Voilà l'analyse, excuse moi pour le temps j'ai du m'absenter merci
Fichier DPTJDMWWHS-390.pms.exe.SVD reçu le 2009.05.30 10:43:11 (UTC)
Situation actuelle: terminé
Résultat: 1/40 (2.50%)
Formaté Formaté
Impression des résultats Impression des résultats
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.05.30 -
AhnLab-V3 5.0.0.2 2009.05.29 -
AntiVir 7.9.0.180 2009.05.29 -
Antiy-AVL 2.0.3.1 2009.05.27 -
Authentium 5.1.2.4 2009.05.29 -
Avast 4.8.1335.0 2009.05.29 -
AVG 8.5.0.339 2009.05.30 -
BitDefender 7.2 2009.05.30 -
CAT-QuickHeal 10.00 2009.05.29 -
ClamAV 0.94.1 2009.05.30 -
Comodo 1203 2009.05.30 -
DrWeb 5.0.0.12182 2009.05.29 MULDROP.Trojan
eSafe 7.0.17.0 2009.05.27 -
eTrust-Vet 31.6.6530 2009.05.30 -
F-Prot 4.4.4.56 2009.05.29 -
F-Secure 8.0.14470.0 2009.05.30 -
Fortinet 3.117.0.0 2009.05.30 -
GData 19 2009.05.30 -
Ikarus T3.1.1.57.0 2009.05.30 -
K7AntiVirus 7.10.749 2009.05.29 -
Kaspersky 7.0.0.125 2009.05.30 -
McAfee 5630 2009.05.29 -
McAfee+Artemis 5630 2009.05.29 -
McAfee-GW-Edition 6.7.6 2009.05.29 -
Microsoft 1.4701 2009.05.30 -
NOD32 4116 2009.05.29 -
Norman 2009.05.29 -
nProtect 2009.1.8.0 2009.05.30 -
Panda 10.0.0.14 2009.05.30 -
PCTools 4.4.2.0 2009.05.29 -
Prevx 3.0 2009.05.30 -
Rising 21.31.21.00 2009.05.27 -
Sophos 4.42.0 2009.05.30 -
Sunbelt 3.2.1858.2 2009.05.30 -
Symantec 1.4.4.12 2009.05.30 -
TheHacker 6.3.4.3.334 2009.05.29 -
TrendMicro 8.950.0.1092 2009.05.29 -
VBA32 3.12.10.6 2009.05.27 -
ViRobot 2009.5.29.1761 2009.05.29 -
VirusBuster 4.6.5.0 2009.05.29 -
Information additionnelle
File size: 250616 bytes
MD5 : 87362a6608127299c3ccccbca7d5a039
SHA1 : 5c307b2b729f4eb29aaca420ffb8129d5e658acd
SHA256: af878c4fa64961341bca75dd7f1adda1b4646ffbd0f333e91e0192eea238ced0
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1B9A7
timedatestamp.....: 0x4A0DC9BB (Fri May 15 21:59:55 2009)
machinetype.......: 0x14C (Intel I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x283A8 0x29000 6.54 5f0f36ea72a8d838c15261c1d8af8f70
.rdata 0x2A000 0xC294 0xD000 5.65 595cd92f0306bf58d14ad6bc9839ee71
.data 0x37000 0x362C 0x2000 2.53 2a8257cdf652864509c6ca64daad075c
.rsrc 0x3B000 0x2838 0x3000 4.49 b051958f9bd41d356bbbb084ba9067f1
( 12 imports )
> advapi32.dll: ReportEventW, RegOpenKeyExW, RegQueryValueExW, RegQueryInfoKeyW, RegSetValueExW, RegCreateKeyExW, LookupPrivilegeValueW, ConvertSidToStringSidW, DeleteService, ControlService, RegisterServiceCtrlHandlerW, SetServiceStatus, StartServiceCtrlDispatcherW, DeregisterEventSource, RegisterEventSourceW, CloseServiceHandle, ChangeServiceConfig2W, OpenServiceW, CreateServiceW, OpenSCManagerW, CreateProcessAsUserW, GetTokenInformation, DuplicateTokenEx, SetTokenInformation, OpenProcessToken, AdjustTokenPrivileges, GetSecurityDescriptorSacl, GetSecurityDescriptorDacl, GetSecurityDescriptorGroup, GetSecurityDescriptorOwner, GetSecurityDescriptorControl, LookupAccountSidW, CopySid, InitializeSid, GetSidLengthRequired, GetSidSubAuthority, IsValidSid, GetLengthSid, RegEnumKeyExW, RegDeleteKeyW, RegDeleteValueW, RegCloseKey
> crypt32.dll: CertNameToStrA, CryptMsgGetAndVerifySigner, CryptQueryObject, CertFreeCertificateContext, CryptMsgClose
