Slt RAPHY,
Ci-joint le scan sur le site que vs m'avez conseillé de la Dll ainsi que celui du deuxième ficher constituant le répertoire de ce mystérieux intrus. Selon ce scan, la Dll n'a pas été diagnostiquée comme suspecte, cependant le fichier UNINST est considéré comme suspect par Panda antivirus.
Puis-je essayer de désinstaller ce truc puisqu'il y a le fichier qui le permet?
-----------------------------------------
RESULTAT DU SCAN:
I/
Fichier LuckyTender.dll reçu le 2008.08.19 16:54:40 (CET)
Situation actuelle: terminé
Résultat: 0/35 (0.00%)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.8.19.0 2008.08.19 -
AntiVir 7.8.1.23 2008.08.19 -
Authentium 5.1.0.4 2008.08.19 -
Avast 4.8.1195.0 2008.08.19 -
AVG 8.0.0.161 2008.08.19 -
BitDefender 7.2 2008.08.19 -
CAT-QuickHeal 9.50 2008.08.18 -
ClamAV 0.93.1 2008.08.19 -
DrWeb 4.44.0.09170 2008.08.19 -
eSafe 7.0.17.0 2008.08.19 -
eTrust-Vet 31.6.6035 2008.08.15 -
Ewido 4.0 2008.08.19 -
F-Prot 4.4.4.56 2008.08.18 -
Fortinet 3.14.0.0 2008.08.19 -
GData 2.0.7306.1023 2008.08.19 -
Ikarus T3.1.1.34.0 2008.08.19 -
K7AntiVirus 7.10.420 2008.08.18 -
Kaspersky 7.0.0.125 2008.08.19 -
McAfee 5363 2008.08.18 -
Microsoft 1.3807 2008.08.19 -
NOD32v2 3368 2008.08.19 -
Norman 5.80.02 2008.08.19 -
Panda 9.0.0.4 2008.08.19 -
PCTools 4.4.2.0 2008.08.19 -
Prevx1 V2 2008.08.19 -
Rising 20.58.12.00 2008.08.19 -
Sophos 4.32.0 2008.08.19 -
Sunbelt 3.1.1546.1 2008.08.15 -
Symantec 10 2008.08.19 -
TheHacker 6.3.0.5.054 2008.08.19 -
TrendMicro 8.700.0.1004 2008.08.19 -
VBA32 3.12.8.3 2008.08.19 -
ViRobot 2008.8.19.1341 2008.08.19 -
VirusBuster 4.5.11.0 2008.08.19 -
Webwasher-Gateway 6.6.2 2008.08.19 -
Information additionnelle
File size: 188416 bytes
MD5...: fbbd36fc9f5de933753a1b855944e04a
SHA1..: 6aff38e2228f86233e103da286381da37feff0ce
SHA256: ff68a2096413a90a3505610353307a88355e1f34d9417acdd4f2d4855db33b62
SHA512: 7bc90a7084cfeb60d6abe4c4d4ac641c9b65fd477c8d57c5b4fa0d84b9a797b6
c4b207b5ac9fb503b42b12212dbefc9507eddf73ef984eb2d4a9cf6b064dbace
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x10014e4e
timedatestamp.....: 0x483f3157 (Thu May 29 22:42:31 2008)
machinetype.......: 0x14c (I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1eadf 0x1f000 6.56 18a58a5964b5c4a2a5e0180ed9b821d9
.orpc 0x20000 0x98 0x1000 0.38 de88e2a9534a45438ef84d879a3fb6c2
.rdata 0x21000 0x58f7 0x6000 4.61 d604ddae12b261089684049d0eb02161
.data 0x27000 0x2d9c 0x2000 2.37 c256d30632cbf17773f9174068b64162
.rsrc 0x2a000 0x1980 0x2000 4.44 683440134b7da1eac728d1d6346f2627
.reloc 0x2c000 0x2630 0x3000 4.46 214c6ce14d917d2141412941d0bab4e5
( 10 imports )
> iphlpapi.dll: GetAdaptersInfo
> KERNEL32.dll: InitializeCriticalSection, DeleteCriticalSection, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, WaitForSingleObject, MultiByteToWideChar, lstrlenA, WideCharToMultiByte, lstrlenW, GetProcessHeap, HeapAlloc, HeapFree, HeapReAlloc, FileTimeToSystemTime, CloseHandle, GetFileTime, CreateFileW, WriteFile, ReleaseMutex, CreateMutexW, GetVolumeInformationW, lstrcpyW, RaiseException, lstrcmpiW, GetModuleFileNameW, lstrcpynW, lstrcatW, InterlockedIncrement, LeaveCriticalSection, FreeLibrary, LoadLibraryExW, GetModuleHandleW, FlushInstructionCache, GetCurrentProcess, GetCurrentThreadId, GetProcAddress, LoadLibraryW, SetFileTime, DeleteFileW, LocalFree, HeapSize, TerminateProcess, GetDateFormatA, GetTimeFormatA, GetSystemInfo, VirtualProtect, VirtualQuery, SetUnhandledExceptionFilter, GetModuleFileNameA, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, TlsGetValue, TlsSetValue, TlsFree, SetLastError, TlsAlloc, EnterCriticalSection, UnhandledExceptionFilter, GetLastError, GetVersionExW, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, SetEnvironmentVariableA, InterlockedDecrement, LCMapStringW, LCMapStringA, IsBadWritePtr, VirtualAlloc, CompareStringW, CompareStringA, FlushFileBuffers, SetStdHandle, GetTimeZoneInformation, SetFilePointer, IsBadCodePtr, GetOEMCP, LoadLibraryA, IsBadReadPtr, GetStringTypeW, GetStringTypeA, GetCPInfo, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetFileType, GetStdHandle, SetHandleCount, VirtualFree, ExitProcess, RtlUnwind, GetSystemTimeAsFileTime, ExitThread, ResumeThread, HeapCreate, HeapDestroy, GetVersionExA, GetCommandLineA, CreateThread
> USER32.dll: SystemParametersInfoW, CreateWindowExW, RegisterClassExW, CallWindowProcW, GetWindowLongW, DefWindowProcW, DestroyWindow, AnimateWindow, LoadCursorW, wsprintfW, GetClassInfoExW, ShowWindow, GetClientRect, GetWindowRect, MoveWindow, SetWindowLongW, UnregisterClassW, CharNextW
> ADVAPI32.dll: RegCreateKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegDeleteValueW, RegDeleteKeyW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey
> SHELL32.dll: SHGetSpecialFolderPathW, FindExecutableW, SHCreateDirectoryExW
> ole32.dll: CoTaskMemAlloc, CoCreateGuid, StringFromGUID2, StringFromCLSID, CoTaskMemFree, CoCreateInstance, CoInitialize, CoTaskMemRealloc
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> RPCRT4.dll: NdrStubCall2, NdrDllUnregisterProxy, NdrDllRegisterProxy, NdrCStdStubBuffer2_Release, NdrCStdStubBuffer_Release, NdrDllCanUnloadNow, NdrDllGetClassObject, NdrOleAllocate, NdrOleFree, IUnknown_QueryInterface_Proxy, IUnknown_AddRef_Proxy, IUnknown_Release_Proxy, CStdStubBuffer_QueryInterface, CStdStubBuffer_AddRef, CStdStubBuffer_Connect, CStdStubBuffer_Disconnect, CStdStubBuffer_Invoke, CStdStubBuffer_IsIIDSupported, CStdStubBuffer_CountRefs, CStdStubBuffer_DebugServerQueryInterface, CStdStubBuffer_DebugServerRelease, NdrStubForwardingFunction
> SHLWAPI.dll: PathFindExtensionW
> WS2_32.dll: WSASocketW, -, -, WSACreateEvent, WSASetEvent, WSAEventSelect, WSARecv, WSAResetEvent, WSASend, WSAGetOverlappedResult, WSAConnect, -, WSAEnumNetworkEvents, WSACloseEvent, -, GetAddrInfoW, FreeAddrInfoW
( 4 exports )
DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=fbbd36fc9f5de933753a1b855944e04a
=======================================================================
II/
Fichier uninst.exe reçu le 2008.06.09 11:52:19 (CET)
Situation actuelle: terminé
Résultat: 1/33 (3.03%)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
F-Prot - - -
F-Secure - - -
FileAdvisor - - -
Fortinet - - -
GData - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - Suspicious file
Prevx1 - - -
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - -
Information additionnelle
MD5: 8a565bebd25c477b103befecedccfc1d
SHA1: c2dd6902649a16a881037ecf44625d2029d555fe
SHA256: b91861ecb07294f6201257bb116503bbaa471642c8c0828f032d21f1c7f38f53
SHA512: e043d7fe1da04971e8eaf2971ffbb01560341a630b501e422a7f22f8b8db5ef97556d8680cd493a7a2476c5d517ca5d36484146d1247da36f97d250d7ef5c1bf
FIN D SCAN
A+