Les rapport de virustotal
rapport C:Program Filesagicommonagservice.exe :
je n'ai pas trouver ce fichier
rapport C:WINDOWSmondrv411.exe :
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.1.0 2008.10.31 -
AntiVir 7.9.0.10 2008.10.31 TR/Agent.PR.16
Authentium 5.1.0.4 2008.11.01 -
Avast 4.8.1248.0 2008.11.01 -
AVG 8.0.0.161 2008.11.01 -
BitDefender 7.2 2008.11.01 -
CAT-QuickHeal 9.50 2008.11.01 -
ClamAV 0.94.1 2008.11.01 -
DrWeb 4.44.0.09170 2008.11.01 -
eSafe 7.0.17.0 2008.10.30 -
eTrust-Vet 31.6.6185 2008.11.01 -
Ewido 4.0 2008.11.01 -
F-Prot 4.4.4.56 2008.10.31 -
F-Secure 8.0.14332.0 2008.11.01 -
Fortinet 3.117.0.0 2008.10.31 -
GData 19 2008.11.01 -
Ikarus T3.1.1.44.0 2008.11.01 Trojan.Win32.Reppop.A
K7AntiVirus 7.10.514 2008.11.01 -
Kaspersky 7.0.0.125 2008.11.01 -
McAfee 5420 2008.11.01 -
Microsoft 1.4005 2008.11.01 Trojan:Win32/Reppop.A
NOD32 3575 2008.10.31 -
Norman 5.80.02 2008.10.31 -
Panda 9.0.0.4 2008.11.01 -
PCTools 4.4.2.0 2008.11.01 -
Prevx1 V2 2008.11.01 Cloaked Malware
Rising 21.01.52.00 2008.11.01 -
SecureWeb-Gateway 6.7.6 2008.11.01 Trojan.Agent.PR.16
Sophos 4.35.0 2008.11.01 -
Sunbelt 3.1.1767.2 2008.10.31 -
Symantec 10 2008.11.01 -
TheHacker 6.3.1.1.135 2008.10.31 -
TrendMicro 8.700.0.1004 2008.10.31 -
VBA32 3.12.8.9 2008.11.01 suspected of Trojan-PSW.Lmir.14 (paranoid heuristics)
ViRobot 2008.10.31.1446 2008.10.31 -
VirusBuster 4.5.11.0 2008.10.31 -
Information additionnelle
File size: 1601536 bytes
MD5...: de1a3c2a708afb3a25dac850f0cd7ab4
SHA1..: d3aea314572df3a51580c2c37ba1bbaf33d589d7
SHA256: 64698b0bec29bc9e9952544668229cdb61cd32c22716067963b4fe7e86b928bb
SHA512: 8bf86e7704844c4b4250602980d55228bb3e507fff001a3eecba3cdaa6655b71<BR>36a3527b25c7b50256c8a880c5f94becbe6ae2ba3d9c4d83641a93788f697589
PEiD..: -
TrID..: File type identification<BR>Win32 Executable Microsoft Visual Basic 6 (90.9%)<BR>Win32 Executable Generic (6.1%)<BR>Generic Win/DOS Executable (1.4%)<BR>DOS Executable Generic (1.4%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x401a74<BR>timedatestamp.....: 0x4900f8e3 (Thu Oct 23 22:21:23 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x117d0 0x12000 5.76 e6699a726abfc5f6b07c1177d5d2632a<BR>.data 0x13000 0xe98 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110<BR>.rsrc 0x14000 0x172ac8 0x173000 4.43 d3e084858987dc32e0f7aab404b8614d<BR><BR>( 1 imports ) <BR>> MSVBVM60.DLL: EVENT_SINK_GetIDsOfNames, __vbaVarSub, __vbaVarTstGt, __vbaStrI2, __vbaNextEachAry, _CIcos, _adj_fptan, __vbaVarMove, __vbaStrI4, __vbaVarVargNofree, __vbaAryMove, __vbaFreeVar, __vbaLineInputStr, __vbaStrVarMove, __vbaLenBstr, __vbaFreeVarList, __vbaEnd, _adj_fdiv_m64, EVENT_SINK_Invoke, -, __vbaFreeObjList, -, _adj_fprem1, -, __vbaStrCat, __vbaLsetFixstr, -, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, Zombie_GetTypeInfo, __vbaAryDestruct, __vbaVarForInit, __vbaForEachCollObj, -, __vbaExitProc, -, -, -, __vbaOnError, __vbaObjSet, _adj_fdiv_m16i, __vbaObjSetAddref, _adj_fdivr_m16i, -, -, __vbaStrFixstr