عرض مشاركة واحدة
قديم 13-04-2009, 17:57   #18
معلومات العضو
عبدالسميع سرحان
نجم الأمل
الصورة الرمزية عبدالسميع سرحان







عبدالسميع سرحان غير متصل

آخر مواضيعي

افتراضي

أخي الحبيب هادي لم أرى ولم أتوقع مثلك في حب خدمة الأخرين
جزاك الله خيرا وبارك الله فيك

1- قمت بحذف الـ avira نهائيا
2- قمت بتثبيت الأفيرا الحر وأعطاني إلى 20/7/1431 هـ وعملت مسح على الوضع الأمن وهذه نتائجه كل شيء على حساب المدير فلا يوجد حساب خاص الآن
كود:
Avira AntiVir Personal
Report file date: 18 ربيع****الثاني, 1430  18:29

Scanning for 1347764 virus strains and unwanted programs.

Licensee        : Avira AntiVir Personal - FREE Antivirus
Serial number   : 0000149996-ADJIE-0000001
Platform        : Windows XP
Windows version : (Service Pack 3)  [5.1.2600]
Boot mode       : Save mode
Username        : Administrator
Computer name   : WINXP-07E684CEF

Version information:
BUILD.DAT       : 9.0.0.387     17962 Bytes  28/03/1430 11:04:00
AVSCAN.EXE      : 9.0.3.3      464641 Bytes  29/02/1430 09:13:26
AVSCAN.DLL      : 9.0.3.0       40705 Bytes  03/03/1430 07:58:24
LUKE.DLL        : 9.0.3.2      209665 Bytes  25/02/1430 08:35:49
LUKERES.DLL     : 9.0.2.0       12033 Bytes  03/03/1430 07:58:52
ANTIVIR0.VDF    : 7.1.0.0    15603712 Bytes  27/10/1429 09:30:36
ANTIVIR1.VDF    : 7.1.2.12    3336192 Bytes  16/02/1430 17:33:26
ANTIVIR2.VDF    : 7.1.3.0     1330176 Bytes  06/04/1430 15:22:55
ANTIVIR3.VDF    : 7.1.3.43     178688 Bytes  18/04/1430 15:22:58
Engineversion   : 8.2.0.138
AEVDF.DLL       : 8.1.1.0      106868 Bytes  01/02/1430 14:36:42
AESCRIPT.DLL    : 8.1.1.73     373114 Bytes  18/04/1430 15:23:19
AESCN.DLL       : 8.1.1.10     127348 Bytes  18/04/1430 15:23:18
AERDL.DLL       : 8.1.1.3      438645 Bytes  29/10/1429 15:24:41
AEPACK.DLL      : 8.1.3.12     397687 Bytes  18/04/1430 15:23:17
AEOFFICE.DLL    : 8.1.0.36     196987 Bytes  02/03/1430 17:01:56
AEHEUR.DLL      : 8.1.0.114   1700214 Bytes  18/04/1430 15:23:14
AEHELP.DLL      : 8.1.2.2      119158 Bytes  02/03/1430 17:01:56
AEGEN.DLL       : 8.1.1.33     340340 Bytes  18/04/1430 15:23:02
AEEMU.DLL       : 8.1.0.9      393588 Bytes  09/10/1429 11:32:40
AECORE.DLL      : 8.1.6.7      176502 Bytes  18/04/1430 15:22:59
AEBB.DLL        : 8.1.0.3       53618 Bytes  09/10/1429 11:32:40
AVWINLL.DLL     : 9.0.0.3       18177 Bytes  14/12/1429 05:47:59
AVPREF.DLL      : 9.0.0.1       43777 Bytes  07/12/1429 07:32:15
AVREP.DLL       : 8.0.0.3      155905 Bytes  24/01/1430 11:34:28
AVREG.DLL       : 9.0.0.0       36609 Bytes  07/12/1429 07:32:09
AVARKT.DLL      : 9.0.0.1      292609 Bytes  14/02/1430 04:52:24
AVEVTLOG.DLL    : 9.0.0.7      167169 Bytes  04/02/1430 07:37:08
SQLITE3.DLL     : 3.6.1.0      326401 Bytes  02/02/1430 12:03:49
SMTPLIB.DLL     : 9.2.0.25      28417 Bytes  07/02/1430 05:21:33
NETNT.DLL       : 9.0.0.0       11521 Bytes  07/12/1429 07:32:10
RCIMAGE.DLL     : 9.0.0.21    2438401 Bytes  14/02/1430 08:45:45
RCTEXT.DLL      : 9.0.35.0      87297 Bytes  15/03/1430 12:55:12

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, E:, 
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR,

Start of the scan: 18 ربيع****الثاني, 1430  18:29

Starting search for hidden objects.
The driver could not be initialized.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
11 processes with 11 modules were scanned

Starting master boot sector scan:

Start scanning boot sectors:

Starting to scan executable files (registry).
The registry was scanned ( '54' files ).