> kernel32.dll: WTSGetActiveConsoleSessionId, CreateToolhelp32Snapshot, Process32FirstW, ProcessIdToSessionId, Process32NextW, OpenProcess, SetErrorMode, GetCommandLineW, Sleep, lstrcatW, LocalFree, LoadLibraryA, lstrlenA, GetCurrentProcessId, GetCurrentDirectoryW, DuplicateHandle, GetFullPathNameW, SetEndOfFile, GetLocaleInfoW, CreateFileW, FlushFileBuffers, SetStdHandle, GetOEMCP, IsBadCodePtr, IsBadReadPtr, IsValidCodePage, IsValidLocale, EnumSystemLocalesA, GetUserDefaultLCID, CreateProcessW, GetSystemTimeAsFileTime, QueryPerformanceCounter, TerminateProcess, SetLastError, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, GetModuleFileNameW, RaiseException, GetModuleHandleW, lstrcpyW, LoadLibraryExW, MultiByteToWideChar, lstrcpynW, lstrcmpiW, FindResourceExW, LoadResource, LockResource, SizeofResource, FindResourceW, GetModuleFileNameA, VirtualFreeEx, FreeLibrary, ResumeThread, CreateRemoteThread, CreateEventA, GetTickCount, GetProcAddress, FlushInstructionCache, WriteProcessMemory, VirtualProtectEx, VirtualAllocEx, LoadLibraryW, GetCurrentProcess, lstrlenW, WideCharToMultiByte, OutputDebugStringW, InterlockedExchange, CreateThread, SetEvent, LeaveCriticalSection, EnterCriticalSection, CreateEventW, DeleteCriticalSection, InitializeCriticalSection, GetVersionExW, GetExitCodeProcess, WaitForSingleObject, SetFilePointer, ReadFile, SetUnhandledExceptionFilter, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetStdHandle, WriteFile, TlsGetValue, TlsSetValue, TlsFree, TlsAlloc, IsBadWritePtr, VirtualFree, HeapCreate, GetStringTypeW, GetStringTypeA, GetCPInfo, LCMapStringW, LCMapStringA, ExitProcess, RtlUnwind, GetCommandLineA, GetStartupInfoA, GetModuleHandleA, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, CloseHandle, GetLastError, GetThreadLocale, GetLocaleInfoA, GetACP, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA
> ole32.dll: CoTaskMemRealloc, CoTaskMemAlloc, CoInitializeSecurity, CoResumeClassObjects, StringFromCLSID, StringFromGUID2, CoSuspendClassObjects, CoCreateInstance, CoTaskMemFree, CoUninitialize, CoRevokeClassObject, CoInitializeEx, CoRegisterClassObject
> oleaut32.dll: -, -, -, -, -, -, -, -, -, -, -
> psapi.dll: GetModuleFileNameExW
> shell32.dll: SHGetFolderPathW
> shlwapi.dll: PathUnquoteSpacesW, PathFindExtensionW, PathAppendW, PathFileExistsW, PathFileExistsA
> user32.dll: CharNextW, MessageBoxW, GetProcessWindowStation, GetThreadDesktop, DispatchMessageW, EnumWindowStationsW, OpenWindowStationW, SetProcessWindowStation, EnumDesktopsW, CloseWindowStation, OpenDesktopW, SetThreadDesktop, EnumDesktopWindows, GetWindowThreadProcessId, CharUpperW, wsprintfW, LoadStringW, PostThreadMessageW, GetMessageW, TranslateMessage
> userenv.dll: LoadUserProfileW, CreateEnvironmentBlock, UnloadUserProfile, DestroyEnvironmentBlock
> wintrust.dll: WinVerifyTrust
> wtsapi32.dll: WTSQueryUserToken
( 0 exports )
TrID : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ssdeep: 3072:9dC8DfIFYQ3cziISOljRy/WZuwcOUTSwx0UtUT/iExEPjbQl5XCnMdYlg5v4:m1+TzyUePSYU1x63WSMdlS
PEiD : -
RDS : NSRL Reference Data Set
-
ATENTION ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares