Bonjour, tout d'abord bonne année ^^
Alors, j'ai lancé HijackThis, que j'ai renommé "viredela.exe" j'ai préféré ne pas utiliser votre exemple car s'il est sur un fofo comme celui ci, je me suis dis qu'il pourrait lui aussi être détecté.
En lançant le scan, ce message d'erreur est apparu :
For some reason your system denied crite access to the Hosts file. If any Hijacked
domains are in this fils hijackthis may not be able to fix this
If that hapens, you need to edit the file yourself. To do this, click Start, Run an type :
notepad C:WindowsSystem32driversetchosts
ans press Enter, Find the line(s) HijackThis reports an delete them.
Save the file as 'hosts.' (with quotes), and reboot.
For vista : simply, exit HijackThis, right click on the HijackThis icon, choose 'Run as administrator'
J'ai donc fait comme ils disent, en le lançant en tant qu'administrateur, le message d'erreur est réaparu quand meme
Dans tout les cas l'analyse s'est fait quand meme, mais je ne sais pas si elle est fiable, voici son rapport :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:37:57, on 07/01/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:PROGRAM FILESPANDA SECURITYPANDA ANTIVIRUS PRO 2009WebProxy.exe
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesIntelIntel Matrix Storage ManagerIAAnotif.exe
C:WindowsRtHDVCpl.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesAcerEmpowering TechnologyeDataSecurityx86eDSLoader.exe
C:Program FilesNewTech InfosystemsNTI Backup Now 5BkupTray.exe
C:WindowsSystem32
undll32.exe
C:Program FilesAcerAcer Bio ProtectionPdtWzd.exe
C:UsersGRONOU~1AppDataLocalTempRtkBtMnt.exe
C:Program FilesLaunch ManagerLManager.exe
C:Program FilesAcerEmpowering TechnologyePowerePower_DMC.exe
C:Program FilesAcerEmpowering TechnologyeAudioeAudio.exe
C:Program FilesPanda SecurityPanda Antivirus Pro 2009ApVxdWin.exe
C:Program FilesJavajre6injusched.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesWIDCOMMBluetooth SoftwareBTTray.exe
C:Windowssystem32wbemunsecapp.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:UsersGronounoursDesktopviredela.exe
C:Program FilesPanda SecurityPanda Antivirus Pro 2009avciman.exe
C:Windowssystem32SearchFilterHost.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://homepage.acer.com/rdr.aspx?b=ACA ... spire_8930
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACA ... spire_8930
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://fr.fr.acer.yahoo.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComet oolsBitCometBHO_1.2.8.7.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre6inssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:Program FilesAcerEmpowering TechnologyeDataSecurityx86ActiveToolBand.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6injp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:Program FilesAcerEmpowering TechnologyeDataSecurityx86eDStoolbar.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [IAAnotif] C:Program FilesIntelIntel Matrix Storage Manageriaanotif.exe
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [eDataSecurity Loader] C:Program FilesAcerEmpowering TechnologyeDataSecurityx86eDSloader.exe
O4 - HKLM..Run: [BkupTray] "C:Program FilesNewTech InfosystemsNTI Backup Now 5BkupTray.exe"
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:Windowssystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:Windowssystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [WarReg_PopUp] C:Program FilesAcerWR_PopUpWarReg_PopUp.exe
O4 - HKLM..Run: [ZPdtWzdVitaKey MC3000] "C:Program FilesAcerAcer Bio ProtectionPdtWzd.exe" show
O4 - HKLM..Run: [LManager] C:PROGRA~1LAUNCH~1LManager.exe
O4 - HKLM..Run: [ePower_DMC] C:Program FilesAcerEmpowering TechnologyePowerePower_DMC.exe
O4 - HKLM..Run: [eAudio] "C:Program FilesAcerEmpowering TechnologyeAudioeAudio.exe"
O4 - HKLM..Run: [APVXDWIN] "C:Program FilesPanda SecurityPanda Antivirus Pro 2009APVXDWIN.EXE" /s
O4 - HKLM..Run: [SCANINICIO] "C:Program FilesPanda SecurityPanda Antivirus Pro 2009Inicio.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre6injusched.exe"
