Bonjour ,
voilà le premier resultat , du fichier C:\WINDOWS\system32\avifile32.dll
Fichier avifile32.dll reçu le 2009.11.03 08:51:21 (UTC)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.41 2009.11.03 Trojan.Win32.Meredrop!IK
AhnLab-V3 5.0.0.2 2009.11.03 -
AntiVir 7.9.1.53 2009.11.02 -
Antiy-AVL 2.0.3.7 2009.11.03 -
Authentium 5.1.2.4 2009.11.03 -
Avast 4.8.1351.0 2009.11.02 -
AVG 8.5.0.423 2009.11.02 Packed.DelfCrypt
BitDefender 7.2 2009.11.03 -
CAT-QuickHeal 10.00 2009.11.03 -
ClamAV 0.94.1 2009.11.03 -
Comodo 2824 2009.11.03 -
DrWeb 5.0.0.12182 2009.11.03 -
eSafe 7.0.17.0 2009.11.02 -
eTrust-Vet 35.1.7099 2009.11.03 -
F-Prot 4.5.1.85 2009.11.02 -
F-Secure 9.0.15370.0 2009.10.30 -
Fortinet 3.120.0.0 2009.11.03 -
GData 19 2009.11.03 -
Ikarus T3.1.1.72.0 2009.11.03 Trojan.Win32.Meredrop
Jiangmin 11.0.800 2009.11.03 -
K7AntiVirus 7.10.886 2009.11.02 Trojan-Dropper.Win32.Delf.ebo
Kaspersky 7.0.0.125 2009.11.03 Trojan-Dropper.Win32.Delf.ebo
McAfee 5790 2009.11.02 -
McAfee+Artemis 5790 2009.11.02 -
McAfee-GW-Edition 6.8.5 2009.11.02 -
Microsoft 1.5202 2009.11.03 -
NOD32 4567 2009.11.03 -
Norman 6.03.02 2009.11.02 -
nProtect 2009.1.8.0 2009.11.03 Trojan-Dropper/W32.Agent.268288.J
Panda 10.0.2.2 2009.11.02 Suspicious file
PCTools 7.0.3.5 2009.11.03 -
Prevx 3.0 2009.11.03 -
Rising 21.54.12.00 2009.11.03 -
Sophos 4.47.0 2009.11.03 -
Sunbelt 3.2.1858.2 2009.11.02 -
Symantec 1.4.4.12 2009.11.03 -
TheHacker 6.5.0.2.059 2009.11.03 -
TrendMicro 8.950.0.1094 2009.11.03 -
VBA32 3.12.10.11 2009.11.02 -
ViRobot 2009.11.3.2019 2009.11.03 -
VirusBuster 4.6.5.0 2009.11.02 TrojanSpy.Agent.PHBK
Information additionnelle
File size: 268288 bytes
MD5...: 02fcc7ed6b56e526b064e9c4196709da
SHA1..: d90f672d6d030d351ac78a6902a70b4ce4e09706
SHA256: c9e0fb2d4d944c44a53e8dafaa20c374a38db365248498f6c548ea37925e13ca
ssdeep: 6144:gs6q7rCFJGkir4YP5dB3IH2XzwnhfyKdyP09cBsy5wYQ:gs6qndpU2Cfyec<br>HwY<br>
PEiD..: -
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x3ce0a<br>timedatestamp.....: 0x48d33211 (Fri Sep 19 05:01:05 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>CODE 0x1000 0x3bfcb 0x3c000 7.99 e8ee52ab48a91603d362f459fc628c18<br>DATA 0x3d000 0x28e13 0x600 3.92 e12ef6600cc0b1ebc4abaf32bdf3f685<br>BSS 0x66000 0xe61 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.idata 0x67000 0x9df 0xa00 4.61 b07b6979bf11706dc6400d25210e5256<br>.reloc 0x68000 0x43fb 0x4400 6.80 2b6eaa5598ed4f934a7134c475087301<br><br>( 10 imports ) <br>> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle<br>> user32.dll: GetKeyboardType, LoadStringA, MessageBoxA, CharNextA<br>> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey<br>> oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen<br>> kernel32.dll: TlsSetValue, TlsGetValue, TlsFree, TlsAlloc, LocalFree, LocalAlloc<br>> kernel32.dll: