بسم الله الرحمن الرحيم
التجربة على المكافي
تم تفعيل ال maximum protection لكن مع وضع الـ Access protection على وضع ال Report only mode
مشاهدة المرفق 55871
ثانيا تم أضافة قاعدة لمراقبة جميع قيم الريجستري
مشاهدة المرفق 55872
مشاهدة المرفق 55873
وقاعدة لمراقبة جميع الملفات بالسي
مشاهدة المرفق 55874
وأخرى لمراقبة الحقن بالعملية explorer.exe
مشاهدة المرفق 55875
ثم تم تشغيل الملف وتجمد النظام>> طبعا المكافي يعطي تقارير فقط
مشاهدة المرفق 55876
وتمت كتابة ok >>> حلوة يايونس

أقترح اضافة ملف مضاد مع الفيروسات التي يطرحها الاعضاء
وظهرت هذة الرسالة بها مسار الفيروس
مشاهدة المرفق 55877
ثم تم عمل ريستارت وأشتغل النظام
مشاهدة المرفق 55878
مشاهدة المرفق 55879
وفي ذلك الحين قام المكافي بفصفصة الملف بشكل كامل وأليكم التقرير + التحليل
تشغيل الملف
30/06/2014 06:04:39 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\VERCLSID.EXE User-defined Rules

revent programs to access to System drive Action blocked : Read
أستخراج نفسه في بيانات البريفيكت >> ليعمل بسرعة وتلقائيا مع بدأ التشغيل رائع يايونس
30/06/2014 06:04:39 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf User-defined Rules

revent programs to access to System drive Action blocked : Read
أضافة قاعدة الى الكرنل عن طريق ملف ال ntdl
30/06/2014 06:04:39 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\ntdll.dll User-defined Rules

revent programs to access to System drive Action blocked : Read
وطبعا بديهي الحقن في ال kernel.dll
30/06/2014 06:04:39 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\KERNEL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
++ مع العلم انه يمكن حقن مكتبة ربط ديناميكي dll بهذين الملفين لجعل أي ملف تريده يعمل مع الستارت اب!!!
يحاول الاتصال بالملف المسؤول عن اليونيكود UNICODE.NLS واعطاب هذا الملف يمنع الجهاز من تنصيب أية برامج
30/06/2014 06:04:40 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\UNICODE.NLS User-defined Rules

revent programs to access to System drive Action blocked : Read
+ التعديل على ملفات أخرى
30/06/2014 06:04:41 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\SORTTBLS.NLS User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:41 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\OLE32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\RPCRT4.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:42 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\SECUR32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:43 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\GDI32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:43 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\USER32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:43 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\MSVCRT.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
يحاول استخراج ملف في مجلد System32
30/06/2014 06:04:44 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\VERCLSID.EXE User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:44 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\LPK.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:44 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\USP10.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:44 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\RPCSS.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:45 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\MSCTF.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:46 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\IMM32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
الملف المستخرج يحاول التعديل على ملف نظام
30/06/2014 06:04:46 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\LPK.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
الحصول على الصلاحيات لتجميد الشاشة
30/06/2014 06:04:46 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:46 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\WININET.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:46 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:46 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:47 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:47 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:47 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\RICHED20.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:47 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:47 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\SHELL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:47 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:48 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\COMCTL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:48 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\VERCLSID.EXE User-defined Rules

revent programs to access to System drive Action blocked : Read
بعد الحصول على الصلاحيات من الملف المستخرج بدا عملية التجميد
30/06/2014 06:04:48 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:48 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MSXML3.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:48 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\LPK.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:48 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MSXML3.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:48 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\USP10.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MSXML3R.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\MSCTF.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
والآن تم الحقن في ملف ال svchost
30/06/2014 06:04:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SoftwareDistribution\ReportingEvents.log User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\MSASN1.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
يحاول ال svchost الحقن في ملف ال wuauclt
30/06/2014 06:04:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wuauclt.exe User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\RICHED20.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\APPHELP.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:50 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares **\VERCLSID.EXE C:\WINDOWS\System32\APPHELP.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:50 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wuauclt.exe User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:50 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\LPK.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:51 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wuauclt.exe User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:51 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\RPCSS.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:51 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wuauclt.exe User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:51 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\MSCTF.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:52 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:52 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\IMM32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
تم الحقن في ملف ال wuauclt
30/06/2014 06:04:52 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:52 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\CLBCATQ.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:53 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\ntdll.dll User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:53 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\Registration\R000000000007.clb User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:53 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\KERNEL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:53 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\SHDOCVW.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:53 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\UNICODE.NLS User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:53 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\SHDOCVW.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:54 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:54 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\LOCALE.NLS User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:54 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\WININET.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:54 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\SORTTBLS.NLS User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:54 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:55 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
;تمت سرقة صلاحيات الملف wuauclt
30/06/2014 06:04:55 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\wuauclt.exe User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:55 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:55 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\MSVCRT.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:55 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\WindowsShell.Manifest User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:55 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\OLE32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:56 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\WindowsShell.Manifest User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:56 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\RPCRT4.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:56 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\WindowsShell.Manifest User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:56 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\WINMM.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:56 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:57 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\MSACM32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:57 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\RICHED20.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:57 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\VERSION.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:58 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
فتح الثغرة للملف المستخرج لتجميد الشاشة
30/06/2014 06:04:58 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\SHELL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:58 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\SHELL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:58 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\SHELL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:59 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\USERENV.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:59 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\SHELL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:04:59 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\UXTHEME.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:04:59 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\SHELL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:00 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\CTYPE.NLS User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:00 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:01 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\system32\verclsid.exe C:\WINDOWS\System32\COMCTL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:01 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\LPK.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\MYDOCS.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\WINSPOOL.DRV User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\Documents and Settings\ALFARES\Start Menu\Programs\DESKTOP.INI User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\IPHLPAPI.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\SHELL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\WINHTTP.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\CRYPT32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\DESKTOP.INI User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\MSASN1.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\DESKTOP.INI User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:02 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\MSPATCHA.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\DESKTOP.INI User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\WBEM\WBEMCOMN.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) SMART-PC\alfares C:\WINDOWS\Explorer.EXE C:\Documents and Settings\All Users\Start Menu\Programs\Games\DESKTOP.INI User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM **\WUAUCLT.EXE C:\WINDOWS\System32\SETUPAPI.DLL User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\SHIMENG.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\Common Framework\ccme_base.dll User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\UXTHEME.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:05:03 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WBEM\Logs\wbemcore.log User-defined Rules

revent programs to access to System drive Action blocked : Write
30/06/2014 06:05:04 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\LPK.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:05:04 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:04 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL User-defined Rules

revent programs to access to System drive Action blocked : Execute
30/06/2014 06:05:04 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM \??\C:\WINDOWS\system32\csrss.exe C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy User-defined Rules

revent programs to access to System drive Action blocked : Read
30/06/2014 06:05:05 ص Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WBEM\Logs\wbemcore.log User-defined Rules

revent programs to access to System drive Action blocked : Write
الحقن عن طريق الربط الديناميكي dll hijacking
بالتوفيق