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesWindows LiveMessengerMsnMsgr.Exe" /background
O4 - HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'SERVICE RESEAU')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet -
res://C:Program FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet -
res://C:Program FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet -
res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:Program FilesWIDCOMMBluetooth Softwaretsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:Program FilesWIDCOMMBluetooth Softwaretsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:Program FilesWIDCOMMBluetooth Softwaretsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:Program FilesWIDCOMMBluetooth Softwaretsendto_ie.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} -
res://C:Program FilesBitComet oolsBitCometBHO_1.2.8.7.dll/206 (file missing)
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) -
http://ax.emsisoft.com/asquared.cab
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:Program FilesAcerAcer Bio ProtectionWinNotify.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:Windowssystem32agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:Program FilesNewTech InfosystemsNTI Backup Now 5ClientAgentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:Program FilesAcerEmpowering TechnologyeDataSecurityx86eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:Program FilesAcerEmpowering TechnologyServiceETService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:Program FilesIntelWiFiinEvtEng.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:Program FilesIntelIntel Matrix Storage ManagerIAANTMon.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:Program FilesAcerAcer Bio ProtectionBASVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program FilesCommon FilesLightScribeLSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:AcerMobility CenterMobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:Program FilesNewTech InfosystemsNTI Backup Now 5BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:Program FilesNewTech InfosystemsNTI Backup Now 5SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:Windowssystem32
vvsvc.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:Program FilesPanda SecurityPanda Antivirus Pro 2009PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Security, S.L. - C:Program FilesPanda SecurityPanda Antivirus Pro 2009PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Security, S.L. - C:Program FilesCommon FilesPanda SecurityPavShldpavprsrv.exe
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:Program FilesPanda SecurityPanda Antivirus Pro 2009pavsrvx86.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - C:Program FilesPanda SecurityPanda Antivirus Pro 2009FirewallPSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:Program FilesPanda SecurityPanda Antivirus Pro 2009PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:Program FilesPanda SecurityPanda Antivirus Pro 2009PskSvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:Program FilesCommon FilesIntelWirelessCommonRegSrvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:Program FilesPanda SecurityPanda Antivirus Pro 2009TPSrv.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:Windowssystem32vfsFPService.exe
--
End of file - 10869 bytes
Ensuite, j'ai fais le scan avec Malwarebytes' Anti-Malware, mon pc a freeze sur un .sys de la carte graphique :
C:WindowsSystem32DriverStoreFilesrepository
v_mo.inf_b52947b3
vlddmkm.sys
Je tiens à préciser que j'ai analysé nvd3dum.dll et nvlddmkm.sys seul à l'aide de panda, il ne trouve aucun virus et le pc ne freeze pas, il ne feeze qu'en analyse.
Enfin voici le rapport avec Virus Total, il n'a rien trouvé comme panda :
Fichier nvd3dum.dll reçu le 2008.12.20 13:08:29 (CET)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.12.19.3 2008.12.19 -
AntiVir 7.9.0.45 2008.12.19 -
