Désolés de ne pas avoir répondu plus tôt mais problème avec ootlook.
voici les deux rapports.
1er fichier.
File size: 174656 bytes
MD5 : 64e413ba0c529aa40c3924bbcc4153db
SHA1 : 8e05d5a28739ed474fe44060ed780378764e2530
SHA256: 9e0eb02078ee250ac618d4a4537d54bacdd7e2b67349162ca61f35eaf91601ee
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x489E
timedatestamp.....: 0x454AC752 (Fri Nov 3 05:36:34 2006)
machinetype.......: 0x14C (Intel I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1D1BA 0x1E000 6.53 3b9155e63fe90fc609f7539428a09e75
.rdata 0x1F000 0x73F0 0x8000 4.52 5109f7f2477caaf5f843717f153855c1
.data 0x27000 0x5274 0x2000 3.69 07b4e18e4e3485e7a0484b23d2c902d4
.rsrc 0x2D000 0x548 0x1000 1.84 4d61de85445e3e3485fe47ecfbfaab3d
( 10 imports )
> advapi32.dll: RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, SetServiceStatus
> comctl32.dll: -
> gdi32.dll: GetStockObject, DeleteDC, ScaleWindowExtEx, SetWindowExtEx, SetTextColor, GetClipBox, CreateBitmap, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, TextOutA, RectVisible, PtVisible, SetMapMode, RestoreDC, SaveDC, ExtTextOutA, DeleteObject, SetBkColor, GetDeviceCaps
> kernel32.dll: GetCurrentProcess, HeapAlloc, HeapFree, RtlUnwind, ExitProcess, GetCommandLineA, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, HeapReAlloc, HeapSize, TerminateProcess, HeapDestroy, HeapCreate, VirtualFree, IsBadWritePtr, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, GetStartupInfoA, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, IsBadReadPtr, IsBadCodePtr, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, SetStdHandle, GetLocaleInfoW, FlushFileBuffers, SetFilePointer, WriteFile, GetOEMCP, GetCPInfo, lstrcpyA, GlobalFlags, lstrcmpA, GlobalGetAtomNameA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, LoadLibraryA, FreeLibrary, lstrcatA, lstrcmpW, GetModuleHandleA, GetProcAddress, InterlockedIncrement, GetCurrentThreadId, CloseHandle, FormatMessageA, InterlockedDecrement, TlsFree, GlobalFree, LocalReAlloc, TlsSetValue, TlsAlloc, TlsGetValue, EnterCriticalSection, GlobalAlloc, GlobalHandle, GlobalUnlock, GlobalReAlloc, GlobalLock, LeaveCriticalSection, LocalFree, LocalAlloc, GetModuleFileNameA, FindResourceA, LoadResource, LockResource, SizeofResource, lstrlenA, lstrcmpiA, GetVersion, DeleteCriticalSection, InitializeCriticalSection, RaiseException, WideCharToMultiByte, MultiByteToWideChar, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, GetLastError, SetLastError, lstrcpynA
> oleacc.dll: LresultFromObject, CreateStdAccessibleObject
> oleaut32.dll: -, -, -
> psikey.dll: -
> rpcrt4.dll: RpcServerUseProtseqEpA, RpcServerRegisterIf, RpcServerListen, NdrServerCall2
> user32.dll: PostQuitMessage, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, DestroyMenu, ClientToScreen, SetWindowTextA, RegisterWindowMessageA, WinHelpA, GetCapture, CreateWindowExA, GetClassLongA, GetClassInfoExA, GetClassNameA, SetPropA, GetPropA, RemovePropA, GetWindowTextA, GetForegroundWindow, GetTopWindow, DestroyWindow, GetMessageTime, GetMessagePos, LoadIconA, MapWindowPoints, SetForegroundWindow, GetClientRect, GetMenu, PostMessageA, AdjustWindowRectEx, GetClassInfoA, UnregisterClassA, EnableWindow, RegisterClassA, GetDlgCtrlID, DefWindowProcA, CallWindowProcA, SetWindowLongA, SetWindowPos, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, CopyRect, PtInRect, GetWindow, GetDlgItem, IsWindowEnabled, GetLastActivePopup, GetWindowLongA, GetParent, MessageBoxA, SendMessageA, UnhookWindowsHookEx, GetSubMenu, GetMenuItemCount, GetMenuItemID, SetMenuItemBitmaps, GetFocus, ModifyMenuA, EnableMenuItem, CheckMenuItem, GetMenuCheckMarkDimensions, LoadBitmapA, LoadCursorA, GetSystemMetrics, GetDC, ReleaseDC, GetSysColor, GetSysColorBrush, SetWindowsHookExA, CallNextHookEx, DispatchMessageA, GetKeyState, PeekMessageA, ValidateRect, GetMenuState
> winspool.drv: DocumentPropertiesA, OpenPrinterA, ClosePrinter
( 0 exports )
TrID : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=64e413ba0c529aa40c3924bbcc4153db
ssdeep: 3072:nGuPQ+Gb/dH0dfRUDXlK34lm/N9v1z9k2W5akcSurQ5aHlDNZ:PPXGb/dHW6phm3fMFc37
PEiD : -
RDS : NSRL Reference Data Set
( Corel Corporation )
Corel Painter Essentials 3: psiservice.exe.7A552993_141F_4F89_B04D_43DF42F703B1
2eme fichier:
File size: 54624 bytes
MD5 : 21e6282042f5fc2a0e47e5324708b6e8
SHA1 : b60951c729e43d483a951a2371a5b9293f11faa3
SHA256: 598d03eef675bbdc4641f7ffc3039e7779e36d0aa21fa08ddbfb1d40704e6a8a
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x2F7F
timedatestamp.....: 0x4ADEB388 (Wed Oct 21 09:08:56 2009)
machinetype.......: 0x14C (Intel I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6384 0x7000 6.22 35d8dfeb58e512a60659105414b8dd6c
.rdata 0x8000 0x18FC 0x2000 4.15 39623f65626c20177aee7dc236fdb0ff
.data 0xA000 0x958 0x1000 1.03 944543b1d50c3955cbcfa2f2a703b231
.rsrc 0xB000 0x10 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
( 1 imports )
> kernel32.dll: lstrcpyA, lstrlenA, UnmapViewOfFile, FlushViewOfFile, MapViewOfFile, CloseHandle, CreateFileMappingA, GetFileSize, CreateFileA, GetProcAddress, LoadLibraryExA, lstrcmpA, RtlUnwind, RaiseException, GetSystemTimeAsFileTime, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapAlloc, HeapFree, SetUnhandledExceptionFilter, ExitProcess, TerminateProcess, GetCurrentProcess, WriteFile, GetStdHandle, GetModuleFileNameA, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetLastError, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, IsBadWritePtr, HeapSize, IsBadReadPtr, IsBadCodePtr, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, GetACP, GetOEMCP, GetCPInfo, LoadLibraryA, InterlockedExchange, VirtualQuery, GetLocaleInfoA, VirtualProtect, GetSystemInfo, LCMapStringA, LCMapStringW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId
( 0 exports )
TrID : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ssdeep: 768:uOYx3SzSZtiYzAmp0GDMgpTfIXrnETwXMGWzOmeRmlODE8BLFJI:uOuiEVeGDMerwiwPW8JDE8Bk
Prevx Info: http://info.prevx.com/...
PEiD : -
RDS : NSRL Reference Data Set
-