, __vbaBoolVar, __vbaForEachCollVar, -, __vbaVarTstLt, __vbaBoolVarNull, _CIsin, -, -, __vbaNextEachCollObj, -, -, __vbaChkstk, -, __vbaFileClose, EVENT_SINK_AddRef, __vbaGenerateBoundsError, __vbaStrCmp, __vbaVarTstEq, __vbaAryConstruct2, __vbaNextEachCollVar, -, __vbaI2I4, DllFunctionCall, __vbaVarOr, __vbaCastObjVar, __vbaRedimPreserve, _adj_fpatan, Zombie_GetTypeInfoCount, __vbaStrR8, __vbaRedim, EVENT_SINK_Release, __vbaNew, __vbaUI1I2, _CIsqrt, __vbaObjIs, __vbaVarAnd, EVENT_SINK_QueryInterface, __vbaExceptHandler, __vbaStrToUnicode, -, __vbaPrintFile, _adj_fprem, _adj_fdivr_m64, __vbaVarDiv, -, -, -, __vbaFPException, __vbaInStrVar, -, -, __vbaStrVarVal, __vbaUbound, __vbaVarCat, __vbaDateVar, -, __vbaLsetFixstrFree, __vbaI2Var, -, _CIlog, __vbaErrorOverflow, __vbaFileOpen, __vbaVar2Vec, __vbaInStr, -, -, __vbaNew2, -, _adj_fdiv_m32i, _adj_fdivr_m32i, -, __vbaStrCopy, __vbaVarNot, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, -, -, __vbaVarTstNe, __vbaI4Var, __vbaForEachAry, __vbaVarCmpEq, __vbaVarAdd, -, __vbaVarDup, __vbaStrToAnsi, __vbaStrComp, -, -, __vbaVarCopy, __vbaFpI4, -, _CIatan, __vbaCastObj, __vbaStrMove, -, __vbaR8IntI4, __vbaStrVarCopy, _allmul, _CItan, -, __vbaAryUnlock, __vbaFPInt, __vbaVarForNext, _CIexp, __vbaI4ErrVar, __vbaFreeStr, __vbaFreeObj<BR><BR>( 0 exports ) <BR>
Prevx info:
http://info.prevx.com/aboutprogramtext. ... 0041F5EFE8
rapport c:windowssystem32
kwnw64k.exe :
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.1.0 2008.11.01 -
AntiVir 7.9.0.10 2008.10.31 TR/Dropper.Gen
Authentium 5.1.0.4 2008.11.01 -
Avast 4.8.1248.0 2008.11.01 Win32:Trojan-gen {Other}
AVG 8.0.0.161 2008.11.01 -
BitDefender 7.2 2008.11.01 Trojan.Agent.AKVY
CAT-QuickHeal 9.50 2008.11.01 -
ClamAV 0.94.1 2008.11.01 -
DrWeb 4.44.0.09170 2008.11.01 -
eSafe 7.0.17.0 2008.10.30 -
eTrust-Vet 31.6.6185 2008.11.01 -
Ewido 4.0 2008.11.01 -
F-Prot 4.4.4.56 2008.11.01 -
Fortinet 3.117.0.0 2008.10.31 -
GData 19 2008.11.01 Trojan.Agent.AKVY
Ikarus T3.1.1.44.0 2008.11.01 Virus.Win32.VB.DAV
K7AntiVirus 7.10.514 2008.11.01 -
Kaspersky 7.0.0.125 2008.11.01 Trojan.Win32.Agent.alld
McAfee 5420 2008.11.01 -
Microsoft 1.4005 2008.11.01 -
Norman 5.80.02 2008.10.31 -
Panda 9.0.0.4 2008.11.01 -
PCTools 4.4.2.0 2008.11.01 -
Rising 21.01.52.00 2008.11.01 -
SecureWeb-Gateway 6.7.6 2008.11.01 Trojan.Dropper.Gen
Sophos 4.35.0 2008.11.01 -
Sunbelt 3.1.1767.2 2008.10.31 -
Symantec 10 2008.11.01 -
TheHacker 6.3.1.1.135 2008.10.31 -
TrendMicro 8.700.0.1004 2008.10.31 -
VBA32 3.12.8.9 2008.11.01 -
ViRobot 2008.10.31.1446 2008.10.31 -
VirusBuster 4.5.11.0 2008.10.31 -
Information additionnelle
File size: 262164 bytes
MD5...: c1a7f0f1d901fc6d4d77bc6c48593b04
SHA1..: 1e5c66d9f3041650d17c66774f1a8df6b6cd9d82
SHA256: 2147e33f9aaded122208a2b134425f03b7e44d00b94ea8cdae850079b21d9e64
SHA512: 0159a44c54978fa1d859b0510defcf4ef4e73a77b70a11627fa7095e6e313a51<BR>00bddf54b06c709332ea2665f42f403e0b1945833791672222c171db2f8f3eb8
PEiD..: -
