها
 
d'gu gd
عفواا الرابط غير صحيح لحظات وننتقل للموقع الجديد
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يطلع لي كذا
 
وين الحل حتى البرامج ماقدر افتح ايش المشكله
 
اعد تحميلها من جديد
وحاول انك تحملها بشكل متواصل دون تقطيع
 
تفضل

Engine Version : 5300.2777
Engine Load Time : 29344 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections

Process : C:\WINDOWS\System32\svchost.exe : contains "Trojan" called "W32/Conficker!mem" (No Action Taken (Clean failed) )
Process : C:\WINDOWS\system32\svchost.exe : contains "Trojan" called "W32/Conficker!mem" (No Action Taken (Clean failed) )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (No Action Taken (Clean failed) )
Memory : Repair Failed
Please wait ... building list of critical files to scan
Critical : Clean
Scanning the computer's cookie directories
Cookies : Clean
c:\pagefile.sys : Scan Failed
c:\Documents and Settings\LocalService\NTUSER.DAT : Scan Failed
c:\Documents and Settings\LocalService\ntuser.dat.LOG : Scan Failed
c:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat : Scan Failed
c:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG : Scan Failed
c:\Documents and Settings\NetworkService\NTUSER.DAT : Scan Failed
c:\Documents and Settings\NetworkService\ntuser.dat.LOG : Scan Failed
c:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat : Scan Failed
c:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG : Scan Failed
c:\Documents and Settings\xp\NTUSER.DAT : Scan Failed
c:\Documents and Settings\xp\ntuser.dat.LOG : Scan Failed
c:\Documents and Settings\xp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat : Scan Failed
c:\Documents and Settings\xp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG : Scan Failed
File : c:\Documents and Settings\xp\Local Settings\Temp\8921485700994 : contains "Trojan" called "Spam-Mailbot" (Deleted )
c:\Documents and Settings\xp\Local Settings\Temp\8921485700994 : Deleted
c:\Documents and Settings\xp\Local Settings\Temp\Perflib_Perfdata_9e8.dat : Scan Failed
File : c:\WINDOWS\system32\jvgqee.dll : contains "Virus" called "W32/Conficker.worm.gen.b" (Deleted )
c:\WINDOWS\system32\jvgqee.dll : Deleted
c:\WINDOWS\system32\config\default : Scan Failed
c:\WINDOWS\system32\config\default.LOG : Scan Failed
c:\WINDOWS\system32\config\SAM : Scan Failed
c:\WINDOWS\system32\config\SAM.LOG : Scan Failed
c:\WINDOWS\system32\config\SECURITY : Scan Failed
c:\WINDOWS\system32\config\SECURITY.LOG : Scan Failed
c:\WINDOWS\system32\config\software : Scan Failed
c:\WINDOWS\system32\config\software.LOG : Scan Failed
c:\WINDOWS\system32\config\system : Scan Failed
c:\WINDOWS\system32\config\system.LOG : Scan Failed
c:\WINDOWS\system32\drivers\fidbox.dat : Scan Failed
c:\WINDOWS\system32\drivers\fidbox.idx : Scan Failed
Scanning the registry
Registry : Clean

Summary :-
FilesFound : 28933
FilesScanned : 18330
FilesNotScanned : 10603

ObjectsFound : 58758
ObjectsInfected : 55
ObjectsCleaned : 50
ObjectsDeleted : 2

FilesInfected : 2
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 2

Started at : 01:52:13 م 26 ربيع الثاني, 1430
Ended at : 02:10:10 م 26 ربيع الثاني, 1430
Duration : 17 minutes 57 seconds
4104 MB scanned in 1077 seconds = 3 MB/s
Engine Version : 5300.2777
Engine Load Time : 21546 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections


Summary :-
FilesFound : 832
FilesScanned : 133
FilesNotScanned : 699

ObjectsFound : 837
ObjectsInfected : 0
ObjectsCleaned : 0
ObjectsDeleted : 0

FilesInfected : 0
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 0

Started at : 02:10:34 م 26 ربيع الثاني, 1430
Ended at : 02:10:51 م 26 ربيع الثاني, 1430
Duration : 16 seconds
119 MB scanned in 16 seconds = 7 MB/s
Engine Version : 5300.2777
Engine Load Time : 23188 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections


Summary :-
FilesFound : 89
FilesScanned : 2
FilesNotScanned : 87

ObjectsFound : 89
ObjectsInfected : 0
ObjectsCleaned : 0
ObjectsDeleted : 0

FilesInfected : 0
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 0

Started at : 02:11:15 م 26 ربيع الثاني, 1430
Ended at : 02:11:19 م 26 ربيع الثاني, 1430
Duration : 3 seconds
5 MB scanned in 3 seconds = 1820 KB/s
Engine Version : 5300.2777
Engine Load Time : 26797 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections


Summary :-
FilesFound : 466
FilesScanned : 139
FilesNotScanned : 327

ObjectsFound : 480
ObjectsInfected : 0
ObjectsCleaned : 0
ObjectsDeleted : 0

FilesInfected : 0
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 0

Started at : 02:11:47 م 26 ربيع الثاني, 1430
Ended at : 02:12:02 م 26 ربيع الثاني, 1430
Duration : 14 seconds
45 MB scanned in 14 seconds = 3 MB/s
Engine Version : 5300.2777
Engine Load Time : 21859 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections

