Bonjour verni29
voici le rapport de virustotal
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.73 2009.01.17 -
AhnLab-V3 2009.1.15.0 2009.01.16 -
AntiVir 7.9.0.55 2009.01.16 -
Authentium 5.1.0.4 2009.01.16 -
Avast 4.8.1281.0 2009.01.16 -
AVG 8.0.0.229 2009.01.16 -
BitDefender 7.2 2009.01.17 -
CAT-QuickHeal 10.00 2009.01.17 -
ClamAV 0.94.1 2009.01.17 -
Comodo 933 2009.01.16 -
DrWeb 4.44.0.09170 2009.01.17 -
eSafe 7.0.17.0 2009.01.15 -
eTrust-Vet 31.6.6312 2009.01.17 -
F-Prot 4.4.4.56 2009.01.16 -
F-Secure 8.0.14470.0 2009.01.17 -
Fortinet 3.117.0.0 2009.01.15 -
GData 19 2009.01.17 -
Ikarus T3.1.1.45.0 2009.01.17 -
K7AntiVirus 7.10.593 2009.01.16 -
Kaspersky 7.0.0.125 2009.01.17 -
McAfee 5497 2009.01.16 -
McAfee+Artemis 5497 2009.01.16 -
Microsoft None 2009.01.17 -
NOD32 3772 2009.01.16 -
Norman 5.93.01 2009.01.16 -
nProtect 2009.1.8.0 2009.01.16 -
Panda 9.5.1.2 2009.01.16 -
PCTools 4.4.2.0 2009.01.16 -
Prevx1 V2 2009.01.17 -
Rising 21.12.51.00 2009.01.17 -
SecureWeb-Gateway 6.7.6 2009.01.16 -
Sophos 4.37.0 2009.01.17 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.01.17 -
TheHacker 6.3.1.4.220 2009.01.14 -
TrendMicro 8.700.0.1004 2009.01.16 -
ViRobot 2009.1.16.1562 2009.01.16 -
VirusBuster 4.5.11.0 2009.01.16 -
Information additionnelle
File size: 333952 bytes
MD5...: 3bb03f2ba89d2be417206c373d2af17c
SHA1..: dca2004e5a5c3a555c7c474e15319df95cad5a67
SHA256: 2efd14332e133e71b09a0e00bf40cd9bc6850e976f05313b94b7e76780cddf3d
SHA512: f7d8afd3c98c9746403f90624e5629e4010a1e5256f4ef9369d2fa6ceaff0be3
cbd005447bec3570af53169e5dedc64c6a8c7c7977b8b675b8ddba66dc1d426d
ssdeep: 6144:IXjqecQPWtHaos5hQCiCHtUtMNAb4bG8z5CuJRylzzfu42MQpGU:IXpI6d5
5NUyAb42pFUpG
PEiD..: -
TrID..: File type identification
Win64 Executable Generic (87.2%)
Win32 Executable Generic (8.6%)
Generic Win/DOS Executable (2.0%)
DOS Executable Generic (2.0%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x5b105
timedatestamp.....: 0x4940f203 (Thu Dec 11 10:57:07 2008)
machinetype.......: 0x14c (I386)
( 10 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x380 0xd680 0xd680 6.63 407e26d68f44c71be08ffa000bb5292e
.rdata 0xda00 0x157c 0x1580 5.12 b17e1f6db3f94a57f1f4e54f8030176a
.data 0xef80 0x1fe8 0x2000 1.90 290252dc7b57e42144db3da8faa7d7d3
PAGE 0x10f80 0x37ced 0x37d00 6.72 fb99e297f8666f6802c4c01c9cb2ca13
PAGE8FIL 0x48c80 0x206e 0x2080 6.51 36e4ca7a7bc34a0ec77c50bc6beb60d1
PAGESMBC 0x4ad00 0x183 0x200 4.92 41e57cfdc1fe0c23081efaebdae18c65
PAGESMBD 0x4af00 0x1cc 0x200 0.42 0a782b525bc792f014a5add935d27659
INIT 0x4b100 0x1f08 0x1f80 5.90 f72c020896c981a8fbbab70966b323f8
.rsrc 0x4d080 0x5e8 0x600 4.93 dace1cea8631ff3c99229ab5e5806f1b
.reloc 0x4d680 0x41ec 0x4200 6.82 a0eb4a0d670cb49b4dde8c9e4cfe2445
( 5 imports )
> HAL.dll: KfReleaseSpinLock, KfAcquireSpinLock, KfLowerIrql, KfRaiseIrql, KeGetCurrentIrql
> ksecdd.sys: QueryContextAttributesW, FreeContextBuffer, MapSecurityError, ImpersonateSecurityContext, DeleteSecurityContext, AcquireCredentialsHandleW, AddCredentialsW, AcceptSecurityContext, InitSecurityInterfaceW, KSecValidateBuffer
> ntoskrnl.exe: ExReleaseResourceLite, ExAcquireResourceExclusiveLite, ExfInterlockedRemoveHeadList, RtlCompareUnicodeString, RtlUpcaseUnicodeChar, KeTickCount, RtlEqualUnicodeString, ExAcquireResourceSharedLite, KefReleaseSpinLockFromDpcLevel, KefAcquireSpinLockAtDpcLevel, RtlUnicodeStringToOemString, RtlxUnicodeStringToOemSize, RtlOemStringToUnicodeString, RtlxOemStringToUnicodeSize, NlsMbOemCodePageTag, KeSetEvent, InterlockedPushEntrySList, IoFreeIrp, IoCheckDesiredAccess, RtlCopyUnicodeString, KeQuerySystemTime, KeUnstackDetachProcess, KeStackAttachProcess, IoGetCurrentProcess, ZwClose, ZwQueryValueKey, ZwOpenKey, _wcsnicmp, ZwOpenFile, NtQueryInformationFile, RtlLengthSecurityDescriptor, NtQueryVolumeInformationFile, KeInitializeTimer, KeInitializeEvent, KeWaitForSingleObject, KeReadStateEvent, KeCancelTimer, KeSetTimer, KeClearEvent, KeSetTargetProcessorDpc, KeInitializeDpc, wcslen, MmBuildMdlForNonPagedPool, IoInitializeIrp, KeInsertQueue, NtWriteFile, NtReadFile, NtSetInformationFile, IoGetRelatedDeviceObject, ObReferenceObjectByHandle, IoCreateFile, memmove, RtlUpperChar, IoWriteErrorLogEntry, IoAllocateErrorLogEntry, IoDeleteDevice, ExQueueWorkItem, ObfReferenceObject, KeLeaveCriticalRegion, KeEnterCriticalRegion, KeInsertHeadQueue, IofCallDriver, IoCreateDevice, WmiGetClock, IoWMIWriteEvent, IofCompleteRequest, IoQueueWorkItem, IoAllocateWorkItem, KeReadStateQueue, ExAllocatePoolWithTagPriority, ProbeForRead, IoWMIRegistrationControl, KeQueryTimeIncrement, _except_handler3, _allmul, SeSinglePrivilegeCheck, SeExports, IoFreeMdl, IoBuildPartialMdl, MmUnlockPages, MmUnmapLockedPages, RtlFreeOemString, NtClose, ZwSetValueKey, _wcsicmp, PoUnregisterSystemState, MmUnlockPagableImageSection, RtlGetOwnerSecurityDescriptor, RtlGetDaclSecurityDescriptor, KeRundownQueue, KeDelayExecutionThread, PoRegisterSystemState, RtlSetOwnerSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlAddAccessAllowedAce, RtlCreateAcl, RtlLengthSid, RtlSubAuthoritySid, ObfDereferenceObject, RtlLengthRequiredSid, RtlCreateSecurityDescriptor, KeInitializeQueue, IoFreeWorkItem, DbgBreakPoint, RtlTimeToTimeFields, ExSystemTimeToLocalTime, RtlTimeFieldsToTime, _alldiv, KeBugCheckEx, RtlTimeToSecondsSince1970, FsRtlDoesNameContainWildCards, KeGetCurrentThread, IoAllocateIrp, IoQueueThreadIrp, MmProbeAndLockPages, IoAllocateMdl, MmLockPagableDataSection, RtlEqualString, NtCreateFile, NtDeviceIoControlFile, ZwDeviceIoControlFile, ZwCreateFile, IoCheckFunctionAccess, FsRtlMdlWriteCompleteDev, FsRtlPrepareMdlWriteDev, FsRtlMdlReadCompleteDev, FsRtlMdlReadDev, IoGetBaseFileSystemDeviceObject, IoCheckEaBufferValidity, RtlPrefixUnicodeString, NtRequestWaitReplyPort, RtlNtStatusToDosErrorNoTeb, IoCancelIrp, RtlInitString, IoWriteTransferCount, IoWriteOperationCount, IoReadTransferCount, IoReadOperationCount, IoStatisticsLock, wcscpy, RtlIntegerToUnicodeString, RtlInt64ToUnicodeString, NtOpenFile, IoSetThreadHardErrorMode, wcschr, _stricmp, RtlRandom, IoFastQueryNetworkAttributes, RtlSecondsSince1970ToTime, IoCheckQuerySetFileInformation, RtlUpcaseUnicodeStringToOemString, RtlFreeAnsiString, IoCheckQuerySetVolumeInformation, NtSetVolumeInformationFile, _allshr, NtSetSecurityObject, RtlValidRelativeSecurityDescriptor, NtQuerySecurityObject, NtQueryQuotaInformationFile, NtSetQuotaInformationFile, IoGetStackLimits, MmSizeOfMdl, wcscmp, RtlInitAnsiString, FsRtlIsFatDbcsLegal, RtlIsNameLegalDOS8Dot3, NlsOemLeadByteInfo, RtlUnicodeToOemN, RtlUpcaseUnicodeToOemN, KeDetachProcess, KeAttachProcess, PsAssignImpersonationToken, SeFreePrivileges, RtlMapGenericMask, IoSetFileOrigin, KeGetRecommendedSharedDataAlignment, KeNumberProcessors, _snwprintf, toupper, RtlTimeToSecondsSince1980, RtlValidSecurityDescriptor, RtlVerifyVersionInfo, VerSetConditionMask, MmIsThisAnNtAsSystem, PsCreateSystemThread, KeSetIdealProcessorThread, NtSetInformationThread, PsTerminateSystemThread, KeRemoveQueue, RtlDestroyHeap, RtlAllocateHeap, RtlFreeHeap, RtlCreateHeap, NtConnectPort, NtCreateSection, KeInitializeSpinLock, ExInitializeResourceLite, InterlockedPopEntrySList, ExDeleteResourceLite, ExAllocatePoolWithTag, DbgPrint, ExFreePoolWithTag, ExLocalTimeToSystemTime, RtlCompareMemory, MmMapLockedPages, MmMapLockedPagesSpecifyCache, RtlAnsiStringToUnicodeString, NtAllocateVirtualMemory, NtFreeVirtualMemory, ExfInterlockedAddUlong, RtlInitUnicodeString, RtlUpcaseUnicodeString, RtlFreeUnicodeString, SeLockSubjectContext, SeQueryAuthenticationIdToken, SeUnlockSubjectContext, SeCaptureSubjectContext, SeAccessCheck, SeReleaseSubjectContext, RtlInitializeSid, WmiTraceMessage, ZwSetEvent, ZwWaitForSingleObject, KeResetEvent, KeWaitForMultipleObjects, KeInitializeSemaphore, ZwCreateEvent, ZwMapViewOfSection, ZwCreateSection, KeReleaseSemaphore, ExfInterlockedInsertTailList
> TDI.SYS: TdiDeregisterPnPHandlers, TdiRegisterPnPHandlers, TdiOpenNetbiosAddress, TdiReturnChainedReceives, TdiCopyBufferToMdl
> WMILIB.SYS: WmiSystemControl, WmiCompleteRequest
( 0 exports )
je fait la suite et te l'envoye
christine29 dit que findykill à été mis a jour cette nuit ,ça va nous servir peux être
A+