WriteFile, WaitForSingleObject, VirtualQuery, SetFilePointer, SetEvent, SetEndOfFile, ResetEvent, ReadFile, LeaveCriticalSection, InitializeCriticalSection, GetVersionExA, GetThreadLocale, GetStringTypeExA, GetStdHandle, GetProcAddress, GetOEMCP, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCPInfo, GetACP, FormatMessageA, EnumCalendarInfoA, EnterCriticalSection, DeleteCriticalSection, CreateFileA, CreateEventA, CompareStringA, CloseHandle<br>> user32.dll: MessageBoxA, LoadStringA, GetSystemMetrics, CharNextA, CharToOemA<br>> kernel32.dll: Sleep<br>> oleaut32.dll: SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit<br>> dsound.dll: DirectSoundCreate<br><br>( 0 exports ) <br>
RDS...: NSRL Reference Data Set<br>-
pdfid.: -
sigcheck:<br>publisher....: n/a<br>copyright....: n/a<br>product......: n/a<br>description..: n/a<br>original name: n/a<br>internal name: n/a<br>file version.: n/a<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
trid..: Win32 Executable Generic (42.3%)<br>Win32 Dynamic Link Library (generic) (37.6%)<br>Generic Win/DOS Executable (9.9%)<br>DOS Executable Generic (9.9%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
et ça pour le dernier C:\WINDOWS\system32\XGEZ7.vbs
Fichier XGEZ7.vbs reçu le 2009.11.03 09:30:51 (UTC)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.41 2009.11.03 Trojan.VBS.Tracur!IK
AhnLab-V3 5.0.0.2 2009.11.03 VBS/Xema
AntiVir 7.9.1.53 2009.11.03 SPR/FWBypass.B
Antiy-AVL 2.0.3.7 2009.11.03 -
Authentium 5.1.2.4 2009.11.03 VBS/Agent.EM
Avast 4.8.1351.0 2009.11.02 -
AVG 8.5.0.423 2009.11.03 -
BitDefender 7.2 2009.11.03 -
CAT-QuickHeal 10.00 2009.11.03 -
ClamAV 0.94.1 2009.11.03 -
Comodo 2824 2009.11.03 -
DrWeb 5.0.0.12182 2009.11.03 -
eSafe 7.0.17.0 2009.11.02 Win32.Horse
eTrust-Vet 35.1.7099 2009.11.03 -
F-Prot 4.5.1.85 2009.11.02 VBS/Agent.EM
F-Secure 9.0.15370.0 2009.10.30 -
Fortinet 3.120.0.0 2009.11.03 -
GData 19 2009.11.03 -
Ikarus T3.1.1.72.0 2009.11.03 Trojan.VBS.Tracur
Jiangmin 11.0.800 2009.11.03 -
K7AntiVirus 7.10.886 2009.11.02 -
Kaspersky 7.0.0.125 2009.11.03 Backdoor.Win32.Agent.amjd
McAfee 5790 2009.11.02 -
McAfee+Artemis 5790 2009.11.02 -
McAfee-GW-Edition 6.8.5 2009.11.03 Riskware.FWBypass.B
Microsoft 1.5202 2009.11.03 Trojan:VBS/Tracur
NOD32 4567 2009.11.03 VBS/Disabler.NAB
Norman 6.03.02 2009.11.02 VBS/Smalltroj.XSV
nProtect 2009.1.8.0 2009.11.03 -
Panda 10.0.2.2 2009.11.02 VBS/Disabler.E
PCTools 7.0.3.5 2009.11.03 Trojan.Agent
Prevx 3.0 2009.11.03 -
Rising 21.54.12.00 2009.11.03 -
Sophos 4.47.0 2009.11.03 Troj/Fwdisab-B
Sunbelt 3.2.1858.2 2009.11.02 -
Symantec 1.4.4.12 2009.11.03 Trojan Horse
TheHacker 6.5.0.2.059 2009.11.03 -
TrendMicro 8.950.0.1094 2009.11.03 -
VBA32 3.12.10.11 2009.11.02 -
ViRobot 2009.11.3.2019 2009.11.03 VBS.Script.615
VirusBuster 4.6.5.0 2009.11.02 -
Information additionnelle
File size: 615 bytes
MD5...: 768466ea2059580a84f9c0e68d94c644
SHA1..: c9ad3cf2b59f4335e92a0640a51c4c52196f7836
SHA256: aa24f9656f6e05d6640100c4d263a6189efdbb102aff72fd8e69c366d8e69cc9
ssdeep: 12:tKT0GWo29iS7fwdRbXc6cw49iFMXFPYjW/QakgNOfwv1SvWdg4chZ:tKWo29i<br>SbyNM9hyW/zh6JA3chZ<br>
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set<br>-
pdfid.: -
trid..: Unknown!
