Oui je te les poste !!! Mais me suis dit, si c'est pas ça, sert à rien de polluer !! :)
donc
C:\Windows\system32\DRIVERS\rimmptsk.sys
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.24 2009.08.28 -
AhnLab-V3 5.0.0.2 2009.08.27 -
AntiVir 7.9.1.7 2009.08.28 -
Antiy-AVL 2.0.3.7 2009.08.24 -
Authentium 5.1.2.4 2009.08.28 -
Avast 4.8.1335.0 2009.08.27 -
AVG 8.5.0.406 2009.08.28 -
BitDefender 7.2 2009.08.28 -
CAT-QuickHeal 10.00 2009.08.28 -
ClamAV 0.94.1 2009.08.28 -
Comodo 2125 2009.08.28 -
DrWeb 5.0.0.12182 2009.08.28 -
eSafe 7.0.17.0 2009.08.27 -
eTrust-Vet 31.6.6706 2009.08.28 -
F-Prot 4.5.1.85 2009.08.27 -
F-Secure 8.0.14470.0 2009.08.28 -
Fortinet 3.120.0.0 2009.08.28 -
GData 19 2009.08.28 -
Ikarus T3.1.1.68.0 2009.08.28 -
Jiangmin 11.0.800 2009.08.28 -
K7AntiVirus 7.10.829 2009.08.27 -
Kaspersky 7.0.0.125 2009.08.28 -
McAfee 5722 2009.08.27 -
McAfee+Artemis 5722 2009.08.27 -
McAfee-GW-Edition 6.8.5 2009.08.28 -
Microsoft 1.5005 2009.08.28 -
NOD32 4376 2009.08.28 -
Norman 2009.08.27 -
nProtect 2009.1.8.0 2009.08.28 -
Panda 10.0.2.2 2009.08.28 -
PCTools 4.4.2.0 2009.08.27 -
Prevx 3.0 2009.08.28 -
Rising 21.44.40.00 2009.08.28 -
Sophos 4.45.0 2009.08.28 -
Sunbelt 3.2.1858.2 2009.08.27 -
Symantec 1.4.4.12 2009.08.28 -
TheHacker 6.3.4.3.389 2009.08.27 -
TrendMicro 8.950.0.1094 2009.08.28 -
VBA32 3.12.10.10 2009.08.28 -
ViRobot 2009.8.28.1907 2009.08.28 -
VirusBuster 4.6.5.0 2009.08.28 -
Information additionnelle
File size: 32256 bytes
MD5...: d85e3fa9f5b1f29bb4ed185c450d1470
SHA1..: bb9d79031b84e3828dc0d24cbd9264eec1e9ac30
SHA256: 5dcb3df594e907b058ccf3eda07eb019d9e1835177b6cdaea2ede9003699809e
ssdeep: 768:sKNy1O0kXcf7KYNahYSY/64oT1COB4H22wHaxY:s/1pzKYAhYnoCmafw6xY
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xb075
timedatestamp.....: 0x455accd7 (Wed Nov 15 08:16:23 2006)
machinetype.......: 0x14c (I386)
( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6172 0x6200 6.19 0664bbb9e15c093ae6be16e60118f702
.rdata 0x8000 0x1d8 0x200 4.84 b333ccbc0d635ab0b8ca5bc3e1ce424f
.data 0x9000 0x94 0x200 0.51 63af74aa04e44312314ff1e10d1c54db
PAGE 0xa000 0x42 0x200 1.03 4859c6f59332b48303fe3579aeec8d59
INIT 0xb000 0x668 0x800 4.91 e6e27c884db7c4b5250bf50dd8aa4b31
.rsrc 0xc000 0x428 0x600 2.48 4a12843d6a901e1cf5f118f070902c6e
.reloc 0xd000 0x3a2 0x400 4.13 2232a76cb6e67722aab58fc17a2b58b0
( 2 imports )
> ntoskrnl.exe: KeSetEvent, MmUnmapIoSpace, IoSetDeviceInterfaceState, ZwSetValueKey, ZwClose, ZwCreateKey, RtlInitUnicodeString, IoDeleteDevice, IoDetachDevice, KeWaitForSingleObject, KeInitializeEvent, READ_REGISTER_BUFFER_UCHAR, MmMapIoSpace, IoReleaseRemoveLockEx, ExAllocatePoolWithTag, IoInvalidateDeviceRelations, swprintf, IoAcquireRemoveLockEx, PoSetPowerState, PoCallDriver, PoStartNextPowerIrp, PoRequestPowerIrp, IofCallDriver, IoRegisterDeviceInterface, IoInitializeRemoveLockEx, IoCreateDevice, READ_REGISTER_BUFFER_ULONG, KeDelayExecutionThread, KeClearEvent, KeSetTimer, ObfDereferenceObject, ObReferenceObjectByHandle, MmMapLockedPagesSpecifyCache, PsTerminateSystemThread, PsCreateSystemThread, IoDisconnectInterrupt, KeInsertQueueDpc, IoConnectInterrupt, KeInitializeDpc, KeInitializeTimer, KeTickCount, KeBugCheckEx, ObfReferenceObject, memcpy, memset, ExAllocatePool, RtlQueryRegistryValues, ExFreePoolWithTag, IoAttachDeviceToDeviceStack, IofCompleteRequest
> HAL.dll: KeGetCurrentIrql, KfAcquireSpinLock, KfReleaseSpinLock, ExReleaseFastMutex, ExAcquireFastMutex
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win64 Executable Generic (95.5%)
Generic Win/DOS Executable (2.2%)
