Je crois peut être avoir trouvé ce qui cloche en analysant : viradd virsiz rawdsiz ntrpy md5
je te post le rapport total mais j'ai vu ça qui me semble louche dedans .
Information additionnelle
File size: 390408 bytes
MD5...: b80c114f2c0a93063e450992e841f770
SHA1..: 8b16b32c178fd5e9dd884ae212ad05bd51a057ce
SHA256: 4f9f3187a392e5e2f3f637a4d9aa87cea8bf2f4975bbb878bab59ce68a2fc424
ssdeep: 6144:QKA0eI3LencpU3NAWwTdFVZwSlrqu6ohVV3MBXMha:pAvAWCzju0hIpT
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1a75d
timedatestamp.....: 0x471cd069 (Mon Oct 22 16:31:37 2007)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2fb84 0x30000 6.60 93727b8c36f44fb6579d23a764a086c8
.rdata 0x31000 0xa09c 0xb000 4.71 bbb59289b51debdc45fb887f6539427d
.data 0x3c000 0x645c 0x3000 2.96 71c84ebfbc252882ec905d9ac2507cdf
.rsrc 0x43000 0x1e624 0x1f000 2.90 4ab9e0082e4f1c91d5b63bc55fae4b2e
( 9 imports )
> KERNEL32.dll: GetFileAttributesA, GetFileTime, RtlUnwind, HeapFree, VirtualAlloc, HeapAlloc, HeapReAlloc, GetCommandLineA, GetProcessHeap, GetStartupInfoA, RaiseException, ExitProcess, HeapSize, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetACP, LCMapStringA, LCMapStringW, Sleep, SetHandleCount, GetStdHandle, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, GetStringTypeA, GetStringTypeW, HeapDestroy, HeapCreate, VirtualFree, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, GetTimeZoneInformation, GetConsoleCP, GetConsoleMode, SetStdHandle, GetLocaleInfoW, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEnvironmentVariableA, FileTimeToLocalFileTime, SetErrorMode, WritePrivateProfileStringA, FileTimeToSystemTime, GetOEMCP, GetCPInfo, InterlockedIncrement, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, GlobalFlags, CreateFileA, GetFullPathNameA, GetVolumeInformationA, FindFirstFileA, FindClose, GetCurrentProcess, DuplicateHandle, GetThreadLocale, GetFileSize, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, InterlockedDecrement, GetModuleFileNameW, GetCurrentProcessId, CloseHandle, GetCurrentThread, ConvertDefaultLocale, GetModuleFileNameA, EnumResourceLanguagesA, GetLocaleInfoA, lstrcmpA, GlobalAlloc, FormatMessageA, LocalFree, MulDiv, GetCurrentThreadId, GlobalGetAtomNameA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, FreeLibrary, LoadLibraryA, SetLastError, lstrcmpW, GetProcAddress, GetVersionExA, GlobalLock, GlobalUnlock, GlobalFree, FreeResource, GetLastError, lstrlenA, CompareStringA, CompareStringW, MultiByteToWideChar, GetVersion, InterlockedExchange, GetCurrentDirectoryA, FindResourceExA, GetUserDefaultLangID, GetModuleHandleA, LoadResource, LockResource, SizeofResource, FindResourceA, GetFileType, WideCharToMultiByte
> USER32.dll: DestroyMenu, LoadCursorA, GetSysColorBrush, EndPaint, BeginPaint, ReleaseDC, GetDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, GetWindowThreadProcessId, SetCursor, GetMessageA, TranslateMessage, GetCursorPos, ValidateRect, PostQuitMessage, ShowWindow, SetWindowTextA, IsDialogMessageA, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapA, ModifyMenuA, EnableMenuItem, CheckMenuItem, RegisterWindowMessageA, WinHelpA, GetCapture, SetWindowsHookExA, CallNextHookEx, GetClassLongA, GetClassNameA, SetPropA, GetPropA, RemovePropA, GetFocus, SetFocus, GetWindowTextLengthA, GetWindowTextA, GetForegroundWindow, GetLastActivePopup, DispatchMessageA, GetTopWindow, UnhookWindowsHookEx, GetMessageTime, GetMessagePos, PeekMessageA, MapWindowPoints, GetKeyState, IsWindowVisible, UpdateWindow, GetClientRect, GetMenu, GetSubMenu, EnableWindow, LoadImageA, MessageBoxA, LoadIconA, SetActiveWindow, SetForegroundWindow, GetMenuItemID, GetMenuItemCount, CreateWindowExA, GetClassInfoExA, GetClassInfoA, RegisterClassA, GetSysColor, AdjustWindowRectEx, CopyRect, UnregisterClassA, PtInRect, GetMenuState, SendMessageA, PostMessageA, InvalidateRect, CharUpperA, EndDialog, GetNextDlgTabItem, GetParent, IsWindowEnabled, GetDlgItem, GetWindowLongA, IsWindow, DestroyWindow, CreateDialogIndirectParamA, GetSystemMetrics, GetActiveWindow, GetDlgCtrlID, DefWindowProcA, CallWindowProcA, SetWindowLongA, SetWindowPos, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetWindow, GetDesktopWindow, SendDlgItemMessageA
> GDI32.dll: DeleteDC, GetStockObject, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutA, TextOutA, RectVisible, PtVisible, DeleteObject, SetMapMode, RestoreDC, SaveDC, GetDeviceCaps, CreateBitmap, GetObjectA, SetBkColor, SetTextColor, GetClipBox
> comdlg32.dll: GetFileTitleA
> WINSPOOL.DRV: ClosePrinter, DocumentPropertiesA, OpenPrinterA
> ADVAPI32.dll: RegQueryValueA, RegEnumKeyA, RegOpenKeyA, RegCloseKey, RegDeleteKeyA, RegEnumKeyExA, RegOpenKeyExA, RegQueryValueExA, RegCreateKeyExA, RegSetValueExA
> COMCTL32.dll: -
> SHLWAPI.dll: PathFindFileNameA, PathStripToRootA, PathFindExtensionA, PathIsUNCA
> OLEAUT32.dll: -, -, -
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
sigcheck:
publisher....: Electronic Arts
copyright....: Electronic Arts, Inc.
product......: n/a
description..: Unified Registration code installer program
original name: n/a
internal name: n/a
file version.: 1.07.08.02
comments.....: n/a
signers......: Electronic Arts
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 3:19 AM 11/7/2007
verified.....: -