من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم ورحمة الله وبركاته
قبل يومين تقريبا اصيب جهازي الاخر باحد الفيروسات وفيما اعتقد انه سالتي ( Sality )
حاولت القضاء عليه وصادفتني بعض المشاكل وبعدها عملت استعادة نسخة جوست
وعملت تنظيف باداة Zyzoom_CyberScrub_Privacy ومن ثم باداة ComboFix
واخيرا فحص بالوضع الامن باداة الكاسبر المحموله
لكن لاحظت ان جميع الملفات مصابه خصوصا ملفات التشغيل :?:
وهذا جزء من التقرير الذي لم يكتمل حتى الان
ارجوا مساعدتي في ذلك وهل هناك ضرر اذا عملت للملفات استعادة ؟
قبل يومين تقريبا اصيب جهازي الاخر باحد الفيروسات وفيما اعتقد انه سالتي ( Sality )
حاولت القضاء عليه وصادفتني بعض المشاكل وبعدها عملت استعادة نسخة جوست
وعملت تنظيف باداة Zyzoom_CyberScrub_Privacy ومن ثم باداة ComboFix
واخيرا فحص بالوضع الامن باداة الكاسبر المحموله
لكن لاحظت ان جميع الملفات مصابه خصوصا ملفات التشغيل :?:
وهذا جزء من التقرير الذي لم يكتمل حتى الان
43% - Scan
----------
Scanned: 142462
Detected: 47
Untreated: 0
Start time: 10/04/1430 04:10:14 م
Duration: 01:08:25
Finish time: 10/04/1430 06:45:07 م
----------
Scanned: 142462
Detected: 47
Untreated: 0
Start time: 10/04/1430 04:10:14 م
Duration: 01:08:25
Finish time: 10/04/1430 06:45:07 م
Detected
--------
Status Object
------ ------
deleted: Trojan program Trojan.Win32.Agent2.fsa File: c:\windows\system32\reader_s.exe
deleted: Trojan program Trojan.Win32.Agent2.fsa File: c:\documents and settings\thunder\reader_s.exe
quarantined: new threat Type_Win32 (modification) File: c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
quarantined: new threat Type_Win32 (modification) File: c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe
deleted: Trojan program Rootkit.Win32.Agent.jj File: c:\windows\system32\drivers\protect.sys
quarantined: new threat Type_Win32 (modification) File: c:\windows\system32\stacsv.exe
quarantined: new threat Type_Win32 (modification) File: c:\program files\golden al-wafi translator\golden al-wafi translator.exe
deleted: Trojan program Packed.Win32.Krap.i File: C:\Documents and Settings\thunder\Local Settings\Temporary Internet Files\Content.IE5\GT6Z4XAR\ge[1].txt
deleted: Trojan program Trojan.Win32.Agent2.fsa File: C:\Documents and Settings\thunder\Local Settings\Temporary Internet Files\Content.IE5\GXE78DI7\abb[1].txt
deleted: Trojan program Trojan.Win32.Obfuscated.gen File: C:\Program Files\Circle Developement\Uninstall.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\K-Lite Codec Pack\kl_upx.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Ozone\Audio Converter\record Crack.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\PaintDotNet.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\SetupNgen.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\UpdateMonitor.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\WiaProxy32.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\SigmaTel\C-Major Audio\WDM\stacsv.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\ATA Live Update.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Setup1.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\SWXCACLS.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Installer\{350C97B7-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
deleted: Trojan program Packed.Win32.Krap.i File: C:\WINDOWS\system32\A.tmp
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\kl_upx.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\lights.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\admin.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\author.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\fp98sadm.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\fpremadm.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\lights.exe
--------
Status Object
------ ------
deleted: Trojan program Trojan.Win32.Agent2.fsa File: c:\windows\system32\reader_s.exe
deleted: Trojan program Trojan.Win32.Agent2.fsa File: c:\documents and settings\thunder\reader_s.exe
quarantined: new threat Type_Win32 (modification) File: c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
quarantined: new threat Type_Win32 (modification) File: c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe
deleted: Trojan program Rootkit.Win32.Agent.jj File: c:\windows\system32\drivers\protect.sys
quarantined: new threat Type_Win32 (modification) File: c:\windows\system32\stacsv.exe
quarantined: new threat Type_Win32 (modification) File: c:\program files\golden al-wafi translator\golden al-wafi translator.exe
deleted: Trojan program Packed.Win32.Krap.i File: C:\Documents and Settings\thunder\Local Settings\Temporary Internet Files\Content.IE5\GT6Z4XAR\ge[1].txt
deleted: Trojan program Trojan.Win32.Agent2.fsa File: C:\Documents and Settings\thunder\Local Settings\Temporary Internet Files\Content.IE5\GXE78DI7\abb[1].txt
deleted: Trojan program Trojan.Win32.Obfuscated.gen File: C:\Program Files\Circle Developement\Uninstall.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\K-Lite Codec Pack\kl_upx.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Ozone\Audio Converter\record Crack.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\PaintDotNet.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\SetupNgen.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\UpdateMonitor.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\Paint.NET\WiaProxy32.exe
quarantined: new threat Type_Win32 (modification) File: C:\Program Files\SigmaTel\C-Major Audio\WDM\stacsv.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\ATA Live Update.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Setup1.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\SWXCACLS.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Installer\{350C97B7-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
deleted: Trojan program Packed.Win32.Krap.i File: C:\WINDOWS\system32\A.tmp
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\kl_upx.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\lights.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\admin.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\author.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\fp98sadm.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\fpremadm.exe
quarantined: new threat Type_Win32 (modification) File: C:\WINDOWS\system32\dllcache\lights.exe
Events
------
Time Name Status Reason
---- ---- ------ ------
10/04/1430 04:11:12 م Running module: smss.exe\smss.exe ok scanned
------
Time Name Status Reason
---- ---- ------ ------
10/04/1430 04:11:12 م Running module: smss.exe\smss.exe ok scanned
Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------
Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Disinfect, delete if disinfection fails
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes
--------
Parameter Value
--------- -----
Security Level Recommended
Action Disinfect, delete if disinfection fails
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
------
Status Object Size
------ ------ ----
ارجوا مساعدتي في ذلك وهل هناك ضرر اذا عملت للملفات استعادة ؟
