المكافي

بالفحص أكتشف ملف واحد :\ وبالارتيميز كمان !!!
وعندد فتح مجلد العينة
مدفع الأفطااااااااار أضضرب
المتبقي
3
وتبين أن ملف ال pdf يحتوي على فيروس بالجافا
تم أستخراجه في ملف التيمب منسفه الأرتيميز
وعند فتحه >ملف فارغ
أما ملف الورد فقد تبين احتواءه على فيروس ماكرو
وبفك الضغط عنه
تظهر امامكم الىن ملفات سكربته الماكرو
وبالتشغيل ظهر تحذير من الاوفيس بوجودد ماكرو
تم عمل ألاو للماكرو
وتم تغيل ملف في التيب في بيئة 16 بت ntvdm
وقام ملف الوورد بنسخ نفسه واخفاء النسخة
وبعد ذالك يتالق المكافي
عطب الملف
الملف الثالث مع سباي يلتير
اولا الملف يحاول تسجيل ضربات لوحة المفاتيح

كيلوجر
بعدد ذلك يريد الاتصال بالانترنت
بعد ذلك الملف يريد حفظ بيانات في نفسه
وطبيعي بعد ذلك انه يريد ارسال رسالة عن طريق البورت 53 ببروتوكول ال UDP
ملحوظة : طبعا الأي بي شبكي لأني عملتله بلوك
بعد ذلك الملف يريد الوصول للكاميرا !!!!
عادي ياعم انا عارف اني حلو


ألاو ياعم هههه بهزر

بس بصراحة كان نفسي اعمله ألاو
كود:
06/07/2014 12:52:48 ص Would be blocked by port blocking rule (rule is currently not enforced) C:\Program Files\Microsoft Office\Office15\WINWORD.EXE Common Maximum Protection:Prevent HTTP communication 65.52.129.119:80
06/07/2014 12:53:44 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Delete
06/07/2014 12:53:49 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{7AC51306-6A3F-49A3-B9D6-3FC46BEA12E0}_{B97FD074-ECF3-440D-9722-7AB2451DB417}_{CF8D5900-4DD5-4D51-B1DE-F7CFA52A3712}\WpadDecisionReason Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Create
06/07/2014 12:53:49 ص Would be blocked by Access Protection rule (rule is currently not enforced) Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE C:\Users\Medo\AppData\Local\Temp\389nvry8392y.exe Anti-spyware Maximum Protection:Prevent all programs from running files from the Temp folder Action blocked : Execute
06/07/2014 12:53:53 ص Would be blocked by Access Protection rule (rule is currently not enforced) Medo-PC\Medo C:\Windows\system32\ntvdm.exe C:\Users\Medo\AppData\Local\Temp\389nvry8392y.exe Anti-spyware Maximum Protection:Prevent all programs from running files from the Temp folder Action blocked : Execute
06/07/2014 12:54:26 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Create
06/07/2014 12:54:28 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Delete
06/07/2014 12:54:29 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE C:\Users\Medo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2OU6E6C1\ss[1].htm Anti-virus Maximum Protection:Protect cached files from password and email address stealers Action blocked : Read
06/07/2014 12:54:29 ص Would be blocked by port blocking rule (rule is currently not enforced) C:\Program Files\Microsoft Office\Office15\WINWORD.EXE Common Maximum Protection:Prevent HTTP communication 186.64.120.59:80
06/07/2014 12:54:32 ص Would be blocked by Access Protection rule (rule is currently not enforced) Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE C:\Users\Medo\AppData\Local\Temp\389nvry8392y.exe Anti-spyware Maximum Protection:Prevent all programs from running files from the Temp folder Action blocked : Execute
06/07/2014 12:54:32 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{7AC51306-6A3F-49A3-B9D6-3FC46BEA12E0}_{B97FD074-ECF3-440D-9722-7AB2451DB417}_{CF8D5900-4DD5-4D51-B1DE-F7CFA52A3712}\WpadDecisionReason Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Create
06/07/2014 12:54:33 ص Would be blocked by Access Protection rule (rule is currently not enforced) Medo-PC\Medo C:\Windows\system32\ntvdm.exe C:\Users\Medo\AppData\Local\Temp\389nvry8392y.exe Anti-spyware Maximum Protection:Prevent all programs from running files from the Temp folder Action blocked : Execute
06/07/2014 12:55:19 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Create
06/07/2014 12:55:23 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Delete
06/07/2014 12:55:24 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE C:\Users\Medo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CPDBO1GK\ss[1].htm Anti-virus Maximum Protection:Protect cached files from password and email address stealers Action blocked : Read
06/07/2014 12:55:29 ص Would be blocked by Access Protection rule (rule is currently not enforced) Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE C:\Users\Medo\AppData\Local\Temp\389nvry8392y.exe Anti-spyware Maximum Protection:Prevent all programs from running files from the Temp folder Action blocked : Execute
06/07/2014 12:55:29 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{7AC51306-6A3F-49A3-B9D6-3FC46BEA12E0}_{B97FD074-ECF3-440D-9722-7AB2451DB417}_{CF8D5900-4DD5-4D51-B1DE-F7CFA52A3712}\WpadDecisionReason Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Create
06/07/2014 12:55:30 ص Would be blocked by Access Protection rule (rule is currently not enforced) Medo-PC\Medo C:\Windows\system32\ntvdm.exe C:\Users\Medo\AppData\Local\Temp\389nvry8392y.exe Anti-spyware Maximum Protection:Prevent all programs from running files from the Temp folder Action blocked : Execute
06/07/2014 12:55:31 ص Blocked by Access Protection rule Medo-PC\Medo C:\Program Files\Microsoft Office\Office15\WINWORD.EXE \REGISTRY\USER\S-1-5-21-14795968-3807436459-3956762135-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Create