Authentium 5.1.0.4 2008.12.20 -
Avast 4.8.1281.0 2008.12.19 -
AVG 8.0.0.199 2008.12.19 -
BitDefender 7.2 2008.12.20 -
CAT-QuickHeal 10.00 2008.12.20 -
ClamAV 0.94.1 2008.12.20 -
Comodo 781 2008.12.19 -
DrWeb 4.44.0.09170 2008.12.20 -
eSafe 7.0.17.0 2008.12.18 -
eTrust-Vet 31.6.6269 2008.12.19 -
Ewido 4.0 2008.12.20 -
F-Prot 4.4.4.56 2008.12.19 -
Fortinet 3.117.0.0 2008.12.20 -
GData 19 2008.12.20 -
Ikarus T3.1.1.45.0 2008.12.20 -
K7AntiVirus 7.10.559 2008.12.19 -
Kaspersky 7.0.0.125 2008.12.20 -
McAfee 5469 2008.12.19 -
McAfee+Artemis 5469 2008.12.19 -
Microsoft 1.4205 2008.12.20 -
NOD32 3708 2008.12.20 -
Norman 5.80.02 2008.12.19 -
Panda 9.0.0.4 2008.12.20 -
PCTools 4.4.2.0 2008.12.20 -
Prevx1 V2 2008.12.20 -
Rising 21.08.52.00 2008.12.20 -
SecureWeb-Gateway 6.7.6 2008.12.19 -
Sophos 4.37.0 2008.12.20 -
Sunbelt 3.2.1801.2 2008.12.10 -
Symantec 10 2008.12.20 -
TheHacker 6.3.1.4.193 2008.12.19 -
TrendMicro 8.700.0.1004 2008.12.19 -
VBA32 3.12.8.10 2008.12.20 -
ViRobot 2008.12.20.1528 2008.12.20 -
VirusBuster 4.5.11.0 2008.12.19 -
Information additionnelle
File size: 3022848 bytes
MD5...: 1f5e2ba84e34115b754e834353d9bee5
SHA1..: 57224db26eb215f49f146568308400ae5b9e60e2
SHA256: 7b90c3e7dc99c02b37f9ff6faa2211987a0cbe74abd0a5251fb934ca36d811d2
SHA512: f511913b3378918e48f9d70034dd7dc7145d1bb9bf351f5ceca6ec152640f8aa<br>1bcc3332ee01dee490e2947782d7aa91bebbcfcea1980cc2e9e955e5599f845e<br>
ssdeep: 49152:pTHwDdGeIa/JsO/f3+Ipo+PQQxQkyl+URwKwqcmPb16V4EYlgOmSDn:pEY<br>/aXpPh6kURNb16V4HlgOmSD<br>
PEiD..: -
TrID..: File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x779476b0<br>timedatestamp.....: 0x4549bde7 (Thu Nov 02 09:44:07 2006)<br>machinetype.......: 0x14c (I386)<br><br>( 6 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x23fb64 0x240000 6.51 64ffd4549fae64b11baebb98f4447a2f<br>.rdata 0x241000 0x1e0f9 0x1f000 5.72 6e2e006a299c70bdf5fbd7847eeea42c<br>.data 0x260000 0xb4f58 0x6e000 5.18 14dbe6a778ddd679ddf47fa0b7298b0d<br>.tls 0x315000 0xd 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110<br>.rsrc 0x316000 0x3d0 0x1000 1.06 d72bb93975e288ce1cfa4417921cf101<br>.reloc 0x317000 0x11db4 0x12000 6.25 7f936379cec01a71f0178fe40b0bf0c7<br><br>( 3 imports ) <br>> KERNEL32.dll: CreateFileA, SetFilePointer, CloseHandle, WriteFile, ReadFile, DeviceIoControl, FreeLibrary, LoadLibraryA, SwitchToThread, GetTickCount, GetCommandLineA, GetCurrentDirectoryA, GetFileAttributesA, Sleep, GetCurrentProcessId, IsBadReadPtr, SetUnhandledExceptionFilter, GetSystemDirectoryA, IsDebuggerPresent, OutputDebugStringA, QueryPerformanceFrequency, GetProcAddress, QueryPerformanceCounter, HeapAlloc, HeapFree, GetCurrentThreadId, GetVersionExA, HeapReAlloc, RtlUnwind, DeleteCriticalSection, LeaveCriticalSection, FatalAppExitA, EnterCriticalSection, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, IsBadWritePtr, GetLastError, RaiseException, ExitProcess, GetModuleHandleA, TerminateProcess, GetCurrentProcess, TlsAlloc, SetLastError, GetCurrentThread, TlsFree, TlsSetValue, TlsGetValue, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, UnhandledExceptionFilter, HeapSize, VirtualProtect, GetSystemInfo, VirtualQuery, LCMapStringA, MultiByteToWideChar, LCMapStringW, InitializeCriticalSection, InterlockedExchange, SetStdHandle, FlushFileBuffers, GetACP, GetOEMCP, GetCPInfo, GetStringTypeA, GetStringTypeW, GetTimeFormatA, GetDateFormatA, GetUserDefaultLCID, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, GetSystemTimeAsFileTime, SetEndOfFile, SetConsoleCtrlHandler, GetTimeZoneInformation, GetLocaleInfoW, CompareStringA, CompareStringW, SetEnvironmentVariableA, IsBadCodePtr<br>> USER32.dll: IntersectRect<br>> ADVAPI32.dll: RegSetValueExA, RegCreateKeyExA, RegQueryValueExA, RegCloseKey, RegOpenKeyExA<br><br>( 4 exports ) <br>GetIAtomString, NvDiagUmdCommand, OpenAdapter, QueryOglResource<br>
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.12.19.3 2008.12.19 -
AntiVir 7.9.0.45 2008.12.19 -
Authentium 5.1.0.4 2008.12.20 -
Avast 4.8.1281.0 2008.12.19 -
AVG 8.0.0.199 2008.12.19 -
