Oui, c'est bien ça, nous sommes dans l'ouest il pleuvait des cordes,
voici le rapport Virus total:
Fichier agent.exe reçu le 2009.05.26 05:44:17 (UTC)Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.05.26 -
AhnLab-V3 5.0.0.2 2009.05.26 -
AntiVir 7.9.0.168 2009.05.25 -
Antiy-AVL 2.0.3.1 2009.05.25 -
Authentium 5.1.2.4 2009.05.25 -
Avast 4.8.1335.0 2009.05.25 -
AVG 8.5.0.339 2009.05.25 -
BitDefender 7.2 2009.05.26 -
CAT-QuickHeal 10.00 2009.05.26 -
ClamAV 0.94.1 2009.05.26 -
Comodo 1199 2009.05.25 -
DrWeb 5.0.0.12182 2009.05.26 -
eSafe 7.0.17.0 2009.05.24 -
eTrust-Vet 31.6.6521 2009.05.25 -
F-Prot 4.4.4.56 2009.05.25 -
F-Secure 8.0.14470.0 2009.05.26 -
Fortinet 3.117.0.0 2009.05.26 -
GData 19 2009.05.26 -
Ikarus T3.1.1.49.0 2009.05.26 -
K7AntiVirus 7.10.744 2009.05.25 -
Kaspersky 7.0.0.125 2009.05.26 -
McAfee 5626 2009.05.25 -
McAfee+Artemis 5626 2009.05.25 -
McAfee-GW-Edition 6.7.6 2009.05.25 -
Microsoft 1.4701 2009.05.25 -
NOD32 4103 2009.05.25 -
Norman 6.01.05 2009.05.25 -
nProtect 2009.1.8.0 2009.05.26 -
Panda 10.0.0.14 2009.05.25 -
PCTools 4.4.2.0 2009.05.21 -
Prevx 3.0 2009.05.26 -
Rising 21.31.10.00 2009.05.26 -
Sophos 4.42.0 2009.05.26 -
Sunbelt 3.2.1858.2 2009.05.25 -
Symantec 1.4.4.12 2009.05.26 -
TheHacker 6.3.4.3.331 2009.05.25 -
TrendMicro 8.950.0.1092 2009.05.26 -
VBA32 3.12.10.6 2009.05.26 -
ViRobot 2009.5.26.1752 2009.05.26 -
VirusBuster 4.6.5.0 2009.05.25 -
Information additionnelle
File size: 512000 bytes
MD5...: 2dcb5abe60984701af96a76b6749148a
SHA1..: be3b7d6f275c5ac14031d44d5b627342e684fa3d
SHA256: f7a192ab4b56d427750e5bfb00a583eb666919468879fced7ab51b013ec8e3a2
ssdeep: 6144:9jvVS1CjPQKGK+t3i+4/6/1d4W+SduDTXW0F1hRiFqbTodWWwvcEb:JtBXG<BR>V3i+4/842YHWCT<BR>
PEiD..: Armadillo v1.71
TrID..: File type identification<BR>Win32 Executable MS Visual C++ (generic) (65.2%)<BR>Win32 Executable Generic (14.7%)<BR>Win32 Dynamic Link Library (generic) (13.1%)<BR>Generic Win/DOS Executable (3.4%)<BR>DOS Executable Generic (3.4%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x3ea23<BR>timedatestamp.....: 0x411759fd (Mon Aug 09 11:03:25 2004)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x4dc69 0x4e000 6.52 5c01ee3b8cd97d829f7cf5a01988a34d<BR>.rdata 0x4f000 0xf020 0x10000 4.15 f1568c4d0b22cdefb46f5eac4bf06afc<BR>.data 0x5f000 0x8708 0x7000 3.94 8cf1b094deac3317b8abfabb861f6266<BR>.rsrc 0x68000 0x16ef8 0x17000 5.22 322878dc55572240ce688b5cec9c27ff<BR><BR>( 8 imports ) <BR>> KERNEL32.dll: GetModuleHandleA, GetModuleFileNameA, lstrcmpiA, InterlockedDecrement, Sleep, SetUnhandledExceptionFilter, CreateProcessA, GetCommandLineA, FreeLibrary, SizeofResource, LoadLibraryExA, lstrcpynA, IsDBCSLeadByte, InitializeCriticalSection, HeapDestroy, DeleteCriticalSection, GetProcAddress, lstrcatA, FindFirstFileA, GetFileAttributesA, FindClose, FindNextFileA, GetWindowsDirectoryA, GetSystemDirectoryA, GetPrivateProfileStringA, WritePrivateProfileStringA, CreateDirectoryA, CopyFileA, LocalAlloc, WritePrivateProfileSectionA, GetPrivateProfileSectionNamesA, RemoveDirectoryA, DeleteFileA, GetTempPathA, ResetEvent, CreateFileA, OutputDebugStringA, GetLocalTime, QueryPerformanceFrequency, WriteFile, GetTempFileNameA, FileTimeToSystemTime, FileTimeToLocalFileTime, GetShortPathNameA, SetEnvironmentVariableA, SetEndOfFile, GetOEMCP, GetACP, GlobalFree, GetCPInfo, GetStringTypeW, GetStringTypeA, FlushFileBuffers, SetStdHandle, SetFilePointer, IsBadCodePtr, IsBadReadPtr, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, IsBadWritePtr, VirtualAlloc, VirtualFree, HeapCreate, GetEnvironmentVariableA, LCMapStringW, LCMapStringA, HeapSize, TerminateProcess, TlsGetValue, TlsAlloc, TlsSetValue, ExitProcess, GetVersion, GetStartupInfoA, GetSystemTime, GetTimeZoneInformation, HeapReAlloc, HeapAlloc, HeapFree, RaiseException, RtlUnwind, SystemTimeToFileTime, QueryPerformanceCounter, CreateFileMappingA, MapViewOfFile, UnmapViewOfFile, GetFileSize, ReadFile, SearchPathA, VirtualProtect, VirtualQuery, InterlockedExchange, GlobalAlloc, GlobalUnlock, InterlockedIncrement, GetCurrentProcess, FlushInstructionCache, GetUserDefaultLangID, FormatMessageA, LocalFree, LoadLibraryA, MultiByteToWideChar, FindResourceExA, FindResourceA, LoadResource, LockResource, GlobalLock, OpenEventA, lstrcmpA, CreateThread, SetEvent, WaitForSingleObject, CloseHandle, CreateEventA, lstrcpyA, EnterCriticalSection, LeaveCriticalSection, lstrlenW, GetTickCount, GetCurrentThreadId, GetVersionExA, CompareStringW, CompareStringA, WideCharToMultiByte, GetLastError, SetLastError, lstrlenA<BR>> USER32.dll: SendDlgItemMessageA, GetWindowLongA, GetSysColor, DialogBoxParamA, EndDialog, GetActiveWindow, LoadCursorA, GetDesktopWindow, MessageBoxA, LoadStringA, CharLowerBuffA, wsprintfA, GetDlgItem, PtInRect, CharLowerA, GetPropA, IsDialogMessageA, KillTimer, IsDlgButtonChecked, GetWindowRect, ClientToScreen, SetCursor, UpdateWindow, InvalidateRect, SetPropA, RemovePropA, EnableMenuItem, SetWindowRgn, ExitWindowsEx, SetWindowTextA, CallWindowProcA, DefWindowProcA, GetClassInfoExA, RegisterClassExA, PostMessageA, DestroyCursor, CreateWindowExA, GetMessageA, CharNextA, PostThreadMessageA, GetDC, ReleaseDC, CreateDialogIndirectParamA, CreateDialogParamA, GetDlgCtrlID, SetWindowLongA, GetSysColorBrush, DialogBoxIndirectParamA, PeekMessageA, MsgWaitForMultipleObjects, TranslateMessage, DispatchMessageA, DestroyWindow, GetParent, GetWindow, SystemParametersInfoA, GetClientRect, MapWindowPoints, SetWindowPos, EnableWindow, SetDlgItemTextA, LoadImageA, SendMessageA, GetSystemMenu, AppendMenuA, ShowWindow, SetForegroundWindow, BeginPaint, IsWindow, EndPaint, FillRect, ScreenToClient<BR>> GDI32.dll: BitBlt, CreateCompatibleBitmap, GetDeviceCaps, SaveDC, SelectObject, SetBkMode, TextOutA, RestoreDC, GetObjectA, SetTextColor, SetBkColor, CreateSolidBrush, DeleteObject, CreateBitmap, CreateCompatibleDC, GetStockObject, CreateRectRgn, CreateFontIndirectA, DeleteDC<BR>> ADVAPI32.dll: RegEnumValueA, RegQueryInfoKeyA, RegDeleteValueA, RegEnumKeyExA, RegDeleteKeyA, RegCreateKeyExA, RegSetValueExA, RegOpenKeyA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, RegEnumKeyA, RegQueryValueA<BR>> SHELL32.dll: ShellExecuteA<BR>> ole32.dll: CoLoadLibrary, CLSIDFromString, StgOpenStorage, CoRevokeClassObject, CoRegisterClassObject, CoTaskMemRealloc, StringFromCLSID, CoCreateGuid, StringFromGUID2, CoCreateInstance, CLSIDFromProgID, CoFreeUnusedLibraries, CoInitialize, CoUninitialize, ProgIDFromCLSID, CoTaskMemFree, CoTaskMemAlloc<BR>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA<BR><BR>( 0 exports ) <BR>
PDFiD.: -
RDS...: NSRL Reference Data Set<BR><BR>( ScanSoft Inc. )<BR><BR>> Dragon Naturally Speaking 8: agent.exe.C3A146F5_4B48_11D5_A819_00B0D0428C0C<BR><BR>
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.05.26 -
AhnLab-V3 5.0.0.2 2009.05.26 -
AntiVir 7.9.0.168 2009.05.25 -
Antiy-AVL 2.0.3.1 2009.05.25 -
Authentium 5.1.2.4 2009.05.25 -
Avast 4.8.1335.0 2009.05.25 -
AVG 8.5.0.339 2009.05.25 -
BitDefender 7.2 2009.05.26 -
CAT-QuickHeal 10.00 2009.05.26 -
ClamAV 0.94.1 2009.05.26 -
Comodo 1199 2009.05.25 -
DrWeb 5.0.0.12182 2009.05.26 -
eSafe 7.0.17.0 2009.05.24 -
eTrust-Vet 31.6.6521 2009.05.25 -
F-Prot 4.4.4.56 2009.05.25 -
F-Secure 8.0.14470.0 2009.05.26 -
Fortinet 3.117.0.0 2009.05.26 -
GData 19 2009.05.26 -
Ikarus T3.1.1.49.0 2009.05.26 -
K7AntiVirus 7.10.744 2009.05.25 -
Kaspersky 7.0.0.125 2009.05.26 -
McAfee 5626 2009.05.25 -
McAfee+Artemis 5626 2009.05.25 -
McAfee-GW-Edition 6.7.6 2009.05.25 -
Microsoft 1.4701 2009.05.25 -
NOD32 4103 2009.05.25 -
Norman 6.01.05 2009.05.25 -
nProtect 2009.1.8.0 2009.05.26 -
Panda 10.0.0.14 2009.05.25 -
PCTools 4.4.2.0 2009.05.21 -
Prevx 3.0 2009.05.26 -
Rising 21.31.10.00 2009.05.26 -
Sophos 4.42.0 2009.05.26 -
Sunbelt 3.2.1858.2 2009.05.25 -
Symantec 1.4.4.12 2009.05.26 -
TheHacker 6.3.4.3.331 2009.05.25 -
TrendMicro 8.950.0.1092 2009.05.26 -
VBA32 3.12.10.6 2009.05.26 -
ViRobot 2009.5.26.1752 2009.05.26 -
VirusBuster 4.6.5.0 2009.05.25 -