Starting the file scan:

Begin scan in 'C:\' <master>
C:\pagefile.sys
    [WARNING]   The file could not be opened!
    [NOTE]      This file is a Windows system file.
    [NOTE]      This file cannot be opened for scanning.
C:\Documents and Settings\Administrator\Desktop\New Folder\ComboFix.exe
  [0] Archive type: RAR SFX (self extracting)
    --> 32788R22FWJFW\psexec.cfexe
      [1] Archive type: RSRC
      --> Object
        [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
    [DETECTION] Contains recognition pattern of the APPL/BoontyGames application
C:\Program Files\SWiSHE.NET\SWiSH2 Book\source\sjc.txt
    [DETECTION] Contains recognition pattern of the JOKE/Rjump joke
Begin scan in 'D:\' <programs>
D:\شرح compo fix\ComboFix.exe
  [0] Archive type: RAR SFX (self extracting)
    --> 32788R22FWJFW\psexec.cfexe
      [1] Archive type: RSRC
      --> Object
        [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
Begin scan in 'E:\' <zhraa>

Beginning disinfection:
C:\Documents and Settings\Administrator\Desktop\New Folder\ComboFix.exe
    [NOTE]      The file was moved to '4a506634.qua'!
C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
    [DETECTION] Contains recognition pattern of the APPL/BoontyGames application
    [NOTE]      The file was moved to '4a526635.qua'!
C:\Program Files\SWiSHE.NET\SWiSH2 Book\source\sjc.txt
    [DETECTION] Contains recognition pattern of the JOKE/Rjump joke
    [NOTE]      The file was moved to '4a466630.qua'!
D:\شرح compo fix\ComboFix.exe
    [NOTE]      The file was moved to '4a506635.qua'!


End of the scan: 18 ربيع****الثاني, 1430  19:18
Used time: 47:03 Minute(s)

The scan has been done completely.

   7157 Scanned directories
 319204 Files were scanned
      4 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      4 Files were moved to quarantine
      0 Files were renamed
      1 Files cannot be scanned
 319199 Files not concerned
   3093 Archives were scanned
      1 Warnings
      5 Notes
وهذا على الوضع العادي... بدأ المسح ذاتيا عند العودة للوضع العادي
كود:
Avira AntiVir Personal
Report file date: 18 ربيع****الثاني, 1430  19:23

Scanning for 1347764 virus strains and unwanted programs.

Licensee        : Avira AntiVir Personal - FREE Antivirus
Serial number   : 0000149996-ADJIE-0000001
Platform        : Windows XP
Windows version : (Service Pack 3)  [5.1.2600]
Boot mode       : Normally booted
Username        : SYSTEM
Computer name   : WINXP-07E684CEF

