Voici le rapport reçu :
Fichier fmxbsftav.exe reçu le 2010.02.18 18:31:20 (UTC)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 15/41 (36.59%)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.50 2010.02.18 -
AhnLab-V3 5.0.0.2 2010.02.18 -
AntiVir 8.2.1.170 2010.02.18 TR/FraudPack.alnv
Antiy-AVL 2.0.3.7 2010.02.18 -
Authentium 5.2.0.5 2010.02.18 W32/FakeAV.RD
Avast 4.8.1351.0 2010.02.18 Win32:Adware-gen
AVG 9.0.0.730 2010.02.18 -
BitDefender 7.2 2010.02.18 -
CAT-QuickHeal 10.00 2010.02.18 -
ClamAV 0.96.0.0-git 2010.02.18 -
Comodo 3982 2010.02.18 -
DrWeb 5.0.1.12222 2010.02.18 -
eSafe 7.0.17.0 2010.02.18 -
eTrust-Vet 35.2.7310 2010.02.18 Win32/AntivirusLive.H
F-Prot 4.5.1.85 2010.02.17 -
F-Secure 9.0.15370.0 2010.02.18 Suspicious:W32/Malware!Gemini
Fortinet 4.0.14.0 2010.02.18 -
GData 19 2010.02.18 Win32:Adware-gen
Ikarus T3.1.1.80.0 2010.02.18 -
Jiangmin 13.0.900 2010.02.18 -
K7AntiVirus 7.10.977 2010.02.18 -
Kaspersky 7.0.0.125 2010.02.17 Trojan.Win32.FraudPack.alnv
McAfee 5896 2010.02.18 -
McAfee+Artemis 5896 2010.02.18 -
McAfee-GW-Edition 6.8.5 2010.02.18 Heuristic.LooksLike.Win32.Suspicious.I
Microsoft 1.5406 2010.02.18 TrojanDownloader:Win32/Renos.KQ
NOD32 4878 2010.02.18 Win32/Adware.SpywareProtect2009
Norman 6.04.08 2010.02.18 -
nProtect 2009.1.8.0 2010.02.18 -
Panda 10.0.2.2 2010.02.18 Suspicious file
PCTools 7.0.3.5 2010.02.17 -
Prevx 3.0 2010.02.18 High Risk Fraudulent Security Program
Rising 22.34.01.03 2010.02.11 -
Sophos 4.50.0 2010.02.18 Mal/FakeAV-CF
Sunbelt 5684 2010.02.18 -
Symantec 20091.2.0.41 2010.02.18 AntiVirus2008
TheHacker 6.5.1.4.198 2010.02.18 Trojan/FraudPack.alnv
TrendMicro 9.120.0.1004 2010.02.18 -
VBA32 3.12.12.2 2010.02.18 -
ViRobot 2010.2.18.2192 2010.02.18 -
VirusBuster 5.0.27.0 2010.02.18 -
Information additionnelle
File size: 278784 bytes
MD5...: b8f270a085334e2ed045ce38b0a80b7c
SHA1..: a1aff9bc48193c0b07529477503864ec71e3518a
SHA256: 55d7f2e2359d9dece893c2600cf9f32d0564f6607cb5466731d86ea2d8611b71
ssdeep: 6144:wiUeyKK3Gz6fvManYDIA9fXFc8Z5NZohtCO/4D0oUshcv5B:Fq2IUyYflyb
C+F4G5B
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x76830
timedatestamp.....: 0x4b7aa27a (Tue Feb 16 13:49:46 2010)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x32000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x33000 0x44000 0x43a00 7.77 65514bda852ec32dcb654e5447edf8bd
.rsrc 0x77000 0x1000 0x200 3.47 77d15c0f01058b7e5b2f173b741cd865
( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> SHLWAPI.dll: UrlHashA
> USER32.dll: GetMessageA
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: UPX compressed Win32 Executable (42.6%)
Win32 EXE Yoda's Crypter (37.0%)
Win32 Executable Generic (11.8%)
Clipper DOS Executable (2.8%)
Generic Win/DOS Executable (2.7%)
packers (F-Prot): UPX
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=26990B360063B95F412E049EC0F46D0012796B2B' target='_blank'>
http://info.prevx.com/...
Dis moi si ça te suffit ou s'il te manque quoi que ce soit ;)
Merci
Mais j'ai encore besoin d'avis de personnes initiées :
http://www.commentcamarche.net/faq/2964-virus-your-computer-is-infected