Ok c'est bien ce qu'il me semblait.
pour C:\program files\ZipRepar.exe
Fichier ZipRepar.exe reçu le 2008.11.19 17:26:28 (CET)
Situation actuelle: terminé
Résultat: 3/36 (8.33%)
Formaté Formaté
Impression des résultats Impression des résultats
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.18.2 2008.11.19 -
AntiVir 7.9.0.34 2008.11.19 -
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 -
AVG 8.0.0.199 2008.11.19 -
BitDefender 7.2 2008.11.19 -
CAT-QuickHeal 10.00 2008.11.19 -
ClamAV 0.94.1 2008.11.19 -
DrWeb 4.44.0.09170 2008.11.19 -
eSafe 7.0.17.0 2008.11.19 Suspicious File
eTrust-Vet 31.6.6217 2008.11.19 -
Ewido 4.0 2008.11.19 -
F-Prot 4.4.4.56 2008.11.18 -
F-Secure 8.0.14332.0 2008.11.19 -
Fortinet 3.117.0.0 2008.11.19 -
GData 19 2008.11.19 -
Ikarus T3.1.1.45.0 2008.11.19 not-a-virus:AdWare.Win32.DownloadWare
K7AntiVirus 7.10.528 2008.11.19 -
Kaspersky 7.0.0.125 2008.11.19 -
McAfee 5438 2008.11.18 -
Microsoft 1.4104 2008.11.19 -
NOD32 3624 2008.11.19 -
Norman 5.80.02 2008.11.19 -
Panda 9.0.0.4 2008.11.19 Suspicious file
PCTools 4.4.2.0 2008.11.19 -
Prevx1 V2 2008.11.19 -
Rising 21.04.22.00 2008.11.19 -
SecureWeb-Gateway 6.7.6 2008.11.19 -
Sophos 4.35.0 2008.11.19 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.19 -
TheHacker 6.3.1.1.158 2008.11.19 -
TrendMicro 8.700.0.1004 2008.11.19 -
VBA32 3.12.8.9 2008.11.19 -
ViRobot 2008.11.18.1474 2008.11.18 -
VirusBuster 4.5.11.0 2008.11.19 -
Information additionnelle
File size: 205312 bytes
MD5...: ba78a4991e6a7881c9126eb305e8d447
SHA1..: bdddbe36c91551efadb1a2cfd8dda0c9e480dffe
SHA256: 96dab1a57af88fcb6f1cbd5dfff63e9f83df32e9da0216fe91113483389eb285
SHA512: 1aedd1f2d95ef7284fe2eba69d6637d082f0ef3a12ed48aeee62b57618a32118
302fcddcd30542f43fb6d7127e3caa65122ccea31d5a366cedb305b96a9eeafb
PEiD..: -
TrID..: File type identification
UPX compressed Win32 Executable (38.5%)
Win32 EXE Yoda's Crypter (33.4%)
Win32 Executable Generic (10.7%)
Win32 Dynamic Link Library (generic) (9.5%)
Win16/32 Executable Delphi generic (2.6%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x488840
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x57000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x58000 0x31000 0x30a00 7.92 ac2922bce50cf624e685c727f3f0f675
.rsrc 0x89000 0x2000 0x1400 4.09 d671dd8aae1dca34707322315330cafb
( 9 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> advapi32.dll: RegCloseKey
> comctl32.dll: ImageList_Add
> comdlg32.dll: GetOpenFileNameA
> gdi32.dll: SaveDC
> ole32.dll: CoInitialize
> oleaut32.dll: VariantCopy
> user32.dll: GetDC
> version.dll: VerQueryValueA
( 0 exports )
packers (F-Prot): UPX
packers (Kaspersky): UPX
pour C:\Documents and Settings\All Users\Application Data\citybooktitlemail\Moveproxy.exe
Fichier Moveproxy.exe reçu le 2008.11.19 17:16:06 (CET)
Situation actuelle: terminé
Résultat: 27/36 (75.00%)
Formaté Formaté
Impression des résultats Impression des résultats
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.18.2 2008.11.19 -