Version information:
BUILD.DAT       : 9.0.0.387     17962 Bytes  28/03/1430 11:04:00
AVSCAN.EXE      : 9.0.3.3      464641 Bytes  29/02/1430 09:13:26
AVSCAN.DLL      : 9.0.3.0       40705 Bytes  03/03/1430 07:58:24
LUKE.DLL        : 9.0.3.2      209665 Bytes  25/02/1430 08:35:49
LUKERES.DLL     : 9.0.2.0       12033 Bytes  03/03/1430 07:58:52
ANTIVIR0.VDF    : 7.1.0.0    15603712 Bytes  27/10/1429 09:30:36
ANTIVIR1.VDF    : 7.1.2.12    3336192 Bytes  16/02/1430 17:33:26
ANTIVIR2.VDF    : 7.1.3.0     1330176 Bytes  06/04/1430 15:22:55
ANTIVIR3.VDF    : 7.1.3.43     178688 Bytes  18/04/1430 15:22:58
Engineversion   : 8.2.0.138
AEVDF.DLL       : 8.1.1.0      106868 Bytes  01/02/1430 14:36:42
AESCRIPT.DLL    : 8.1.1.73     373114 Bytes  18/04/1430 15:23:19
AESCN.DLL       : 8.1.1.10     127348 Bytes  18/04/1430 15:23:18
AERDL.DLL       : 8.1.1.3      438645 Bytes  29/10/1429 15:24:41
AEPACK.DLL      : 8.1.3.12     397687 Bytes  18/04/1430 15:23:17
AEOFFICE.DLL    : 8.1.0.36     196987 Bytes  02/03/1430 17:01:56
AEHEUR.DLL      : 8.1.0.114   1700214 Bytes  18/04/1430 15:23:14
AEHELP.DLL      : 8.1.2.2      119158 Bytes  02/03/1430 17:01:56
AEGEN.DLL       : 8.1.1.33     340340 Bytes  18/04/1430 15:23:02
AEEMU.DLL       : 8.1.0.9      393588 Bytes  09/10/1429 11:32:40
AECORE.DLL      : 8.1.6.7      176502 Bytes  18/04/1430 15:22:59
AEBB.DLL        : 8.1.0.3       53618 Bytes  09/10/1429 11:32:40
AVWINLL.DLL     : 9.0.0.3       18177 Bytes  14/12/1429 05:47:59
AVPREF.DLL      : 9.0.0.1       43777 Bytes  07/12/1429 07:32:15
AVREP.DLL       : 8.0.0.3      155905 Bytes  24/01/1430 11:34:28
AVREG.DLL       : 9.0.0.0       36609 Bytes  07/12/1429 07:32:09
AVARKT.DLL      : 9.0.0.1      292609 Bytes  14/02/1430 04:52:24
AVEVTLOG.DLL    : 9.0.0.7      167169 Bytes  04/02/1430 07:37:08
SQLITE3.DLL     : 3.6.1.0      326401 Bytes  02/02/1430 12:03:49
SMTPLIB.DLL     : 9.2.0.25      28417 Bytes  07/02/1430 05:21:33
NETNT.DLL       : 9.0.0.0       11521 Bytes  07/12/1429 07:32:10
RCIMAGE.DLL     : 9.0.0.21    2438401 Bytes  14/02/1430 08:45:45
RCTEXT.DLL      : 9.0.35.0      87297 Bytes  15/03/1430 12:55:12

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, E:, 
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR,

Start of the scan: 18 ربيع****الثاني, 1430  19:23

Starting search for hidden objects.
'47047' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'IEMonitor.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'YahooAUService.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'IDMan.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'UnlockerAssistant.exe' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
32 processes with 32 modules were scanned

Starting master boot sector scan:

Start scanning boot sectors:

Starting to scan executable files (registry).
The registry was scanned ( '56' files ).


Starting the file scan:

Begin scan in 'C:\' <master>
C:\pagefile.sys
    [WARNING]   The file could not be opened!
    [NOTE]      This file is a Windows system file.
    [NOTE]      This file cannot be opened for scanning.
C:\System Volume Information\_restore{2FCFF432-6BE0-475C-BE2F-5E9914F3CB75}\RP165\A0045583.exe
  [0] Archive type: RAR SFX (self extracting)
    --> 32788R22FWJFW\psexec.cfexe
      [1] Archive type: RSRC
      --> Object
        [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
C:\System Volume Information\_restore{2FCFF432-6BE0-475C-BE2F-5E9914F3CB75}\RP165\A0045584.exe
    [DETECTION] Contains recognition pattern of the APPL/BoontyGames application
Begin scan in 'D:\' <programs>
D:\System Volume Information\_restore{2FCFF432-6BE0-475C-BE2F-5E9914F3CB75}\RP165\A0045585.exe
  [0] Archive type: RAR SFX (self extracting)
    --> 32788R22FWJFW\psexec.cfexe
      [1] Archive type: RSRC
      --> Object
        [DETECTION] Contains recognition pattern of the APPL/PsExec.E application
Begin scan in 'E:\' <zhraa>

Beginning disinfection:
C:\System Volume Information\_restore{2FCFF432-6BE0-475C-BE2F-5E9914F3CB75}\RP165\A0045583.exe
    [NOTE]      The file was moved to '4a136e72.qua'!
C:\System Volume Information\_restore{2FCFF432-6BE0-475C-BE2F-5E9914F3CB75}\RP165\A0045584.exe
    [DETECTION] Contains recognition pattern of the APPL/BoontyGames application
    [NOTE]      The file was moved to '4b682c9b.qua'!
D:\System Volume Information\_restore{2FCFF432-6BE0-475C-BE2F-5E9914F3CB75}\RP165\A0045585.exe
    [NOTE]      The file was moved to '4b6b45e3.qua'!


End of the scan: 18 ربيع****الثاني, 1430  19:54
Used time: 26:25 Minute(s)

The scan has been done completely.

   7245 Scanned directories
 320506 Files were scanned
      3 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      3 Files were moved to quarantine
      0 Files were renamed
      1 Files cannot be scanned
 320502 Files not concerned
   3095 Archives were scanned
      1 Warnings
      4 Notes
  47047 Objects were scanned with rootkit scan
      0 Hidden objects were found



التوقيع