Bonjour vieux bison boiteux,
J'ai fait le scan et voici le rapport :
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.12.10.2 2008.12.10 -
AntiVir 7.9.0.43 2008.12.10 TR/BHO.325120
Authentium 5.1.0.4 2008.12.10 -
Avast 4.8.1281.0 2008.12.10 -
AVG 8.0.0.199 2008.12.09 -
BitDefender 7.2 2008.12.10 Trojan.Generic.1212503
CAT-QuickHeal 10.00 2008.12.10 -
ClamAV 0.94.1 2008.12.10 Adware.AdRotator-10
Comodo 718 2008.12.10 -
DrWeb 4.44.0.09170 2008.12.10 -
eSafe 7.0.17.0 2008.12.09 -
eTrust-Vet 31.6.6253 2008.12.10 -
Ewido 4.0 2008.12.09 -
F-Prot 4.4.4.56 2008.12.10 -
F-Secure 8.0.14332.0 2008.12.10 -
Fortinet 3.117.0.0 2008.12.10 -
GData 19 2008.12.10 Trojan.Generic.1212503
Ikarus T3.1.1.45.0 2008.12.10 Trojan.BHO
K7AntiVirus 7.10.549 2008.12.09 -
Kaspersky 7.0.0.125 2008.12.10 -
McAfee 5459 2008.12.09 AdClicker-GI
McAfee+Artemis 5459 2008.12.09 AdClicker-GI
Microsoft 1.4205 2008.12.10 Adware:Win32/AdRotator
NOD32 3681 2008.12.10 probably a variant of Win32/Adware.GooochiBiz
Norman 5.80.02 2008.12.09 -
Panda 9.0.0.4 2008.12.09 Generic Trojan
PCTools 4.4.2.0 2008.12.09 -
Prevx1 V2 2008.12.10 Cloaked Malware
Rising 21.07.22.00 2008.12.10 Trojan.Win32.Undef.tdz
SecureWeb-Gateway 6.7.6 2008.12.10 Trojan.BHO.325120
Sophos 4.36.0 2008.12.10 SuperiorAds
Sunbelt 3.2.1801.2 2008.12.10 -
Symantec 10 2008.12.10 -
TheHacker 6.3.1.2.182 2008.12.10 -
TrendMicro 8.700.0.1004 2008.12.10 -
VBA32 3.12.8.10 2008.12.09 -
ViRobot 2008.12.10.1511 2008.12.10 -
VirusBuster 4.5.11.0 2008.12.09 Adware.Adrotator.Gen.2
Information additionnelle
File size: 325120 bytes
MD5...: 591a6037f0ce87500556d602b30528d6
SHA1..: 2784fb5ffd7d0589191bf7cc0aeb90e2cc1f8be5
SHA256: 9e4d7a1d8dc801a2c7a9bfeeffaa9028c6ed63615ed562b776cb3a6cbb054e6e
SHA512: 875536aaa0624d4a336d23d8335bb8d3a05f6427ca38af2e099ba1a2a4ce3c1f
cddbc7640688bfbef680d99ad06b3eb9b70fb89f3972b326daf73230d8d1367c
ssdeep: 6144:lbpmOz9GgRx9r/wpDAwRlnjHTogIPqwLAtiCu54+iOdSncKZ:lbpmOz8gRx
9r/0rRlnjHTHIPqweiV7i3
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1002d5d8
timedatestamp.....: 0x49253388 (Thu Nov 20 09:53:12 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3f311 0x3f400 6.47 367dda58118cb1b84673d7cce806b3cf
.rdata 0x41000 0x757f 0x7600 4.88 12b17df958ba8b90d9144fd0caf3b825
.data 0x49000 0x3b00 0x1600 3.56 40900456cc056cc215b00c6362d76a93
.rsrc 0x4d000 0x34c 0x400 4.69 cc872a35f28b7739ca3ce94c69702baf
.reloc 0x4e000 0x6d46 0x6e00 4.19 a5d773e3995570cc5bf9b10424c45ea4
( 8 imports )
> RPCRT4.dll: UuidToStringW, RpcStringFreeW
> SHLWAPI.dll: StrStrIW, SHDeleteKeyW, UrlEscapeW, StrCmpIW, PathStripPathW
> urlmon.dll: URLDownloadToFileW
> KERNEL32.dll: InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetProcAddress, LoadLibraryA, ExitThread, GetSystemTime, CreateEventW, CloseHandle, DeleteFileW, MoveFileExW, FreeLibrary, LoadLibraryW, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, GetStringTypeA, LCMapStringA, GetLocaleInfoA, InitializeCriticalSectionAndSpinCount, GetConsoleMode, GetConsoleCP, SetFilePointer, HeapReAlloc, VirtualAlloc, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, VirtualFree, HeapDestroy, HeapCreate, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, GetStringTypeW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetFileType, SetHandleCount, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetModuleFileNameA, GetStdHandle, WriteFile, GetModuleHandleA, ExitProcess, HeapSize, Sleep, RaiseException, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlUnwind, GetCurrentThreadId, GetCommandLineA, GetLastError, HeapFree, HeapAlloc, GetModuleHandleW, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, InterlockedDecrement, LCMapStringW
> USER32.dll: GetWindowTextW, EnumChildWindows, RealGetWindowClassW, CallWindowProcW, SetWindowLongW, SetPropW, GetWindowThreadProcessId, PostMessageW, SendMessageW, GetPropW, RemovePropW, OffsetRect, IntersectRect, InflateRect, ClientToScreen, SetWindowTextW, MsgWaitForMultipleObjects, PeekMessageW, TranslateMessage, DispatchMessageW, GetClassNameW, SetActiveWindow
> ADVAPI32.dll: RegQueryValueExW, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, SetSecurityInfo, RegOpenKeyExW, RegDeleteKeyW, RegQueryValueW, RegDeleteValueW, RegSetValueExW, RegCreateKeyW, RegCloseKey
> ole32.dll: CoTaskMemFree, CoCreateInstance, CoUninitialize, CoInitializeEx
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -
( 5 exports )
DllCanUnloadNow, DllGetClassObject, DllPreinstall, DllRegisterServer, DllUnregisterServer
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=8F9F589D00AB9BBFF6870407F72AF4000CB0E111' target='_blank'>http://info.prevx.com/...