AntiVir 7.9.0.34 2008.11.19 ADSPY/Lop.ad.24
Authentium 5.1.0.4 2008.11.18 W32/LopP.E
Avast 4.8.1281.0 2008.11.18 Win32:Swizzor-gen
AVG 8.0.0.199 2008.11.19 Lop.B
BitDefender 7.2 2008.11.19 GenPack:Trojan.Swizzor.HJ
CAT-QuickHeal 10.00 2008.11.19 Win32.Trojan.C2Lop.B.5
ClamAV 0.94.1 2008.11.19 -
DrWeb 4.44.0.09170 2008.11.19 Trojan.Swizzor
eSafe 7.0.17.0 2008.11.18 -
eTrust-Vet 31.6.6217 2008.11.19 Win32/Swizzor
Ewido 4.0 2008.11.19 -
F-Prot 4.4.4.56 2008.11.18 W32/LopP.E
F-Secure 8.0.14332.0 2008.11.19 Swizzor.gen
Fortinet 3.117.0.0 2008.11.19 -
GData 19 2008.11.19 GenPack:Trojan.Swizzor.HJ
Ikarus T3.1.1.45.0 2008.11.19 AdWare.Lop.AG
K7AntiVirus 7.10.528 2008.11.19 -
Kaspersky 7.0.0.125 2008.11.19 not-a-virus:AdWare.Win32.Lop.bb
McAfee 5438 2008.11.18 Swizzor.gen
Microsoft 1.4104 2008.11.19 Trojan:Win32/C2Lop.B
NOD32 3624 2008.11.19 a variant of Win32/TrojanDownloader.Swizzor
Norman 5.80.02 2008.11.19 Swizzor.gen
Panda 9.0.0.4 2008.11.19 Trj/Ofuscated.gen
PCTools 4.4.2.0 2008.11.19 Trojan.Lop_com
Prevx1 V2 2008.11.19 -
Rising 21.04.22.00 2008.11.19 Trojan.DL.Swizzor.dvu
SecureWeb-Gateway 6.7.6 2008.11.19 Ad-Spyware.Lop.ad.24
Sophos 4.35.0 2008.11.19 Troj/Swizz-Fam
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.19 Adware.Lop
TheHacker 6.3.1.1.158 2008.11.19 Trojan/Downloader.Swizzor
TrendMicro 8.700.0.1004 2008.11.19 TROJ_SWIZZOR.KQ
VBA32 3.12.8.9 2008.11.19 AdWare.Win32.Lop.ag
ViRobot 2008.11.18.1474 2008.11.18 -
VirusBuster 4.5.11.0 2008.11.19 Packed/UPC
Information additionnelle
File size: 365403 bytes
MD5...: d752c1000eeca22b1e20645ddad0194d
SHA1..: 13b009923f06e8bf2aa479cd82a411615580ba0f
SHA256: 8511fd393fbe3fd7e63759ff84fa9339b6b8338042d30adcbe163eb431f5f595
SHA512: 835d08aa349d98133fe2e89e82f3cbd08f642a7b938326fdea2c8193a28d9290
7dd8d489845b4948880c2e7914d1cb366e7c7ba5430c612dfd7b86a8c00eb096
PEiD..: -
TrID..: File type identification
Win32 Dynamic Link Library (generic) (65.4%)
Generic Win/DOS Executable (17.2%)
DOS Executable Generic (17.2%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x401074
timedatestamp.....: 0x43b18c24 (Tue Dec 27 18:47:00 2005)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5b756 0x265bc 8.00 3a71113e3d08a5e7e6b60dd803c3ccad
.rdata 0x5d000 0xa84a 0x5044 7.99 d7432bf5eab06ff2752e881176373d96
.data 0x68000 0x61578 0x27cec 8.00 c35282f4a2bae113990f0bb083c963c8
.rsrc 0xca000 0x1e0 0x13c 4.94 30ea38652513b57bef14831aa3d7d9cf
.reloc 0xcb000 0x7f74 0x4b47 7.99 5c3d33e07f5c4e4a23037d72f74029bb
( 1 imports )
> KERNEL32.DLL: -
( 0 exports )
pour C:\windows\system32\drivers\kx.sys :
Fichier kx.sys reçu le 2008.11.19 17:21:51 (CET)
Situation actuelle: terminé
Résultat: 0/36 (0.00%)
Formaté Formaté
Impression des résultats Impression des résultats
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.18.2 2008.11.19 -
AntiVir 7.9.0.34 2008.11.19 -
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 -
AVG 8.0.0.199 2008.11.19 -
BitDefender 7.2 2008.11.19 -
