Bonjour gen,
J'ai réussi à réaliser la première opération, c'est à dire le passage des 2 fichiers indiqués par VirusTotal:
C:\Windows\sysnative\DRIVERS\61883.sys
C:\Windows\UA000074.DLL
remarque: 61883.sys n'est pas à l'endroit que tu m'indiques
-> voici le résultat pour 61883.sys :
Fichier 61883.sys reçu le 2009.06.19 16:01:21 (UTC)Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.18 2009.06.19 -
AhnLab-V3 5.0.0.2 2009.06.19 -
AntiVir 7.9.0.193 2009.06.19 -
Antiy-AVL 2.0.3.1 2009.06.19 -
Authentium 5.1.2.4 2009.06.19 -
Avast 4.8.1335.0 2009.06.18 -
AVG 8.5.0.339 2009.06.19 -
BitDefender 7.2 2009.06.19 -
CAT-QuickHeal 10.00 2009.06.19 -
ClamAV 0.94.1 2009.06.19 -
Comodo 1372 2009.06.19 -
DrWeb 5.0.0.12182 2009.06.19 -
eSafe 7.0.17.0 2009.06.18 -
eTrust-Vet 31.6.6569 2009.06.19 -
F-Prot 4.4.4.56 2009.06.19 -
F-Secure 8.0.14470.0 2009.06.19 -
Fortinet 3.117.0.0 2009.06.19 -
GData 19 2009.06.19 -
Ikarus T3.1.1.59.0 2009.06.19 -
Jiangmin 11.0.706 2009.06.19 -
K7AntiVirus 7.10.768 2009.06.19 -
Kaspersky 7.0.0.125 2009.06.19 -
McAfee 5650 2009.06.18 -
McAfee+Artemis 5650 2009.06.18 -
McAfee-GW-Edition 6.7.6 2009.06.19 -
Microsoft 1.4803 2009.06.19 -
NOD32 4172 2009.06.19 -
Norman 6.01.09 2009.06.19 -
nProtect 2009.1.8.0 2009.06.19 -
Panda 10.0.0.16 2009.06.19 -
PCTools 4.4.2.0 2009.06.19 -
Prevx 3.0 2009.06.19 -
Rising 21.34.44.00 2009.06.19 -
Sophos 4.42.0 2009.06.19 -
Sunbelt 3.2.1858.2 2009.06.18 -
Symantec 1.4.4.12 2009.06.19 -
TheHacker 6.3.4.3.348 2009.06.19 -
TrendMicro 8.950.0.1094 2009.06.19 -
VBA32 3.12.10.7 2009.06.19 -
ViRobot 2009.6.19.1796 2009.06.19 -
VirusBuster 4.6.5.0 2009.06.19 -
Information additionnelle
File size: 58496 bytes
MD5...: 78e902fb660bd5003fe726b9bef300b6
SHA1..: c38f0b592bd3e61e257de859678a5cae0c1010fb
SHA256: c43761c5e7544b6026375215dec8313df744a41d15f7b107c34f195730d5d077
ssdeep: 1536:NgVUQOG/Dy25yW4a65555XjaI1dqgnxzCmR/2RG:NgVUQOG/m25j4N5VjaI<BR>XqgxzjuRG<BR>
PEiD..: -
TrID..: File type identification<BR>Win64 Executable Generic (95.5%)<BR>Generic Win/DOS Executable (2.2%)<BR>DOS Executable Generic (2.2%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0xd7cc<BR>timedatestamp.....: 0x479199de (Sat Jan 19 06:34:06 2008)<BR>machinetype.......: 0x8664 (AMD64)<BR><BR>( 9 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x380 0xbf56 0xbf80 6.25 58840f9d50dc78c34b4d1e7879bf4478<BR>.rdata 0xc300 0x8f4 0x900 5.12 07f1c8f88f921faba00b25c743254c7d<BR>.data 0xcc00 0x298 0x300 1.67 daf947dd33eb11311a8d7df8a106df15<BR>.pdata 0xcf00 0x558 0x580 4.39 039111ef79f0396bcb3e5497cf95befc<BR>.guids 0xd480 0x10 0x80 1.04 61bd79003a118bcb238c982d082627d9<BR>PAGE 0xd500 0x1f8 0x200 5.93 2fec73dd5565bc05b5488bbce5905e89<BR>INIT 0xd700 0x870 0x880 5.21 a6ba8a88174886ef5bb63960cd975611<BR>.rsrc 0xdf80 0x3f0 0x400 3.34 32cac7361db46dad08c356bd42acd5e4<BR>.reloc 0xe380 0xf4 0x100 2.40 78564c82530d8d03c2b55aa44e0432ba<BR><BR>( 1 imports ) <BR>> ntoskrnl.exe: