Cette fois, je n'ai besoin que d'un avis concernant un fichier que j'ai fait analyser en ligne par VirusTotal. Je vous copie ci-dessous le résultat, et j'aimerais savoir ce que vous en pensez...
Bien sincèrement,
RV.
- Code: Tout sélectionner
a-squared 5.0.0.26 2010.05.31 -
AhnLab-V3 2010.05.30.00 2010.05.29 -
AntiVir 8.2.1.242 2010.05.31 Worm/AInfBot.BK.1
Antiy-AVL 2.0.3.7 2010.05.31 -
Authentium 5.2.0.5 2010.05.31 -
Avast 4.8.1351.0 2010.05.31 Win32:Trojan-gen
Avast5 5.0.332.0 2010.05.31 Win32:Trojan-gen
AVG 9.0.0.787 2010.05.31 -
BitDefender 7.2 2010.05.31 -
CAT-QuickHeal 10.00 2010.05.31 -
ClamAV 0.96.0.3-git 2010.05.31 -
Comodo 4965 2010.05.31 -
DrWeb 5.0.2.03300 2010.05.31 Trojan.PWS.Dybalom
eSafe 7.0.17.0 2010.05.30 -
eTrust-Vet 35.2.7522 2010.05.31 -
F-Prot 4.6.0.103 2010.05.31 -
F-Secure 9.0.15370.0 2010.05.31 -
Fortinet 4.1.133.0 2010.05.30 -
GData 21 2010.05.31 Win32:Trojan-gen
Ikarus T3.1.1.84.0 2010.05.31 -
Jiangmin 13.0.900 2010.05.30 -
Kaspersky 7.0.0.125 2010.05.31 Worm.Win32.AInfBot.bk
McAfee 5.400.0.1158 2010.05.31 -
McAfee-GW-Edition 2010.1 2010.05.31 Artemis!91B305B9CAC5
Microsoft 1.5802 2010.05.31 -
NOD32 5158 2010.05.31 a variant of Win32/Injector.BVU
Norman 6.04.12 2010.05.31 -
nProtect 2010-05-31.01 2010.05.31 -
Panda 10.0.2.7 2010.05.30 Suspicious file
PCTools 7.0.3.5 2010.05.31 -
Prevx 3.0 2010.05.31 -
Rising 22.50.00.04 2010.05.31 -
Sophos 4.53.0 2010.05.31 Mal/Generic-L
Sunbelt 6382 2010.05.31 -
Symantec 20101.1.0.89 2010.05.31 -
TheHacker 6.5.2.0.290 2010.05.31 -
TrendMicro 9.120.0.1004 2010.05.31 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.31 -
VBA32 3.12.12.5 2010.05.31 -
ViRobot 2010.5.31.2331 2010.05.31 -
VirusBuster 5.0.27.0 2010.05.31 -
Information additionnelle
File size: 1462272 bytes
MD5 : 91b305b9cac5271a25b1756829487e6d
SHA1 : b3dffc65efa200bcf947242d86bb368b87145c8a
SHA256: 24df72b3e5fc9d6f6dd3d183fce829600e544c4e70ff37fd79de70a11754dfbf
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x17D8
timedatestamp.....: 0x4BFF8587 (Fri May 28 10:57:43 2010)
machinetype.......: 0x14C (Intel I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xE3DC 0xF000 5.38 4442dd8a0469de17d33ab86bb2af80c5
.data 0x10000 0x964 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x11000 0x1537F8 0x154000 7.91 44ad86ef68070efd2f35267a67e24774
( 1 imports )
> msvbvm60.dll: __vbaVarSub, __vbaStrI2, _CIcos, _adj_fptan, __vbaVarMove, __vbaFreeVar, __vbaAryMove, __vbaLenBstr, __vbaStrVarMove, __vbaFreeVarList, _adj_fdiv_m64, -, _adj_fprem1, __vbaRecAnsiToUni, -, __vbaStrCat, __vbaLsetFixstr, __vbaSetSystemError, __vbaRecDestruct, __vbaHresultCheckObj, _adj_fdiv_m32, -, __vbaAryVar, __vbaAryDestruct, -, -, __vbaOnError, -, _adj_fdiv_m16i, _adj_fdivr_m16i, -, -, _CIsin, -, __vbaErase, __vbaVarCmpGt, __vbaVarZero, -, __vbaChkstk, __vbaFileClose, __vbaGenerateBoundsError, __vbaStrCmp, __vbaPutOwner3, __vbaVarTstEq, __vbaAryConstruct2, __vbaI2I4, DllFunctionCall, __vbaRedimPreserve, _adj_fpatan, __vbaFixstrConstruct, __vbaRedim, __vbaUI1ErrVar, __vbaRecUniToAnsi, __vbaUI1I2, _CIsqrt, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, -, __vbaFPException, __vbaInStrVar, -, __vbaGetOwner3, __vbaUbound, __vbaStrVarVal, __vbaVarCat, -, -, _CIlog, __vbaErrorOverflow, __vbaFileOpen, __vbaR8Str, -, __vbaNew2, __vbaInStr, __vbaVar2Vec, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaI4Str, -, __vbaFreeStrList, __vbaDerefAry1, _adj_fdivr_m32, _adj_fdiv_r, -, -, __vbaI4Var, __vbaVarCmpEq, __vbaAryLock, __vbaStrToAnsi, __vbaVarDup, __vbaAryVarVarg, __vbaFpI4, __vbaRecDestructAnsi, -, _CIatan, __vbaStrMove, __vbaAryCopy, -, __vbaStrVarCopy, _allmul, _CItan, __vbaAryUnlock, __vbaFPInt, _CIexp, __vbaFreeObj, __vbaFreeStr
( 0 exports )
TrID : File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
Symantec reputation: Suspicious.Insight http://www.symantec.com/security_response/writeup.jsp?docid=2010-021223-0550-99
ssdeep: 24576:Gbk6gx8EvFtnveKn1BX/OT2WlABXNwWdepzKurH/k5xyMi0BYawnei:P8Ev6K1BXz6AEHpmu7WxPDBYaw
sigcheck: publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEiD : -
RDS : NSRL Reference Data Set
-