TrID..: File type identification<BR>Win32 Executable Generic (68.0%)<BR>Generic Win/DOS Executable (15.9%)<BR>DOS Executable Generic (15.9%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x4010b8<BR>timedatestamp.....: 0x48e24a39 (Tue Sep 30 15:48:09 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x7f84 0x8000 5.82 30c2921ab149a7ef0eed1c4372f92aeb<BR>.data 0x9000 0xcc8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>.rsrc 0xa000 0x5168 0x6000 5.42 940ea870337e549611aaa18dad0e6c9a<BR><BR>( 1 imports ) <BR>> MSVBVM60.DLL: -, -, -, -, -, -, EVENT_SINK_AddRef, DllFunctionCall, EVENT_SINK_Release, -, EVENT_SINK_QueryInterface, __vbaExceptHandler, -, ProcCallEngine, -, -, -<BR><BR>( 0 exports ) <BR>
rapport C:Documents and SettingsHP_Propriétaire.MOIIApplication Data mobd.exe :
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.1.0 2008.11.01 -
AntiVir 7.9.0.10 2008.10.31 -
Authentium 5.1.0.4 2008.11.01 -
Avast 4.8.1248.0 2008.11.01 -
AVG 8.0.0.161 2008.11.01 -
BitDefender 7.2 2008.11.01 -
CAT-QuickHeal 9.50 2008.11.01 -
ClamAV 0.94.1 2008.11.01 -
DrWeb 4.44.0.09170 2008.11.01 -
eSafe 7.0.17.0 2008.10.30 Suspicious File
eTrust-Vet 31.6.6185 2008.11.01 -
Ewido 4.0 2008.11.01 -
F-Prot 4.4.4.56 2008.11.01 -
F-Secure 8.0.14332.0 2008.11.01 -
Fortinet 3.117.0.0 2008.10.31 -
GData 19 2008.11.01 -
Ikarus T3.1.1.44.0 2008.11.01 -
K7AntiVirus 7.10.514 2008.11.01 -
Kaspersky 7.0.0.125 2008.11.01 -
McAfee 5420 2008.11.01 -
Microsoft 1.4005 2008.11.01 -
NOD32 3575 2008.10.31 -
Norman 5.80.02 2008.10.31 -
Panda 9.0.0.4 2008.11.01 -
PCTools 4.4.2.0 2008.11.01 -
Prevx1 V2 2008.11.01 Adware
Rising 21.01.52.00 2008.11.01 -
SecureWeb-Gateway 6.7.6 2008.11.01 -
Sophos 4.35.0 2008.11.01 -
Sunbelt 3.1.1767.2 2008.10.31 -
Symantec 10 2008.11.01 -
TheHacker 6.3.1.1.135 2008.10.31 -
TrendMicro 8.700.0.1004 2008.10.31 -
VBA32 3.12.8.9 2008.11.01 -
ViRobot 2008.10.31.1446 2008.10.31 -
VirusBuster 4.5.11.0 2008.10.31 -
Information additionnelle
File size: 2438299 bytes
MD5...: eb77b6dd3fbe8404d2188c71c96d42f7
SHA1..: 70191b9d65e79280236e6603a8d66d7ba7d1435a
SHA256: cf56964eaa76f200dcc70a18f8ee6160bc0392a656fb9f754f9b35fdf3e4bfbc
SHA512: 854aeb920e70f7ae4ff12a83a3731540ccb4c7ceed4da3bc270f332a33f1bae2<BR>f066d71d18a92652d2550c9a5ffbef415e49220823349e57456dfbebcf31fbc9
PEiD..: -
TrID..: File type identification<BR>UPX compressed Win32 Executable (39.5%)<BR>Win32 EXE Yoda's Crypter (34.3%)<BR>Win32 Executable Generic (11.0%)<BR>Win32 Dynamic Link Library (generic) (9.8%)<BR>Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x41a0d0<BR>timedatestamp.....: 0x44fd6e58 (Tue Sep 05 12:32:24 2006)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>UPX0 0x1000 0xe000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<BR>UPX1 0xf000 0xc000 0xb400 7.90 77d4d376105d2d3c4289c6261353a09d<BR>.rsrc 0x1b000 0x1000 0x800 4.46 6697db56186e616f0c22a90fb05315ef<BR><BR>( 4 imports ) <BR>> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess<BR>> COMCTL32.dll: -<BR>> USER32.dll: MessageBoxA<BR>> WS2_32.dll: -<BR><BR>( 0 exports ) <BR>