sigcheck:<br>publisher....: n/a<br>copyright....: n/a<br>product......: n/a<br>description..: n/a<br>original name: n/a<br>internal name: n/a<br>file version.: n/a<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
C:\WINDOWS\system32\0t6HAmRVcT4FbDS.vbs
Fichier 0t6HAmRVcT4FbDS.vbs reçu le 2009.11.03 09:47:12 (UTC)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.41 2009.11.03 Trojan.VBS.Tracur!IK
AhnLab-V3 5.0.0.2 2009.11.03 VBS/Xema
AntiVir 7.9.1.53 2009.11.03 SPR/FWBypass.B
Antiy-AVL 2.0.3.7 2009.11.03 -
Authentium 5.1.2.4 2009.11.03 VBS/Agent.EM
Avast 4.8.1351.0 2009.11.02 -
AVG 8.5.0.423 2009.11.03 -
BitDefender 7.2 2009.11.03 -
CAT-QuickHeal 10.00 2009.11.03 -
ClamAV 0.94.1 2009.11.03 -
Comodo 2824 2009.11.03 -
DrWeb 5.0.0.12182 2009.11.03 -
eSafe 7.0.17.0 2009.11.02 Win32.Horse
eTrust-Vet 35.1.7099 2009.11.03 -
F-Prot 4.5.1.85 2009.11.02 VBS/Agent.EM
F-Secure 9.0.15370.0 2009.10.30 -
Fortinet 3.120.0.0 2009.11.03 -
GData 19 2009.11.03 -
Ikarus T3.1.1.72.0 2009.11.03 Trojan.VBS.Tracur
Jiangmin 11.0.800 2009.11.03 -
K7AntiVirus 7.10.886 2009.11.02 -
Kaspersky 7.0.0.125 2009.11.03 Backdoor.Win32.Agent.amjd
McAfee 5790 2009.11.02 -
McAfee+Artemis 5790 2009.11.02 -
McAfee-GW-Edition 6.8.5 2009.11.03 Riskware.FWBypass.B
Microsoft 1.5202 2009.11.03 Trojan:VBS/Tracur
NOD32 4568 2009.11.03 VBS/Disabler.NAB
Norman 6.03.02 2009.11.02 VBS/Smalltroj.XSV
nProtect 2009.1.8.0 2009.11.03 -
Panda 10.0.2.2 2009.11.02 VBS/Disabler.E
PCTools 7.0.3.5 2009.11.03 Trojan.Agent
Prevx 3.0 2009.11.03 -
Rising 21.54.12.00 2009.11.03 -
Sophos 4.47.0 2009.11.03 Troj/Fwdisab-B
Sunbelt 3.2.1858.2 2009.11.02 -
Symantec 1.4.4.12 2009.11.03 Trojan Horse
TheHacker 6.5.0.2.059 2009.11.03 -
TrendMicro 8.950.0.1094 2009.11.03 -
VBA32 3.12.10.11 2009.11.02 -
ViRobot 2009.11.3.2019 2009.11.03 VBS.Script.615
VirusBuster 4.6.5.0 2009.11.02 -
Information additionnelle
File size: 615 bytes
MD5...: 768466ea2059580a84f9c0e68d94c644
SHA1..: c9ad3cf2b59f4335e92a0640a51c4c52196f7836
SHA256: aa24f9656f6e05d6640100c4d263a6189efdbb102aff72fd8e69c366d8e69cc9
ssdeep: 12:tKT0GWo29iS7fwdRbXc6cw49iFMXFPYjW/QakgNOfwv1SvWdg4chZ:tKWo29i<br>SbyNM9hyW/zh6JA3chZ<br>
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set<br>-
pdfid.: -
sigcheck:<br>publisher....: n/a<br>copyright....: n/a<br>product......: n/a<br>description..: n/a<br>original name: n/a<br>internal name: n/a<br>file version.: n/a<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
trid..: Unknown!
PS: les analyses n'ont pas dépassés les 47 %