DOS Executable Generic (2.2%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
C:\Windows\system32\DRIVERS\rimsptsk.sys
a-squared 4.5.0.24 2009.08.28 -
AhnLab-V3 5.0.0.2 2009.08.27 -
AntiVir 7.9.1.7 2009.08.28 -
Antiy-AVL 2.0.3.7 2009.08.24 -
Authentium 5.1.2.4 2009.08.28 -
Avast 4.8.1335.0 2009.08.27 -
AVG 8.5.0.406 2009.08.28 -
BitDefender 7.2 2009.08.28 -
CAT-QuickHeal 10.00 2009.08.28 -
ClamAV 0.94.1 2009.08.28 -
Comodo 2124 2009.08.28 -
DrWeb 5.0.0.12182 2009.08.28 -
eSafe 7.0.17.0 2009.08.27 -
eTrust-Vet 31.6.6706 2009.08.28 -
F-Prot 4.5.1.85 2009.08.27 -
F-Secure 8.0.14470.0 2009.08.28 -
Fortinet 3.120.0.0 2009.08.28 -
GData 19 2009.08.28 -
Ikarus T3.1.1.68.0 2009.08.28 -
Jiangmin 11.0.800 2009.08.28 -
K7AntiVirus 7.10.829 2009.08.27 -
Kaspersky 7.0.0.125 2009.08.28 -
McAfee 5722 2009.08.27 -
McAfee+Artemis 5722 2009.08.27 -
McAfee-GW-Edition 6.8.5 2009.08.28 -
Microsoft 1.5005 2009.08.28 -
NOD32 4376 2009.08.28 -
Norman 2009.08.27 -
nProtect 2009.1.8.0 2009.08.28 -
Panda 10.0.2.2 2009.08.28 -
PCTools 4.4.2.0 2009.08.27 -
Prevx 3.0 2009.08.28 -
Rising 21.44.40.00 2009.08.28 -
Sophos 4.45.0 2009.08.28 -
Sunbelt 3.2.1858.2 2009.08.27 -
Symantec 1.4.4.12 2009.08.28 -
TheHacker 6.3.4.3.389 2009.08.27 -
TrendMicro 8.950.0.1094 2009.08.28 -
VBA32 3.12.10.10 2009.08.28 -
ViRobot 2009.8.28.1907 2009.08.28 -
VirusBuster 4.6.5.0 2009.08.28 -
Information additionnelle
File size: 43520 bytes
MD5...: db8eb01c58c9fada00c70b1775278ae0
SHA1..: 258ede9df9bc792f16d6962543c7faf91a34bd59
SHA256: 35f0f3f15211d0f0b3ec85832c7e307ed7fda6a2c9b463740ea0d7a49bc64926
ssdeep: 768:Nt5Q9sM3B+W8gIvX1R1AnzWzAgbGSWqlmEheH0:lQ9sMR+vgEXBACzAciql3
e
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x11075
timedatestamp.....: 0x455a8cb5 (Wed Nov 15 03:42:45 2006)
machinetype.......: 0x14c (I386)
( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x895b 0x8a00 6.35 b633949163e1f8f1df59929d44146ac7
.rdata 0xa000 0x260 0x400 3.47 4d13e0c8dcf074f953573c6d43d70424
.data 0xb000 0x40bc 0x200 0.64 b72db85d2803d5b046b78325b8161ade
PAGE 0x10000 0x42 0x200 1.03 8348cfd4778e19133d98f58d0f90dd29
INIT 0x11000 0x70a 0x800 5.33 2ab53d69dc2bece78c9814b5d2536233
.rsrc 0x12000 0x440 0x600 2.55 a16ddfc6c1a8283f4490c24209188e84
.reloc 0x13000 0x4d8 0x600 4.46 09cab1831eba4608e93bb3759b9bb18c
( 2 imports )
> ntoskrnl.exe: ObfReferenceObject, IofCallDriver, KeSetEvent, MmUnmapIoSpace, IoSetDeviceInterfaceState, ZwClose, ZwSetValueKey, ZwCreateKey, ZwQueryValueKey, ZwOpenKey, RtlInitUnicodeString, IoDeleteDevice, IoDetachDevice, KeWaitForSingleObject, KeInitializeEvent, MmMapIoSpace, IoReleaseRemoveLockEx, IoInvalidateDeviceRelations, swprintf, IoAcquireRemoveLockEx, KeClearEvent, PoSetPowerState, PoCallDriver, PoStartNextPowerIrp, PoRequestPowerIrp, memcpy, IoRegisterDeviceInterface, IoInitializeRemoveLockEx, IoCreateDevice, IoFreeIrp, IoAllocateIrp, KeDelayExecutionThread, MmGetPhysicalAddress, READ_REGISTER_BUFFER_ULONG, KeSetTimer, ObfDereferenceObject, ObReferenceObjectByHandle, PsTerminateSystemThread, PsCreateSystemThread, IoDisconnectInterrupt, KeInsertQueueDpc, MmMapLockedPagesSpecifyCache, IoConnectInterrupt, KeInitializeDpc, KeInitializeTimer, KeReleaseInterruptSpinLock, KeAcquireInterruptSpinLock, IoCreateNotificationEvent, KeTickCount, KeBugCheckEx, RtlUnwind, memset, ExAllocatePoolWithTag, RtlQueryRegistryValues, ExFreePoolWithTag, IoAttachDeviceToDeviceStack, IofCompleteRequest
> HAL.dll: KfReleaseSpinLock, KeGetCurrentIrql, ExReleaseFastMutex, ExAcquireFastMutex, KfAcquireSpinLock
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)