Prevx info:
http://info.prevx.com/aboutprogramtext. ... 0054434EED
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
rapport C:Program Filesagicommon\_agcutils.pyd :
je ne trouve pas ce fichier
rapport C:WINDOWSsystem32ukpolyhasqbycqzc.dll
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.1.0 2008.11.01 -
AntiVir 7.9.0.10 2008.10.31 -
Authentium 5.1.0.4 2008.11.01 -
Avast 4.8.1248.0 2008.11.01 -
AVG 8.0.0.161 2008.11.01 -
BitDefender 7.2 2008.11.01 -
CAT-QuickHeal 9.50 2008.11.01 -
ClamAV 0.94.1 2008.11.01 -
DrWeb 4.44.0.09170 2008.11.01 -
eSafe 7.0.17.0 2008.10.30 -
eTrust-Vet 31.6.6185 2008.11.01 -
Ewido 4.0 2008.11.01 -
F-Prot 4.4.4.56 2008.11.01 -
F-Secure 8.0.14332.0 2008.11.01 -
Fortinet 3.117.0.0 2008.10.31 Adware/AdClicker
GData 19 2008.11.01 -
Ikarus T3.1.1.44.0 2008.11.01 -
K7AntiVirus 7.10.514 2008.11.01 -
Kaspersky 7.0.0.125 2008.11.01 -
McAfee 5420 2008.11.01 -
Microsoft 1.4005 2008.11.01 -
NOD32 3575 2008.10.31 -
Norman 5.80.02 2008.10.31 -
Panda 9.0.0.4 2008.11.01 -
PCTools 4.4.2.0 2008.11.01 -
Prevx1 V2 2008.11.01 -
Rising 21.01.52.00 2008.11.01 -
SecureWeb-Gateway 6.7.6 2008.11.01 -
Sophos 4.35.0 2008.11.01 -
Sunbelt 3.1.1767.2 2008.10.31 -
Symantec 10 2008.11.01 -
TheHacker 6.3.1.1.135 2008.10.31 -
TrendMicro 8.700.0.1004 2008.10.31 -
VBA32 3.12.8.9 2008.11.01 -
ViRobot 2008.10.31.1446 2008.10.31 -
VirusBuster 4.5.11.0 2008.10.31 -
Information additionnelle
File size: 178176 bytes
MD5...: c74c12d25bcc9645a02e3bc61d1db0f6
SHA1..: a91633fc68cc32e9e372b046e51d7767175d150f
SHA256: 8fc742a0e1b4ae269c421a55cb06c6d586a99c3bcf934b9379502afcb3275b12
SHA512: 4940ba745ae22d6ac5a08f66597e701c3306e94529de1036a66dadfd427e6647<BR>6745d468327785ed042c9479240fff7f8bcaf72001ea54330116149fac7eb077
PEiD..: -
TrID..: File type identification<BR>Win64 Executable Generic (59.6%)<BR>Win32 Executable MS Visual C++ (generic) (26.2%)<BR>Win32 Executable Generic (5.9%)<BR>Win32 Dynamic Link Library (generic) (5.2%)<BR>Generic Win/DOS Executable (1.3%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x100137f8<BR>timedatestamp.....: 0x490c2372 (Sat Nov 01 09:37:54 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x20c20 0x20e00 6.58 0c120bf3e939e92e441e5a2061392795<BR>.rdata 0x22000 0x6267 0x6400 5.26 c79181a22240e537b8df592b321bc771<BR>.data 0x29000 0x30a0 0x1600 3.54 f2d2f2d1c742560d34a6d3efc8494e06<BR>.rsrc 0x2d000 0x34c 0x400 4.69 78c79b2295c89456e7d8e51fcd1b7ce1<BR>.reloc 0x2e000 0x26c4 0x2800 4.84 08d9a75eb9f1df08e2d7dc1f72f7cd85<BR><BR>( 8 imports ) <BR>> RPCRT4.dll: UuidToStringW, RpcStringFreeW<BR>> VERSION.dll: VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW<BR>> SHLWAPI.dll: StrCmpIW, StrStrIW, PathStripPathW, UrlEscapeW, SHDeleteKeyW<BR>> KERNEL32.dll: ExitThread, WaitForSingleObject, CreateThread, Sleep, GetModuleFileNameW, OpenMutexW, GetSystemTime, CreateEventW, OpenProcess, CreateMutexW, GetLastError, InterlockedIncrement, InterlockedDecrement, lstrcmpW, GetTickCount, SystemTimeToFileTime, GetLocalTime, LocalFree, LoadLibraryA, FreeLibrary, ExpandEnvironmentStringsW, WideCharToMultiByte, MultiByteToWideChar, GetTempFileNameW, GetEnvironmentVariableW, LocalAlloc, VirtualQuery, GetVolumeInformationW, LoadLibraryW, GetSystemInfo, GetStringTypeW, GetStringTypeA, LCMapStringA, GetLocaleInfoA, InitializeCriticalSectionAndSpinCount, GetConsoleMode, GetConsoleCP, SetFilePointer, HeapReAlloc, VirtualAlloc, GetSystemTimeAsFileTime, GetCurrentProcessId, QueryPerformanceCounter, VirtualFree, HeapDestroy, HeapCreate, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetProcAddress, CreateProcessW, CloseHandle, SetEvent, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, lstrlenW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, GetWindowsDirectoryW, GetFileType, SetHandleCount, LCMapStringW, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetModuleFileNameA, GetStdHandle, WriteFile, ExitProcess, HeapSize, GetModuleHandleA, SetLastError, TlsFree, TlsSetValue, RaiseException, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlUnwind, GetCurrentThreadId, GetCommandLineA, HeapFree, HeapAlloc, GetModuleHandleW, TlsGetValue, TlsAlloc<BR>> USER32.dll: GetWindowTextW, EnumChildWindows, RealGetWindowClassW, CallWindowProcW, SetWindowLongW, GetWindowThreadProcessId, SetActiveWindow, SendMessageW, GetPropW, RemovePropW, SetWindowTextW, SetPropW, IntersectRect, InflateRect, ClientToScreen, MsgWaitForMultipleObjects, PeekMessageW, TranslateMessage, DispatchMessageW, GetClassNameW, PostMessageW, OffsetRect<BR>> ADVAPI32.dll: CryptCreateHash, CryptGetHashParam, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, SetSecurityInfo, CryptGenRandom, CryptAcquireContextW, CryptHashData, CryptDestroyHash, CryptReleaseContext, RegQueryValueExW, RegCreateKeyW, RegCreateKeyExW, RegSetValueW, RegDeleteValueW, RegOpenKeyExW, RegSetValueExW, RegCloseKey<BR>> ole32.dll: CoInitializeEx, CoCreateInstance, CoTaskMemFree, CoUninitialize<BR>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -<BR><BR>( 4 exports ) <BR>DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer<BR>
rapport C:Program FilesWindows LiveMessengerwlchtc.dll :
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.9.23.1 2008.09.24 -
AntiVir 7.8.1.34 2008.09.24 -
Authentium 5.1.0.4 2008.09.23 -
Avast 4.8.1195.0 2008.09.23 -
AVG 8.0.0.161 2008.09.24 -
BitDefender 7.2 2008.09.24 -
CAT-QuickHeal 9.50 2008.09.24 -
ClamAV 0.93.1 2008.09.24 -
DrWeb 4.44.0.09170 2008.09.24 -
eSafe 7.0.17.0 2008.09.24 -
eTrust-Vet 31.6.6103 2008.09.24 -
Ewido 4.0 2008.09.24 -
F-Prot 4.4.4.56 2008.09.23 -
F-Secure 8.0.14332.0 2008.09.24 -
Fortinet 3.113.0.0 2008.09.23 -
GData 19 2008.09.24 -
Ikarus T3.1.1.34.0 2008.09.24 -
K7AntiVirus 7.10.470 2008.09.24 -
Kaspersky 7.0.0.125 2008.09.24 -
McAfee 5390 2008.09.23 -
Microsoft 1.3903 2008.09.24 -
NOD32 3468 2008.09.24 -
Norman 5.80.02 2008.09.23 -
Panda 9.0.0.4 2008.09.24 -
PCTools 4.4.2.0 2008.09.24 -
Prevx1 V2 2008.09.24 -
