Résultat de l'analyse de mfevtps.exe :
Fichier mfevtps.exe reçu le 2009.04.19 20:27:41 (CET)Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.04.19 -
AhnLab-V3 5.0.0.2 2009.04.19 -
AntiVir 7.9.0.148 2009.04.19 -
Antiy-AVL 2.0.3.1 2009.04.17 -
Authentium 5.1.2.4 2009.04.19 -
Avast 4.8.1335.0 2009.04.19 -
AVG 8.5.0.287 2009.04.18 -
BitDefender 7.2 2009.04.19 -
CAT-QuickHeal 10.00 2009.04.18 -
ClamAV 0.94.1 2009.04.19 -
Comodo 1121 2009.04.19 -
DrWeb 4.44.0.09170 2009.04.19 -
eSafe 7.0.17.0 2009.04.19 -
eTrust-Vet 31.6.6455 2009.04.14 -
F-Prot 4.4.4.56 2009.04.19 -
F-Secure 8.0.14470.0 2009.04.19 -
Fortinet 3.117.0.0 2009.04.19 -
GData 19 2009.04.19 -
Ikarus T3.1.1.49.0 2009.04.19 -
K7AntiVirus 7.10.707 2009.04.17 -
Kaspersky 7.0.0.125 2009.04.19 -
McAfee 5589 2009.04.19 -
McAfee+Artemis 5589 2009.04.19 -
McAfee-GW-Edition 6.7.6 2009.04.19 -
Microsoft 1.4502 2009.04.19 -
NOD32 4019 2009.04.18 -
Norman 6.00.06 2009.04.17 -
nProtect 2009.1.8.0 2009.04.19 -
Panda 10.0.0.14 2009.04.19 -
PCTools 4.4.2.0 2009.04.17 -
Prevx1 V2 2009.04.19 -
Rising 21.25.62.00 2009.04.19 -
Sophos 4.40.0 2009.04.19 -
Sunbelt 3.2.1858.2 2009.04.18 -
Symantec 1.4.4.12 2009.04.19 -
TheHacker 6.3.4.0.309 2009.04.16 -
TrendMicro 8.700.0.1004 2009.04.17 -
VBA32 3.12.10.2 2009.04.12 -
ViRobot 2009.4.18.1685 2009.04.18 -
VirusBuster 4.6.5.0 2009.04.19 -
Information additionnelle
File size: 67904 bytes
MD5...: b87b41f2c05788f04a3b487902803fd2
SHA1..: 54a5aa890e26d9e83abb26c43ff00972a6fd6be6
SHA256: 62e14fb50e815cc5994155108055af72e908fd887070c33f6b2f980951e4673a
SHA512: 0d60d0474cf8b112198f9e436255b2e7fc010f3e18d5d96756b08ee13912991e<BR>b58c44260ffcc14d8eb3b68a8c719b223d2eb4e9fbb91b10b8884efc8cf08594
ssdeep: 1536:vSgONlbwGiXZcCshFZaRKjOOeUeEoRhXjR8:v/1xX68KjXeUey<BR>
PEiD..: -
TrID..: File type identification<BR>Win32 Executable Generic (42.3%)<BR>Win32 Dynamic Link Library (generic) (37.6%)<BR>Generic Win/DOS Executable (9.9%)<BR>DOS Executable Generic (9.9%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x612d<BR>timedatestamp.....: 0x48d2de36 (Thu Sep 18 23:03:18 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x5a12 0x5c00 6.38 c967e99fef55683f19d20ff0d0bbacb3<BR>.rdata 0x7000 0x359a 0x3600 5.23 a37d987e15dacfd22251e7d8b724643a<BR>.data 0xb000 0x5840 0x5400 5.10 24615b081256e7a1f1665c1b1593eedc<BR>.bldvar 0x11000 0x13 0x200 0.33 ce0d85a5378e39e6757076f58752d0b7<BR>.rsrc 0x12000 0x540 0x600 3.83 52ed1c39de138bfcb8d63fceb8083624<BR><BR>( 7 imports ) <BR>> PSAPI.DLL: EnumProcessModules, GetMappedFileNameW, GetModuleInformation<BR>> ADVAPI32.dll: GetTokenInformation, CryptReleaseContext, RegOpenKeyW, CryptAcquireContextW, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, OpenProcessToken, OpenThreadToken, AdjustTokenPrivileges, PrivilegeCheck, LookupPrivilegeValueW, StartServiceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, QueryServiceStatus, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, GetSecurityDescriptorDacl, CopySid, GetLengthSid, SetServiceObjectSecurity, AllocateAndInitializeSid, SetSecurityDescriptorDacl, AddAccessAllowedAceEx, AddAccessDeniedAceEx, InitializeAcl, InitializeSecurityDescriptor<BR>> WINTRUST.dll: WTHelperGetProvCertFromChain, WTHelperProvDataFromStateData, WinVerifyTrust, WTHelperGetProvSignerFromChain<BR>> CRYPT32.dll: CertEnumCertificatesInStore, CertNameToStrW, CertCompareCertificate, CertOpenStore, CertAddSerializedElementToStore<BR>> KERNEL32.dll: GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, FindClose, FindFirstFileW, GetModuleHandleA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetProcAddress, GetVersion, GetLastError, DeviceIoControl, WaitForSingleObject, GetSystemDirectoryW, CloseHandle, CreateThread, CreateEventW, SetEvent, FreeLibrary, LoadLibraryA, GetCurrentProcess, GetCurrentThread, Sleep, CreateFileW, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, GetFileAttributesExW, GetSystemWindowsDirectoryW, EnterCriticalSection, QueryDosDeviceW, GetLogicalDriveStringsW, LoadLibraryW, GetVersionExW, OpenProcess, DeleteCriticalSection, InitializeCriticalSection, GetWindowsDirectoryW, GetEnvironmentVariableW, FileTimeToSystemTime, FileTimeToLocalFileTime, GetModuleFileNameW, InterlockedCompareExchange, InterlockedIncrement, InterlockedDecrement, InterlockedExchange, GetCurrentThreadId, TerminateProcess, QueryPerformanceCounter, DebugBreak<BR>> msvcrt.dll: wcschr, malloc, memset, free, _snwprintf, _purecall, wcsrchr, wcsncpy, printf, memcpy, _wcsnicmp, _wcsdup, _wcsicmp, _unlock, __dllonexit, _lock, _onexit, __wgetmainargs, _exit, _XcptFilter, exit, _initterm, _amsg_exit, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _terminate@@YAXXZ, _controlfp, wcscpy, _errno, _cexit, wcscat<BR>> ntdll.dll: RtlUnwind<BR><BR>( 0 exports ) <BR>
RDS...: NSRL Reference Data Set<BR>-
CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=b87b41f2c05788f04a3b487902803fd2' target='_blank'>http://research.sunbelt-software.com/...
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.04.19 -
AhnLab-V3 5.0.0.2 2009.04.19 -
AntiVir 7.9.0.148 2009.04.19 -
Antiy-AVL 2.0.3.1 2009.04.17 -
Authentium 5.1.2.4 2009.04.19 -
Avast 4.8.1335.0 2009.04.19 -
AVG 8.5.0.287 2009.04.18 -
BitDefender 7.2 2009.04.19 -
CAT-QuickHeal 10.00 2009.04.18 -
ClamAV 0.94.1 2009.04.19 -
Comodo 1121 2009.04.19 -
DrWeb 4.44.0.09170 2009.04.19 -
eSafe 7.0.17.0 2009.04.19 -
eTrust-Vet 31.6.6455 2009.04.14 -
F-Prot 4.4.4.56 2009.04.19 -
F-Secure 8.0.14470.0 2009.04.19 -
Fortinet 3.117.0.0 2009.04.19 -
GData 19 2009.04.19 -
Ikarus T3.1.1.49.0 2009.04.19 -
K7AntiVirus 7.10.707 2009.04.17 -
Kaspersky 7.0.0.125 2009.04.19 -
McAfee 5589 2009.04.19 -
McAfee+Artemis 5589 2009.04.19 -
McAfee-GW-Edition 6.7.6 2009.04.19 -
Microsoft 1.4502 2009.04.19 -
NOD32 4019 2009.04.18 -
Norman 6.00.06 2009.04.17 -
nProtect 2009.1.8.0 2009.04.19 -
Panda 10.0.0.14 2009.04.19 -
PCTools 4.4.2.0 2009.04.17 -
Prevx1 V2 2009.04.19 -
Rising 21.25.62.00 2009.04.19 -
Sophos 4.40.0 2009.04.19 -
Sunbelt 3.2.1858.2 2009.04.18 -
Symantec 1.4.4.12 2009.04.19 -
TheHacker 6.3.4.0.309 2009.04.16 -
TrendMicro 8.700.0.1004 2009.04.17 -
VBA32 3.12.10.2 2009.04.12 -
ViRobot 2009.4.18.1685 2009.04.18 -
VirusBuster 4.6.5.0 2009.04.19 -
Information additionnelle
File size: 67904 bytes
MD5...: b87b41f2c05788f04a3b487902803fd2
SHA1..: 54a5aa890e26d9e83abb26c43ff00972a6fd6be6
SHA256: 62e14fb50e815cc5994155108055af72e908fd887070c33f6b2f980951e4673a
SHA512: 0d60d0474cf8b112198f9e436255b2e7fc010f3e18d5d96756b08ee13912991e<BR>b58c44260ffcc14d8eb3b68a8c719b223d2eb4e9fbb91b10b8884efc8cf08594