Information additionnelle
File size: 512000 bytes
MD5...: 2dcb5abe60984701af96a76b6749148a
SHA1..: be3b7d6f275c5ac14031d44d5b627342e684fa3d
SHA256: f7a192ab4b56d427750e5bfb00a583eb666919468879fced7ab51b013ec8e3a2
ssdeep: 6144:9jvVS1CjPQKGK+t3i+4/6/1d4W+SduDTXW0F1hRiFqbTodWWwvcEb:JtBXG<BR>V3i+4/842YHWCT<BR>
PEiD..: Armadillo v1.71
TrID..: File type identification<BR>Win32 Executable MS Visual C++ (generic) (65.2%)<BR>Win32 Executable Generic (14.7%)<BR>Win32 Dynamic Link Library (generic) (13.1%)<BR>Generic Win/DOS Executable (3.4%)<BR>DOS Executable Generic (3.4%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x3ea23<BR>timedatestamp.....: 0x411759fd (Mon Aug 09 11:03:25 2004)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x4dc69 0x4e000 6.52 5c01ee3b8cd97d829f7cf5a01988a34d<BR>.rdata 0x4f000 0xf020 0x10000 4.15 f1568c4d0b22cdefb46f5eac4bf06afc<BR>.data 0x5f000 0x8708 0x7000 3.94 8cf1b094deac3317b8abfabb861f6266<BR>.rsrc 0x68000 0x16ef8 0x17000 5.22 322878dc55572240ce688b5cec9c27ff<BR><BR>( 8 imports ) <BR>> KERNEL32.dll: GetModuleHandleA, GetModuleFileNameA, lstrcmpiA, InterlockedDecrement, Sleep, SetUnhandledExceptionFilter, CreateProcessA, GetCommandLineA, FreeLibrary, SizeofResource, LoadLibraryExA, lstrcpynA, IsDBCSLeadByte, InitializeCriticalSection, HeapDestroy, DeleteCriticalSection, GetProcAddress, lstrcatA, FindFirstFileA, GetFileAttributesA, FindClose, FindNextFileA, GetWindowsDirectoryA, GetSystemDirectoryA, GetPrivateProfileStringA, WritePrivateProfileStringA, CreateDirectoryA, CopyFileA, LocalAlloc, WritePrivateProfileSectionA, GetPrivateProfileSectionNamesA, RemoveDirectoryA, DeleteFileA, GetTempPathA, ResetEvent, CreateFileA, OutputDebugStringA, GetLocalTime, QueryPerformanceFrequency, WriteFile, GetTempFileNameA, FileTimeToSystemTime, FileTimeToLocalFileTime, GetShortPathNameA, SetEnvironmentVariableA, SetEndOfFile, GetOEMCP, GetACP, GlobalFree, GetCPInfo, GetStringTypeW, GetStringTypeA, FlushFileBuffers, SetStdHandle, SetFilePointer, IsBadCodePtr, IsBadReadPtr, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, IsBadWritePtr, VirtualAlloc, VirtualFree, HeapCreate, GetEnvironmentVariableA, LCMapStringW, LCMapStringA, HeapSize, TerminateProcess, TlsGetValue, TlsAlloc, TlsSetValue, ExitProcess, GetVersion, GetStartupInfoA, GetSystemTime, GetTimeZoneInformation, HeapReAlloc, HeapAlloc, HeapFree, RaiseException, RtlUnwind, SystemTimeToFileTime, QueryPerformanceCounter, CreateFileMappingA, MapViewOfFile, UnmapViewOfFile, GetFileSize, ReadFile, SearchPathA, VirtualProtect, VirtualQuery, InterlockedExchange, GlobalAlloc, GlobalUnlock, InterlockedIncrement, GetCurrentProcess, FlushInstructionCache, GetUserDefaultLangID, FormatMessageA, LocalFree, LoadLibraryA, MultiByteToWideChar, FindResourceExA, FindResourceA, LoadResource, LockResource, GlobalLock, OpenEventA, lstrcmpA, CreateThread, SetEvent, WaitForSingleObject, CloseHandle, CreateEventA, lstrcpyA, EnterCriticalSection, LeaveCriticalSection, lstrlenW, GetTickCount, GetCurrentThreadId, GetVersionExA, CompareStringW, CompareStringA, WideCharToMultiByte, GetLastError, SetLastError, lstrlenA<BR>> USER32.dll: SendDlgItemMessageA, GetWindowLongA, GetSysColor, DialogBoxParamA, EndDialog, GetActiveWindow, LoadCursorA, GetDesktopWindow, MessageBoxA, LoadStringA, CharLowerBuffA, wsprintfA, GetDlgItem, PtInRect, CharLowerA, GetPropA, IsDialogMessageA, KillTimer, IsDlgButtonChecked, GetWindowRect, ClientToScreen, SetCursor, UpdateWindow, InvalidateRect, SetPropA, RemovePropA, EnableMenuItem, SetWindowRgn, ExitWindowsEx, SetWindowTextA, CallWindowProcA, DefWindowProcA, GetClassInfoExA, RegisterClassExA, PostMessageA, DestroyCursor, CreateWindowExA, GetMessageA, CharNextA, PostThreadMessageA, GetDC, ReleaseDC, CreateDialogIndirectParamA, CreateDialogParamA, GetDlgCtrlID, SetWindowLongA, GetSysColorBrush, DialogBoxIndirectParamA, PeekMessageA, MsgWaitForMultipleObjects, TranslateMessage, DispatchMessageA, DestroyWindow, GetParent, GetWindow, SystemParametersInfoA, GetClientRect, MapWindowPoints, SetWindowPos, EnableWindow, SetDlgItemTextA, LoadImageA, SendMessageA, GetSystemMenu, AppendMenuA, ShowWindow, SetForegroundWindow, BeginPaint, IsWindow, EndPaint, FillRect, ScreenToClient<BR>> GDI32.dll: BitBlt, CreateCompatibleBitmap, GetDeviceCaps, SaveDC, SelectObject, SetBkMode, TextOutA, RestoreDC, GetObjectA, SetTextColor, SetBkColor, CreateSolidBrush, DeleteObject, CreateBitmap, CreateCompatibleDC, GetStockObject, CreateRectRgn, CreateFontIndirectA, DeleteDC<BR>> ADVAPI32.dll: RegEnumValueA, RegQueryInfoKeyA, RegDeleteValueA, RegEnumKeyExA, RegDeleteKeyA, RegCreateKeyExA, RegSetValueExA, RegOpenKeyA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, RegEnumKeyA, RegQueryValueA<BR>> SHELL32.dll: ShellExecuteA<BR>> ole32.dll: CoLoadLibrary, CLSIDFromString, StgOpenStorage, CoRevokeClassObject, CoRegisterClassObject, CoTaskMemRealloc, StringFromCLSID, CoCreateGuid, StringFromGUID2, CoCreateInstance, CLSIDFromProgID, CoFreeUnusedLibraries, CoInitialize, CoUninitialize, ProgIDFromCLSID, CoTaskMemFree, CoTaskMemAlloc<BR>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA<BR><BR>( 0 exports ) <BR>
PDFiD.: -
RDS...: NSRL Reference Data Set<BR><BR>( ScanSoft Inc. )<BR><BR>> Dragon Naturally Speaking 8: agent.exe.C3A146F5_4B48_11D5_A819_00B0D0428C0C<BR><BR>