Rising 20.63.22.00 2008.09.24 -
Sophos 4.33.0 2008.09.24 -
Sunbelt 3.1.1666.1 2008.09.24 -
Symantec 10 2008.09.24 -
TheHacker 6.3.0.9.092 2008.09.24 -
TrendMicro 8.700.0.1004 2008.09.24 -
VBA32 3.12.8.5 2008.09.23 -
ViRobot 2008.9.24.1390 2008.09.24 -
VirusBuster 4.5.11.0 2008.09.24 -
Webwasher-Gateway 6.6.2 2008.09.24 -
Information additionnelle
File size: 75272 bytes
MD5...: 6ba2cd421d1fe739c461706efbd25754
SHA1..: 0202bf957c6d24d374a1f597eefc00cf918881dd
SHA256: d3626a54150788faf65c934184b023bc7b420e451e7d548489ae2e5acf243225
SHA512: 2853a32eb9076dc36ec88b0c3358b78d4be0c25ef9ff3a22c756107f302f77d9<BR>c0e8759875b197fd08fa34d5872eb0281503cf1b84c21a70bd1c86373aa8becb
PEiD..: -
TrID..: File type identification<BR>DirectShow filter (43.0%)<BR>Windows OCX File (26.3%)<BR>Win64 Executable Generic (18.2%)<BR>Win32 Executable MS Visual C++ (generic) (8.0%)<BR>Win32 Executable Generic (1.8%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x409a98<BR>timedatestamp.....: 0x48be0bc2 (Wed Sep 03 04:00:02 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0xb193 0xb200 6.18 561bfd731423f6d51a842d736fdc524d<BR>.data 0xd000 0x91c 0x600 3.98 2a14eb56c6a01a39466e1814737bed86<BR>.rsrc 0xe000 0x39e0 0x3a00 3.54 fbee300e7749bb478acab95d0f2e7387<BR>.reloc 0x12000 0xbbc 0xc00 5.87 1a04660f32c01081bdf4b82dac4728bb<BR><BR>( 6 imports ) <BR>> MSVCR80.dll: _crt_debugger_hook, __type_info_dtor_internal_method@type_info@@QAEXXZ, __clean_type_info_names_internal, _onexit, _lock, __dllonexit, _unlock, _except_handler4_common, _terminate@@YAXXZ, __CppXcptFilter, _adjust_fdiv, _amsg_exit, _initterm_e, _initterm, _decode_pointer, _encoded_null, _malloc_crt, _encode_pointer, _wcslwr_s, wcscat_s, wcscpy_s, isdigit, ___V@YAXPAX@Z, iswspace, iswalpha, __2@YAPAXI@Z, _recalloc, _purecall, _CxxThrowException, memset, __CxxFrameHandler3, towupper, vswprintf_s, _vscwprintf, memcpy_s, malloc, free, memmove_s, wcsncpy_s, _wcsicmp, wcsstr, wcschr, __3@YAXPAX@Z<BR>> KERNEL32.dll: IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, InterlockedCompareExchange, Sleep, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetLocaleInfoA, GetACP, InterlockedExchange, GetModuleHandleA, GetModuleHandleW, GetProcAddress, GetFileAttributesW, GetVersion, lstrlenW, RaiseException, InitializeCriticalSection, DeleteCriticalSection, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, GetLastError, lstrcmpiW, LoadLibraryW, SetLastError, GetModuleFileNameW, OutputDebugStringA, LoadLibraryExW, InterlockedIncrement, InterlockedDecrement, FreeLibrary, MultiByteToWideChar, EnterCriticalSection, LeaveCriticalSection, SetThreadLocale, GetThreadLocale<BR>> USER32.dll: UnregisterClassA, CharNextW<BR>> ADVAPI32.dll: RegFlushKey, RegQueryValueExW, RegCreateKeyW, RegOpenKeyW, RegDeleteValueW, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteKeyW<BR>> ole32.dll: CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, StringFromGUID2, CoCreateInstance<BR>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -<BR><BR>( 4 exports ) <BR>DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer<BR>
