Bonjour et d'avance merci,
Aux adeptes de l'énigme, je pose cette question à laquelle j'espère qu'il voudront bien répondre :
"Le fichier "ComRepl", présent sur mon ordinateur à l'adresse "C:\Users\utilisateur\AppData\Roaming", est-il (infecté par) un programme malveillant ?"
Je joins le rapport d'analyse par VirusTotal dudit fichier :
"Résultat: 6/39 (15.39%)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.73 2008.12.24 Trojan.Win32.Tervemoy.A!IK
AhnLab-V3 2008.12.25.0 2008.12.24 -
AntiVir 7.9.0.45 2008.12.24 -
Authentium 5.1.0.4 2008.12.24 -
Avast 4.8.1281.0 2008.12.24 -
AVG 8.0.0.199 2008.12.24 -
BitDefender 7.2 2008.12.24 -
CAT-QuickHeal 10.00 2008.12.24 -
ClamAV 0.94.1 2008.12.24 -
Comodo 809 2008.12.24 -
DrWeb 4.44.0.09170 2008.12.24 -
eSafe 7.0.17.0 2008.12.24 -
eTrust-Vet 31.6.6276 2008.12.24 -
Ewido 4.0 2008.12.24 -
F-Prot 4.4.4.56 2008.12.24 -
F-Secure 8.0.14332.0 2008.12.24 -
Fortinet 3.117.0.0 2008.12.24 -
GData 19 2008.12.24 -
Ikarus T3.1.1.45.0 2008.12.24 Trojan.Win32.Tervemoy.A
K7AntiVirus 7.10.564 2008.12.24 -
Kaspersky 7.0.0.125 2008.12.24 Heur.Trojan.Generic
McAfee 5474 2008.12.24 -
McAfee+Artemis 5473 2008.12.23 -
Microsoft 1.4205 2008.12.24 TrojanDownloader:Win32/Horst.O
NOD32 3716 2008.12.24 -
Norman 5.80.02 2008.12.24 -
Panda 9.0.0.4 2008.12.24 Suspicious file
PCTools 4.4.2.0 2008.12.24 -
Prevx1 V2 2008.12.24 Cloaked Malware
Rising 21.09.22.00 2008.12.24 -
SecureWeb-Gateway 6.7.6 2008.12.24 -
Sophos 4.37.0 2008.12.24 -
Sunbelt 3.2.1809.2 2008.12.22 -
Symantec 10 2008.12.24 -
TheHacker 6.3.1.4.199 2008.12.23 -
TrendMicro 8.700.0.1004 2008.12.24 -
VBA32 3.12.8.10 2008.12.24 -
ViRobot 2008.12.24.1534 2008.12.24 -
VirusBuster 4.5.11.0 2008.12.24 -
Information additionnelle
File size: 65536 bytes
MD5...: 0ceb7e9eec9d08970b7d43bbe929b16d
SHA1..: 1b2829d1cec7b61c8c29cebb6da5ae5e3f91de10
SHA256: e665b8c9981cba4a94fc9e7be827b06314afc28bb2c42e029c93c2381ea02942
SHA512: 02d82654f6e0287258e439d605ccd4273661a1154b0752e929a793bca3865f72
874e441f3b1b21c614f0a19cc538d97684daaf1a4b84569c0bde58e707faed25
ssdeep: 1536:Lbo3eg7YmiKOO/oB3SaJRF1JDjCUP2YbmR22IZSlZ9mh+oMt:Lc3eg7Yml/
oB3SaJRF1JDjCUP2esIZSB
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x406efe
timedatestamp.....: 0x48aeba24 (Fri Aug 22 13:07:48 2008)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xb71f 0xc000 6.26 426a20ba672f2868648cba331492bf16
.rdata 0xd000 0x1b12 0x2000 4.66 360b324f2418b6753a0b2274aff03861
.data 0xf000 0x49d8 0x1000 1.48 2577f403568056cc12d69fba7074117a
( 5 imports )
> USER32.dll: LoadImageA
> ADVAPI32.dll: RegCreateKeyExA, RegQueryValueExA, RegGetKeySecurity, RegOpenKeyExA, RegSetValueExA, RegCloseKey
> WS2_32.dll: -
> WININET.dll: HttpQueryInfoA, InternetOpenA, InternetOpenUrlA, InternetReadFile, InternetCloseHandle
> KERNEL32.dll: ExitProcess, GetSystemInfo, VirtualProtect, GetLocaleInfoA, FlushFileBuffers, GetStringTypeW, GetStringTypeA, LCMapStringW, MultiByteToWideChar, LCMapStringA, CreateDirectoryA, GetStartupInfoA, GetFileTime, GetVolumeInformationA, GetSystemDirectoryA, GetFileType, OpenProcess, GetProcessPriorityBoost, OpenMutexA, CreateMutexA, CloseHandle, GetLogicalDriveStringsA, GetDriveTypeA, Sleep, GetLocalTime, LoadLibraryA, GetModuleFileNameA, SetEnvironmentVariableA, GetEnvironmentVariableA, ReadFile, CreateFileA, WriteFile, CreateProcessA, GlobalFree, CopyFileA, CreateThread, GlobalAlloc, GetCurrentProcess, GetProcAddress, RtlUnwind, GetModuleHandleA, TerminateProcess, GetCommandLineA, GetVersionExA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetLastError, GetEnvironmentStringsW, SetHandleCount, HeapDestroy, HeapCreate, VirtualFree, HeapFree, SetFilePointer, HeapAlloc, InterlockedExchange, VirtualQuery, SetUnhandledExceptionFilter, IsBadReadPtr, IsBadWritePtr, IsBadCodePtr, HeapReAlloc, HeapSize, GetACP, GetOEMCP, GetCPInfo, VirtualAlloc, SetStdHandle
( 0 exports )
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=3263BBB600FF712200E5016B0598A30056934E70' target='_blank'>http://info.prevx.com/..."
Configuration: Windows Vista
Internet Explorer 7.0