CAT-QuickHeal 10.00 2008.11.19 -
ClamAV 0.94.1 2008.11.19 -
DrWeb 4.44.0.09170 2008.11.19 -
eSafe 7.0.17.0 2008.11.18 -
eTrust-Vet 31.6.6217 2008.11.19 -
Ewido 4.0 2008.11.19 -
F-Prot 4.4.4.56 2008.11.18 -
F-Secure 8.0.14332.0 2008.11.19 -
Fortinet 3.117.0.0 2008.11.19 -
GData 19 2008.11.19 -
Ikarus T3.1.1.45.0 2008.11.19 -
K7AntiVirus 7.10.528 2008.11.19 -
Kaspersky 7.0.0.125 2008.11.19 -
McAfee 5438 2008.11.18 -
Microsoft 1.4104 2008.11.19 -
NOD32 3624 2008.11.19 -
Norman 5.80.02 2008.11.19 -
Panda 9.0.0.4 2008.11.19 -
PCTools 4.4.2.0 2008.11.19 -
Prevx1 V2 2008.11.19 -
Rising 21.04.22.00 2008.11.19 -
SecureWeb-Gateway 6.7.6 2008.11.19 -
Sophos 4.35.0 2008.11.19 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.19 -
TheHacker 6.3.1.1.158 2008.11.19 -
TrendMicro 8.700.0.1004 2008.11.19 -
VBA32 3.12.8.9 2008.11.19 -
ViRobot 2008.11.18.1474 2008.11.18 -
VirusBuster 4.5.11.0 2008.11.19 -
Information additionnelle
File size: 571776 bytes
MD5...: 2404b1c9c1f4f7e3f43fc0050608f490
SHA1..: 4fa51ff9581e9544268a252d93de2a06b0a29eda
SHA256: 13594944479c3a718a60971129641cd4b654dd7d51a046e8ba36b15ca43d7225
SHA512: 36990cf3b9c676588176533db290fd5d6f7627f461d61cd8c0131557e770b053
161f5ddbeb7c34ed96d47e6a9fc0859821fcb2c9fb9792007fd230a7be052c6a
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x96f24
timedatestamp.....: 0x40313a39 (Mon Feb 16 21:46:33 2004)
machinetype.......: 0x14c (I386)
( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x380 0x528cc 0x52900 6.37 5703e8dd5e6b23dc6044c9a4f104b702
.rdata 0x52c80 0x3718 0x3780 6.02 6c7d020b57b4c433983d4d5a965d79a7
.data 0x56400 0xea00 0xea00 3.54 78f708dec4ab75d955ac0e902101398c
PAGE 0x64e00 0x21fe7 0x22000 6.45 f9d3c30c22f559a02ddc200c41486d14
.edata 0x86e00 0x80 0x80 4.37 55cde00cd449d7544be7e52b85606278
INIT 0x86e80 0x7fc 0x800 5.54 9e236fe28eadc9e25de2f420a3f8a650
.rsrc 0x87680 0x418 0x480 3.19 f22e30b154a0d8c79235382ac9595cdb
.reloc 0x87b00 0x3e34 0x3e80 6.63 be8713de4d5a38765c8980890d084848
( 4 imports )
> NTOSKRNL.EXE: IoGetDeviceProperty, ExFreePool, ZwClose, RtlFreeUnicodeString, ZwSetValueKey, wcslen, RtlAnsiStringToUnicodeString, RtlInitAnsiString, sprintf, strncpy, KeInitializeDpc, IoOpenDeviceInterfaceRegistryKey, wcsstr, RtlInitUnicodeString, IoGetDeviceInterfaces, KeInitializeSpinLock, KeSynchronizeExecution, KeInsertQueueDpc, KefReleaseSpinLockFromDpcLevel, KefAcquireSpinLockAtDpcLevel, ExAllocatePoolWithTag, strstr, _vsnprintf, DbgPrint, ZwQueryValueKey, KeSaveFloatingPointState, KeRestoreFloatingPointState, InterlockedIncrement, InterlockedDecrement, toupper, isxdigit, _purecall, IoFreeMdl, MmMapLockedPages, MmBuildMdlForNonPagedPool, IoAllocateMdl, MmUnlockPages, MmProbeAndLockPages, MmUnmapLockedPages, IoDeleteSymbolicLink, IoSetDeviceInterfaceState, IoCreateSymbolicLink, IoRegisterDeviceInterface, MmAllocatePagesForMdl, MmFreePagesFromMdl, RtlAssert, RtlRaiseException
> HAL.DLL: KfAcquireSpinLock, KeGetCurrentIrql, KfReleaseSpinLock