rapport C:WINDOWSSystem32
egsvr32.exe
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.1.0 2008.11.01 -
AntiVir 7.9.0.10 2008.10.31 -
Authentium 5.1.0.4 2008.11.01 -
Avast 4.8.1248.0 2008.11.01 -
AVG 8.0.0.161 2008.11.01 -
BitDefender 7.2 2008.11.01 -
CAT-QuickHeal 9.50 2008.11.01 -
ClamAV 0.94.1 2008.11.01 -
DrWeb 4.44.0.09170 2008.11.01 -
eSafe 7.0.17.0 2008.10.30 -
eTrust-Vet 31.6.6185 2008.11.01 -
Ewido 4.0 2008.11.01 -
F-Prot 4.4.4.56 2008.11.01 -
F-Secure 8.0.14332.0 2008.11.01 -
Fortinet 3.117.0.0 2008.10.31 -
GData 19 2008.11.01 -
Ikarus T3.1.1.44.0 2008.11.01 -
K7AntiVirus 7.10.514 2008.11.01 -
Kaspersky 7.0.0.125 2008.11.01 -
McAfee 5420 2008.11.01 -
Microsoft 1.4005 2008.11.01 -
NOD32 3575 2008.10.31 -
Norman 5.80.02 2008.10.31 -
Panda 9.0.0.4 2008.11.01 -
PCTools 4.4.2.0 2008.11.01 -
Rising 21.01.52.00 2008.11.01 -
SecureWeb-Gateway 6.7.6 2008.11.01 -
Sophos 4.35.0 2008.11.01 -
Sunbelt 3.1.1767.2 2008.10.31 -
Symantec 10 2008.11.01 -
TheHacker 6.3.1.1.135 2008.10.31 -
TrendMicro 8.700.0.1004 2008.10.31 -
VBA32 3.12.8.9 2008.11.01 -
ViRobot 2008.10.31.1446 2008.10.31 -
VirusBuster 4.5.11.0 2008.10.31 -
Information additionnelle
File size: 12288 bytes
MD5...: 9e243ecd2de787de5033f80bf14df17f
SHA1..: 2a28e455ebdeae69deb2a4a220d72a91840be222
SHA256: 4c2951d518e30588a451583e99fb242cce0b9bdbf676dbf9a700022436667488
SHA512: 9aabf9853971c460c2f0ccaec6f3921ece48e1e77181154014c54d98d5682b32<BR>d68e195085dff6a7a047e928e6d3505cb9beb6e3535e83ef906caf3a225bd722
PEiD..: -
TrID..: File type identification<BR>Win32 Executable Generic (42.3%)<BR>Win32 Dynamic Link Library (generic) (37.6%)<BR>Generic Win/DOS Executable (9.9%)<BR>DOS Executable Generic (9.9%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x1002327<BR>timedatestamp.....: 0x4802543f (Sun Apr 13 18:43:11 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x1ad8 0x1c00 5.94 7b0612df22d18ed546bcf2bc8d95a9ab<BR>.data 0x3000 0x42c 0x200 1.24 f3191982f025c39a4245004017cf6071<BR>.rsrc 0x4000 0xc30 0xe00 3.96 4117521d712bd5bb1e1753e621a263f9<BR><BR>( 5 imports ) <BR>> msvcrt.dll: _controlfp, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __wgetmainargs, exit, _cexit, _XcptFilter, _exit, _c_exit, _except_handler3, __argc, __wargv, _wsplitpath, _wcmdln, wcslen<BR>> ADVAPI32.dll: RegQueryValueW, RegCloseKey, RegOpenKeyExW<BR>> KERNEL32.dll: SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, GetModuleHandleA, LocalAlloc, FormatMessageW, SetErrorMode, lstrcatA, WideCharToMultiByte, LoadLibraryExW, GetLastError, GetProcAddress, lstrcmpW, GetStartupInfoW, QueryPerformanceCounter, lstrlenW, lstrcpyW, lstrcatW, lstrcpynW, FreeLibrary<BR>> USER32.dll: LoadStringW, MessageBoxW, wsprintfW<BR>> ole32.dll: OleInitialize, OleUninitialize<BR><BR>( 0 exports ) <BR>
rapport C:Program Filesppcboosterppcb_32.exe
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.1.0 2008.10.31 -