ssdeep: 1536:vSgONlbwGiXZcCshFZaRKjOOeUeEoRhXjR8:v/1xX68KjXeUey<BR>
PEiD..: -
TrID..: File type identification<BR>Win32 Executable Generic (42.3%)<BR>Win32 Dynamic Link Library (generic) (37.6%)<BR>Generic Win/DOS Executable (9.9%)<BR>DOS Executable Generic (9.9%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x612d<BR>timedatestamp.....: 0x48d2de36 (Thu Sep 18 23:03:18 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x5a12 0x5c00 6.38 c967e99fef55683f19d20ff0d0bbacb3<BR>.rdata 0x7000 0x359a 0x3600 5.23 a37d987e15dacfd22251e7d8b724643a<BR>.data 0xb000 0x5840 0x5400 5.10 24615b081256e7a1f1665c1b1593eedc<BR>.bldvar 0x11000 0x13 0x200 0.33 ce0d85a5378e39e6757076f58752d0b7<BR>.rsrc 0x12000 0x540 0x600 3.83 52ed1c39de138bfcb8d63fceb8083624<BR><BR>( 7 imports ) <BR>> PSAPI.DLL: EnumProcessModules, GetMappedFileNameW, GetModuleInformation<BR>> ADVAPI32.dll: GetTokenInformation, CryptReleaseContext, RegOpenKeyW, CryptAcquireContextW, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, OpenProcessToken, OpenThreadToken, AdjustTokenPrivileges, PrivilegeCheck, LookupPrivilegeValueW, StartServiceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, QueryServiceStatus, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, GetSecurityDescriptorDacl, CopySid, GetLengthSid, SetServiceObjectSecurity, AllocateAndInitializeSid, SetSecurityDescriptorDacl, AddAccessAllowedAceEx, AddAccessDeniedAceEx, InitializeAcl, InitializeSecurityDescriptor<BR>> WINTRUST.dll: WTHelperGetProvCertFromChain, WTHelperProvDataFromStateData, WinVerifyTrust, WTHelperGetProvSignerFromChain<BR>> CRYPT32.dll: CertEnumCertificatesInStore, CertNameToStrW, CertCompareCertificate, CertOpenStore, CertAddSerializedElementToStore<BR>> KERNEL32.dll: GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, FindClose, FindFirstFileW, GetModuleHandleA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetProcAddress, GetVersion, GetLastError, DeviceIoControl, WaitForSingleObject, GetSystemDirectoryW, CloseHandle, CreateThread, CreateEventW, SetEvent, FreeLibrary, LoadLibraryA, GetCurrentProcess, GetCurrentThread, Sleep, CreateFileW, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, GetFileAttributesExW, GetSystemWindowsDirectoryW, EnterCriticalSection, QueryDosDeviceW, GetLogicalDriveStringsW, LoadLibraryW, GetVersionExW, OpenProcess, DeleteCriticalSection, InitializeCriticalSection, GetWindowsDirectoryW, GetEnvironmentVariableW, FileTimeToSystemTime, FileTimeToLocalFileTime, GetModuleFileNameW, InterlockedCompareExchange, InterlockedIncrement, InterlockedDecrement, InterlockedExchange, GetCurrentThreadId, TerminateProcess, QueryPerformanceCounter, DebugBreak<BR>> msvcrt.dll: wcschr, malloc, memset, free, _snwprintf, _purecall, wcsrchr, wcsncpy, printf, memcpy, _wcsnicmp, _wcsdup, _wcsicmp, _unlock, __dllonexit, _lock, _onexit, __wgetmainargs, _exit, _XcptFilter, exit, _initterm, _amsg_exit, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _terminate@@YAXXZ, _controlfp, wcscpy, _errno, _cexit, wcscat<BR>> ntdll.dll: RtlUnwind<BR><BR>( 0 exports ) <BR>
RDS...: NSRL Reference Data Set<BR>-
CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=b87b41f2c05788f04a3b487902803fd2' target='_blank'>http://research.sunbelt-software.com/...