BitDefender 7.2 2008.12.20 -
CAT-QuickHeal 10.00 2008.12.20 -
ClamAV 0.94.1 2008.12.20 -
Comodo 781 2008.12.19 -
DrWeb 4.44.0.09170 2008.12.20 -
eSafe 7.0.17.0 2008.12.18 -
eTrust-Vet 31.6.6269 2008.12.19 -
Ewido 4.0 2008.12.20 -
F-Prot 4.4.4.56 2008.12.19 -
Fortinet 3.117.0.0 2008.12.20 -
GData 19 2008.12.20 -
Ikarus T3.1.1.45.0 2008.12.20 -
K7AntiVirus 7.10.559 2008.12.19 -
Kaspersky 7.0.0.125 2008.12.20 -
McAfee 5469 2008.12.19 -
McAfee+Artemis 5469 2008.12.19 -
Microsoft 1.4205 2008.12.20 -
NOD32 3708 2008.12.20 -
Norman 5.80.02 2008.12.19 -
Panda 9.0.0.4 2008.12.20 -
PCTools 4.4.2.0 2008.12.20 -
Prevx1 V2 2008.12.20 -
Rising 21.08.52.00 2008.12.20 -
SecureWeb-Gateway 6.7.6 2008.12.19 -
Sophos 4.37.0 2008.12.20 -
Sunbelt 3.2.1801.2 2008.12.10 -
Symantec 10 2008.12.20 -
TheHacker 6.3.1.4.193 2008.12.19 -
TrendMicro 8.700.0.1004 2008.12.19 -
VBA32 3.12.8.10 2008.12.20 -
ViRobot 2008.12.20.1528 2008.12.20 -
VirusBuster 4.5.11.0 2008.12.19 -
Information additionnelle
File size: 3022848 bytes
MD5...: 1f5e2ba84e34115b754e834353d9bee5
SHA1..: 57224db26eb215f49f146568308400ae5b9e60e2
SHA256: 7b90c3e7dc99c02b37f9ff6faa2211987a0cbe74abd0a5251fb934ca36d811d2
SHA512: f511913b3378918e48f9d70034dd7dc7145d1bb9bf351f5ceca6ec152640f8aa<br>1bcc3332ee01dee490e2947782d7aa91bebbcfcea1980cc2e9e955e5599f845e<br>
ssdeep: 49152:pTHwDdGeIa/JsO/f3+Ipo+PQQxQkyl+URwKwqcmPb16V4EYlgOmSDn:pEY<br>/aXpPh6kURNb16V4HlgOmSD<br>
PEiD..: -
TrID..: File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x779476b0<br>timedatestamp.....: 0x4549bde7 (Thu Nov 02 09:44:07 2006)<br>machinetype.......: 0x14c (I386)<br><br>( 6 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x23fb64 0x240000 6.51 64ffd4549fae64b11baebb98f4447a2f<br>.rdata 0x241000 0x1e0f9 0x1f000 5.72 6e2e006a299c70bdf5fbd7847eeea42c<br>.data 0x260000 0xb4f58 0x6e000 5.18 14dbe6a778ddd679ddf47fa0b7298b0d<br>.tls 0x315000 0xd 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110<br>.rsrc 0x316000 0x3d0 0x1000 1.06 d72bb93975e288ce1cfa4417921cf101<br>.reloc 0x317000 0x11db4 0x12000 6.25 7f936379cec01a71f0178fe40b0bf0c7<br><br>( 3 imports ) <br>> KERNEL32.dll: CreateFileA, SetFilePointer, CloseHandle, WriteFile, ReadFile, DeviceIoControl, FreeLibrary, LoadLibraryA, SwitchToThread, GetTickCount, GetCommandLineA, GetCurrentDirectoryA, GetFileAttributesA, Sleep, GetCurrentProcessId, IsBadReadPtr, SetUnhandledExceptionFilter, GetSystemDirectoryA, IsDebuggerPresent, OutputDebugStringA, QueryPerformanceFrequency, GetProcAddress, QueryPerformanceCounter, HeapAlloc, HeapFree, GetCurrentThreadId, GetVersionExA, HeapReAlloc, RtlUnwind, DeleteCriticalSection, LeaveCriticalSection, FatalAppExitA, EnterCriticalSection, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, IsBadWritePtr, GetLastError, RaiseException, ExitProcess, GetModuleHandleA, TerminateProcess, GetCurrentProcess, TlsAlloc, SetLastError, GetCurrentThread, TlsFree, TlsSetValue, TlsGetValue, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, UnhandledExceptionFilter, HeapSize, VirtualProtect, GetSystemInfo, VirtualQuery, LCMapStringA, MultiByteToWideChar, LCMapStringW, InitializeCriticalSection, InterlockedExchange, SetStdHandle, FlushFileBuffers, GetACP, GetOEMCP, GetCPInfo, GetStringTypeA, GetStringTypeW, GetTimeFormatA, GetDateFormatA, GetUserDefaultLCID, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, GetSystemTimeAsFileTime, SetEndOfFile, SetConsoleCtrlHandler, GetTimeZoneInformation, GetLocaleInfoW, CompareStringA, CompareStringW, SetEnvironmentVariableA, IsBadCodePtr<br>> USER32.dll: IntersectRect<br>> ADVAPI32.dll: RegSetValueExA, RegCreateKeyExA, RegQueryValueExA, RegCloseKey, RegOpenKeyExA<br><br>( 4 exports ) <br>GetIAtomString, NvDiagUmdCommand, OpenAdapter, QueryOglResource<br>
Mon pc ne freezait pas que nvd3dum.dll, mais aussi si d'autre du meme dossier, je l'ai ai toute analysé une par une, aucun virus n'a été trouvé
Mon pc est de plus en plus lent, étant joueur, cela me dérange quelque peu ^^
Merci beaucoup, bonne année encore