AntiVir 7.9.0.10 2008.10.31 HEUR/Malware
Authentium 5.1.0.4 2008.11.01 -
Avast 4.8.1248.0 2008.11.01 -
AVG 8.0.0.161 2008.11.01 -
BitDefender 7.2 2008.11.01 -
CAT-QuickHeal 9.50 2008.11.01 -
ClamAV 0.94.1 2008.11.01 -
DrWeb 4.44.0.09170 2008.11.01 -
eSafe 7.0.17.0 2008.10.30 -
eTrust-Vet 31.6.6185 2008.11.01 -
Ewido 4.0 2008.11.01 -
F-Prot 4.4.4.56 2008.10.31 -
F-Secure 8.0.14332.0 2008.11.01 -
Fortinet 3.117.0.0 2008.10.31 -
GData 19 2008.11.01 -
Ikarus T3.1.1.44.0 2008.11.01 -
K7AntiVirus 7.10.514 2008.11.01 -
Kaspersky 7.0.0.125 2008.11.01 -
McAfee 5420 2008.11.01 -
Microsoft 1.4005 2008.11.01 TrojanDownloader:Win32/Lwsta.A
NOD32 3575 2008.10.31 -
Norman 5.80.02 2008.10.31 -
Panda 9.0.0.4 2008.11.01 -
PCTools 4.4.2.0 2008.11.01 -
Prevx1 V2 2008.11.01 -
Rising 21.01.52.00 2008.11.01 -
SecureWeb-Gateway 6.7.6 2008.11.01 Heuristic.Malware
Sophos 4.35.0 2008.11.01 -
Sunbelt 3.1.1767.2 2008.10.31 -
Symantec 10 2008.11.01 -
TheHacker 6.3.1.1.135 2008.10.31 -
TrendMicro 8.700.0.1004 2008.10.31 -
VBA32 3.12.8.9 2008.11.01 -
ViRobot 2008.10.31.1446 2008.10.31 -
VirusBuster 4.5.11.0 2008.10.31 -
Information additionnelle
File size: 24576 bytes
MD5...: a60457da886d0a2c6d44c349814eaf2a
SHA1..: a70adb02e888cb16733066b47f2b629516f5ed84
SHA256: cad304b5822256c6c2000142d92153b8630262314bdd2e0cbe794ee63b0ab16f
SHA512: 7f12dd662ce7dc9187516f32b1dc45e3b5aa81ea87e612080a08dcd1a88d27a9<BR>34465297fe89921b9475193184454a7def750b6fd33d9275b6b0e74940b23cf5
PEiD..: -
TrID..: File type identification<BR>Win32 Executable Microsoft Visual Basic 6 (90.9%)<BR>Win32 Executable Generic (6.1%)<BR>Generic Win/DOS Executable (1.4%)<BR>DOS Executable Generic (1.4%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x401374<BR>timedatestamp.....: 0x490751b6 (Tue Oct 28 17:53:58 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x23c0 0x3000 4.39 2407205d49129204a18afe0bdc279f68<BR>.data 0x4000 0xa50 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110<BR>.rsrc 0x5000 0x8e0 0x1000 1.94 75016dd2b726cdfc3c731a7ccfc32797<BR><BR>( 1 imports ) <BR>> MSVBVM60.DLL: _CIcos, _adj_fptan, __vbaStrI4, __vbaFreeVar, __vbaLenBstr, _adj_fdiv_m64, _adj_fprem1, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, __vbaAryDestruct, __vbaOnError, __vbaObjSet, _adj_fdiv_m16i, _adj_fdivr_m16i, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, -, __vbaGenerateBoundsError, __vbaStrCmp, __vbaObjVar, DllFunctionCall, _adj_fpatan, __vbaRedim, EVENT_SINK_Release, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, __vbaStrToUnicode, -, _adj_fprem, _adj_fdivr_m64, -, __vbaFPException, __vbaStrVarVal, _CIlog, __vbaErrorOverflow, __vbaNew2, __vbaInStr, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, -, __vbaVarSetVar, __vbaLateMemCall, __vbaAryLock, __vbaStrToAnsi, __vbaVarDup, __vbaVarCopy, -, _CIatan, __vbaStrMove, _allmul, _CItan, __vbaAryUnlock, _CIexp, __vbaFreeObj, __vbaFreeStr<BR><BR>( 0 exports ) <BR>
j'espére que c'est assez claire jte remercie pour ton aide