> portcls.sys: PcRegisterAdapterPowerManagement, PcRegisterPhysicalConnection, PcNewPort, PcRegisterSubdevice, PcAddAdapterDevice, PcNewServiceGroup, PcNewInterruptSync, PcInitializeAdapterDriver
> ntoskrnl.exe: strncmp, MmFreeContiguousMemory, MmAllocateContiguousMemory, MmGetPhysicalAddress
( 3 exports )
_ac3_decode_frame@4, _ac3_init@4, _get_frame_size@16
pour C:\windows\system32\drivers\PfModNT.sys
Fichier PfModNT.sys reçu le 2008.11.19 17:33:16 (CET)
Situation actuelle: terminé
Résultat: 0/36 (0.00%)
Formaté Formaté
Impression des résultats Impression des résultats
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.18.2 2008.11.19 -
AntiVir 7.9.0.34 2008.11.19 -
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 -
AVG 8.0.0.199 2008.11.19 -
BitDefender 7.2 2008.11.19 -
CAT-QuickHeal 10.00 2008.11.19 -
ClamAV 0.94.1 2008.11.19 -
DrWeb 4.44.0.09170 2008.11.19 -
eSafe 7.0.17.0 2008.11.19 -
eTrust-Vet 31.6.6217 2008.11.19 -
Ewido 4.0 2008.11.19 -
F-Prot 4.4.4.56 2008.11.18 -
F-Secure 8.0.14332.0 2008.11.19 -
Fortinet 3.117.0.0 2008.11.19 -
GData 19 2008.11.19 -
Ikarus T3.1.1.45.0 2008.11.19 -
K7AntiVirus 7.10.528 2008.11.19 -
Kaspersky 7.0.0.125 2008.11.19 -
McAfee 5438 2008.11.18 -
Microsoft 1.4104 2008.11.19 -
NOD32 3624 2008.11.19 -
Norman 5.80.02 2008.11.19 -
Panda 9.0.0.4 2008.11.19 -
PCTools 4.4.2.0 2008.11.19 -
Prevx1 V2 2008.11.19 -
Rising 21.04.22.00 2008.11.19 -
SecureWeb-Gateway 6.7.6 2008.11.19 -
Sophos 4.35.0 2008.11.19 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.19 -
TheHacker 6.3.1.1.158 2008.11.19 -
TrendMicro 8.700.0.1004 2008.11.19 -
VBA32 3.12.8.9 2008.11.19 -
ViRobot 2008.11.18.1474 2008.11.18 -
VirusBuster 4.5.11.0 2008.11.19 -
Information additionnelle
File size: 15840 bytes
MD5...: c8a2d6ff660ac601b7bb9a9b16a5c25e
SHA1..: f9fc00b53dec9040f5493060c251b8b630578f93
SHA256: bbf97622ab15943f614ae3901860de4b1380d5878fcc6eaa2384b4c9432c0b4b
SHA512: 7e2a6ccf478aa486dbfee51314d330dc542de6ddfd3f47a7d4987e5e8f1bef20
c04f1549d507faf63aa3d9b4a766a023862bced2328e2ef0ab618c6c9a83404e
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x10ae4
timedatestamp.....: 0x3e657ad0 (Wed Mar 05 04:19:28 2003)
machinetype.......: 0x14c (I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x2c0 0xae4 0xb00 6.20 fc83be8b3a6d950f00e0c0fb0d9abb7e
.rdata 0xdc0 0x6c 0x80 2.27 50c48f5b0b2e8e510c386829b92e23fa
.data 0xe40 0x2888 0x28a0 0.00 4b6926325b72261cbdc0c9bcb558b0e4
INIT 0x36e0 0x1fa 0x200 4.86 784a860445a618cdaaea22ececce0879
.rsrc 0x38e0 0x3f8 0x400 3.29 4103054a93267520887f94e24e16e570
.reloc 0x3ce0 0xb4 0xc0 3.93 e1367440c5324eb591c175499eea2a8f
( 2 imports )
> ntoskrnl.exe: IoDeleteDevice, IoCreateSymbolicLink, IoCreateDevice, RtlCopyUnicodeString, KeInitializeTimer, IoDeleteSymbolicLink, IoReportResourceUsage, IofCompleteRequest, ExAllocatePoolWithTag, ExFreePool, _alldiv, RtlInitUnicodeString, _allmul
> HAL.dll: HalSetBusDataByOffset, HalGetBusDataByOffset, KeQueryPerformanceCounter, HalGetBusData
( 0 exports )