Process : C:\WINDOWS\System32\svchost.exe : contains "Trojan" called "W32/Conficker!mem" (No Action Taken (Clean failed) )
Process : C:\WINDOWS\system32\svchost.exe : contains "Trojan" called "W32/Conficker!mem" (No Action Taken (Clean failed) )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (Cleaned )
Process : C:\WINDOWS\Explorer.EXE : contains "Trojan" called "W32/Sality!mem" (No Action Taken (Clean failed) )
Memory : Repair Failed
Please wait ... building list of critical files to scan
Critical : Clean
Scanning the computer's cookie directories
Cookies : Clean
c:\pagefile.sys : Scan Failed
c:\Documents and Settings\LocalService\NTUSER.DAT : Scan Failed
c:\Documents and Settings\LocalService\ntuser.dat.LOG : Scan Failed
c:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat : Scan Failed
c:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG : Scan Failed
c:\Documents and Settings\NetworkService\NTUSER.DAT : Scan Failed
c:\Documents and Settings\NetworkService\ntuser.dat.LOG : Scan Failed
c:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat : Scan Failed
c:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG : Scan Failed
c:\Documents and Settings\xp\NTUSER.DAT : Scan Failed
c:\Documents and Settings\xp\ntuser.dat.LOG : Scan Failed
c:\Documents and Settings\xp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat : Scan Failed
c:\Documents and Settings\xp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG : Scan Failed
File : c:\Documents and Settings\xp\Local Settings\Temp\nsng.exe : contains "Trojan" called "Spam-Mailbot" (Deleted )
c:\Documents and Settings\xp\Local Settings\Temp\nsng.exe : Deleted
c:\Documents and Settings\xp\Local Settings\Temp\Perflib_Perfdata_198.dat : Scan Failed
c:\Documents and Settings\xp\Local Settings\Temp\Photoshop Temp111821 : Scan Failed
File : c:\System Volume Information\_restore{66E550E0-C946-43E6-9D64-C9324E29D389}\RP1\A0000035.dll : contains "Virus" called "W32/Conficker.worm.gen.b" (Deleted )
c:\System Volume Information\_restore{66E550E0-C946-43E6-9D64-C9324E29D389}\RP1\A0000035.dll : Deleted
c:\WINDOWS\system32\config\default : Scan Failed
c:\WINDOWS\system32\config\default.LOG : Scan Failed
c:\WINDOWS\system32\config\SAM : Scan Failed
c:\WINDOWS\system32\config\SAM.LOG : Scan Failed
c:\WINDOWS\system32\config\SECURITY : Scan Failed
c:\WINDOWS\system32\config\SECURITY.LOG : Scan Failed
c:\WINDOWS\system32\config\software : Scan Failed
c:\WINDOWS\system32\config\software.LOG : Scan Failed
c:\WINDOWS\system32\config\system : Scan Failed
c:\WINDOWS\system32\config\system.LOG : Scan Failed
c:\WINDOWS\system32\drivers\fidbox.dat : Scan Failed
c:\WINDOWS\system32\drivers\fidbox.idx : Scan Failed
Scanning the registry
Registry : Clean

Summary :-
FilesFound : 29635
FilesScanned : 18603
FilesNotScanned : 11032

ObjectsFound : 59657
ObjectsInfected : 55
ObjectsCleaned : 50
ObjectsDeleted : 2

FilesInfected : 2
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 2

Started at : 02:12:46 م 26 ربيع الثاني, 1430
Ended at : 02:32:11 م 26 ربيع الثاني, 1430
Duration : 19 minutes 25 seconds
4112 MB scanned in 1165 seconds = 3 MB/s
Engine Version : 5300.2777
Engine Load Time : 29640 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections


Summary :-
FilesFound : 832
FilesScanned : 133
FilesNotScanned : 699

ObjectsFound : 837
ObjectsInfected : 0
ObjectsCleaned : 0
ObjectsDeleted : 0

FilesInfected : 0
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 0

Started at : 02:32:47 م 26 ربيع الثاني, 1430
Ended at : 02:33:12 م 26 ربيع الثاني, 1430
Duration : 24 seconds
119 MB scanned in 24 seconds = 4 MB/s
Engine Version : 5300.2777
Engine Load Time : 21125 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections


Summary :-
FilesFound : 89
FilesScanned : 2
FilesNotScanned : 87

ObjectsFound : 89
ObjectsInfected : 0
ObjectsCleaned : 0
ObjectsDeleted : 0

FilesInfected : 0
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 0

Started at : 02:33:34 م 26 ربيع الثاني, 1430
Ended at : 02:33:38 م 26 ربيع الثاني, 1430
Duration : 3 seconds
5 MB scanned in 3 seconds = 1824 KB/s
Engine Version : 5300.2777
Engine Load Time : 20250 milliseconds
AV DAT Version : 5492.0000 488805 detections Built 15 محرم, 1430
Extra DAT : 0 detections


Summary :-
FilesFound : 466
FilesScanned : 139
FilesNotScanned : 327

ObjectsFound : 480
ObjectsInfected : 0
ObjectsCleaned : 0
ObjectsDeleted : 0

FilesInfected : 0
FilesCleaned : 0
FilesMoved : 0
FilesDeleted : 0

Started at : 02:33:59 م 26 ربيع الثاني, 1430
Ended at : 02:34:06 م 26 ربيع الثاني, 1430
Duration : 7 seconds
45 MB scanned in 7 seconds = 6 MB/s
 
عودة
أعلى