PDA

نسخه کامل مشاهده نسخه کامل : آیا این پروسسها ویروس اند ؟



mohammadgame
20-08-2009, 14:02
من sysinpectore نود 32 رو دارم وقتی بازش می کنم این پروسسها رو با رنگ قرمز نشون می ده !!

"Process" = "winwd.exe" 644 ; MOHAMMAD\mohamad ; ( 6: Unknown ) ;
"File Size" = "26624"
"SHA1" = "74D0852EC608C79990DB2F194251E48CF9AA7F3D"
"Creation Time" = "2005/04/19 02:26"
"Last Write Time" = "2005/04/19 02:26"
"Linked to" = "Running Processes -> winwd.exe"
"Linked to" = "Running Processes -> winwd.exe -> c:\windows\winwd.exe"
"Linked to" = "Important Registry Entries -> Standard Autostart -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\WINDOWS\winwd.exe"




"Process" = "winsersec.exe" 904 ; NT AUTHORITY\SYSTEM ; ( 6: Unknown ) ;
"File Size" = "53248"
"SHA1" = "0AD803AE6B8539E6629FBA125E600EA4D4840377"
"Creation Time" = "2005/04/14 03:07"
"Last Write Time" = "2005/04/14 03:07"
"Linked to" = "Running Processes -> winsersec.exe"
"Linked to" = "Running Processes -> winsersec.exe -> c:\windows\system32\winsersec.exe"
"Linked to" = "Services -> c:\windows\system32\winsersec.exe"

همچنین تو گزینه درایور این گزینه زیر قرمز رنگ هست
"winachsf" = "c:\windows\system32\drivers\hsf_cnxt.sys" Manual ; Running ; ( 6: Unknown ) ; HSF_CNXT driver ; Conexant Systems, Inc. ;
"Internal Name" = "HSF_CNXT.sys"
"Product Name" = "SoftK56 Modem Driver"
"File Version" = "7.60.00 built by: WinDDK"
"Company Name" = "Conexant Systems, Inc."
"File Description" = "HSF_CNXT driver"
"File Size" = "730112"
"SHA1" = "33D185F553197A97A245B124C8D5EA1FD7627376"
"Creation Time" = "2009/07/16 16:52"
"Last Write Time" = "2006/11/08 11:29"
"Linked to" = "Drivers -> c:\windows\system32\drivers\hsf_cnxt.sys"

saeed774
21-08-2009, 12:38
اين برنامه نود پروسس هايي كه به رنگ قرمز نشون ميده نشان دهنده اينه كه اين فايل ها از فايل هاي آسيب پذير هستن و ميتونن در معرض خطر قرار بگيرن . در ثاني اگه ويروس بودن كه خودش عكس العملي چيزي نشون ميداد .