ExAllocatePoolWithTag, ZwCreateKey, ExReleaseFastMutex, RtlAnsiStringToUnicodeString, ExAcquireFastMutex, IoFreeWorkItem, ExpInterlockedPushEntrySList, RtlAppendUnicodeToString, RtlInitAnsiString, KeReleaseSpinLock, ExpInterlockedPopEntrySList, MmBuildMdlForNonPagedPool, IoFreeMdl, ZwQueryValueKey, ExFreePool, IoAllocateWorkItem, ZwClose, ExQueryDepthSList, IoFreeIrp, IoAllocateIrp, IoOpenDeviceRegistryKey, IoQueueWorkItem, IoAllocateMdl, KeAcquireSpinLockRaiseToDpc, ExInitializeNPagedLookasideList, KeSetEvent, KeInitializeEvent, IofCompleteRequest, KeWaitForSingleObject, IofCallDriver, IoAcquireRemoveLockEx, IoReuseIrp, KeInitializeDpc, IoReleaseRemoveLockEx, KeInitializeTimer, IoReleaseRemoveLockAndWaitEx, KeSetTimer, IoInitializeRemoveLockEx, KeCancelTimer, ExInterlockedInsertTailList, RtlCopyUnicodeString, IoReleaseCancelSpinLock, ExDeleteNPagedLookasideList, IoRegisterDeviceInterface, RtlIntegerToUnicodeString, IoDeleteDevice, RtlQueryRegistryValues, IoDetachDevice, PoSetPowerState, RtlFreeUnicodeString, PoStartNextPowerIrp, RtlAppendUnicodeStringToString, IoAttachDeviceToDeviceStack, PoCallDriver, ObfReferenceObject, IoCreateDevice, KeBugCheckEx, ProbeForRead, ExAllocatePoolWithQuotaTag, __C_specific_handler<BR><BR>( 0 exports ) <BR>
PDFiD.: -
RDS...: NSRL Reference Data Set<BR>-
-> voici le résultat pour UA000074.DLL:
Fichier UA000074.DLL reçu le 2009.06.19 15:56:09 (UTC)Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.18 2009.06.19 -
AhnLab-V3 5.0.0.2 2009.06.19 -
AntiVir 7.9.0.193 2009.06.19 -
Antiy-AVL 2.0.3.1 2009.06.19 -
Authentium 5.1.2.4 2009.06.19 -
Avast 4.8.1335.0 2009.06.18 -
AVG 8.5.0.339 2009.06.19 -
BitDefender 7.2 2009.06.19 -
CAT-QuickHeal 10.00 2009.06.19 -
ClamAV 0.94.1 2009.06.19 -
Comodo 1372 2009.06.19 -
DrWeb 5.0.0.12182 2009.06.19 -
eSafe 7.0.17.0 2009.06.18 -
eTrust-Vet 31.6.6569 2009.06.19 -
F-Prot 4.4.4.56 2009.06.19 -
F-Secure 8.0.14470.0 2009.06.19 -
Fortinet 3.117.0.0 2009.06.19 -
GData 19 2009.06.19 -
Ikarus T3.1.1.59.0 2009.06.19 -
Jiangmin 11.0.706 2009.06.19 -
K7AntiVirus 7.10.768 2009.06.19 -
Kaspersky 7.0.0.125 2009.06.19 -
McAfee 5650 2009.06.18 -
McAfee+Artemis 5650 2009.06.18 -
McAfee-GW-Edition 6.7.6 2009.06.19 -
Microsoft 1.4803 2009.06.19 -
NOD32 4172 2009.06.19 -
Norman 6.01.09 2009.06.19 -
nProtect 2009.1.8.0 2009.06.19 -
Panda 10.0.0.16 2009.06.19 -
PCTools 4.4.2.0 2009.06.19 -
Prevx 3.0 2009.06.19 -
Rising 21.34.44.00 2009.06.19 -
Sophos 4.42.0 2009.06.19 -
Sunbelt 3.2.1858.2 2009.06.18 -
Symantec 1.4.4.12 2009.06.19 -
TheHacker 6.3.4.3.348 2009.06.19 -
TrendMicro 8.950.0.1094 2009.06.19 -
VBA32 3.12.10.7 2009.06.19 -
ViRobot 2009.6.19.1796 2009.06.19 -
VirusBuster 4.6.5.0 2009.06.19 -
Information additionnelle
File size: 7420 bytes
MD5...: 97165eebf15ad5e886403ee9534ef785
SHA1..: eadbf2e789cd0445260e648926e74adf77652817
SHA256: 5c2e00a48086e6af64a45ce858b1ee88bdb51f47f139fe67eb93a700bb48ae33
ssdeep: 192:QsRjIxVSTAXxtR2s/SqZc146zPwZb4y3ZHJHp:QsR2VBBnNZcWBZb46P<BR>
PEiD..: -
TrID..: File type identification<BR>Unknown!
PEInfo: -
PDFiD.: -
RDS...: NSRL Reference Data Set<BR>-
Je n'arrive pas è réaliser la seconde opération avec OTL 2.1.1.0 que j'ai téléchargé avant hier, car la zone sous Customs Scans/Fixes n'est pas accessible !
Dans l'attente de ton analyse et de tes explications,
Merci beaucoup