Re: Trojan quand je lance Anno1701
le 20 Mai 2011 20:56
Bonsoir Bernard
J'ai analysé le fichier avec Avast, il ne détecte rien.
Je viens de l'analyser par le lien que tu m'as envoyé, un seul des antivirus sur 36 (VIPRE) trouve le même virus :
Antivirus Version Last Update Result
AntiVir 7.11.8.85 2011.05.20 -
Antiy-AVL 2.0.3.7 2011.05.20 -
Avast 4.8.1351.0 2011.05.20 -
Avast5 5.0.677.0 2011.05.20 -
AVG 10.0.0.1190 2011.05.20 -
BitDefender 7.2 2011.05.20 -
CAT-QuickHeal 11.00 2011.05.20 -
ClamAV 0.97.0.0 2011.05.20 -
Commtouch 5.3.2.6 2011.05.20 -
Comodo 8772 2011.05.20 -
DrWeb 5.0.2.03300 2011.05.20 -
Emsisoft 5.1.0.5 2011.05.20 -
eSafe 7.0.17.0 2011.05.19 -
eTrust-Vet 36.1.8339 2011.05.20 -
F-Secure 9.0.16440.0 2011.05.20 -
Fortinet 4.2.257.0 2011.05.20 -
GData 22 2011.05.20 -
Ikarus T3.1.1.104.0 2011.05.20 -
Jiangmin 13.0.900 2011.05.20 -
K7AntiVirus 9.103.4693 2011.05.20 -
Kaspersky 9.0.0.837 2011.05.20 -
McAfee 5.400.0.1158 2011.05.20 -
McAfee-GW-Edition 2010.1D 2011.05.20 -
Microsoft 1.6903 2011.05.20 -
NOD32 6139 2011.05.20 -
nProtect 2011-05-20.01 2011.05.20 -
Prevx 3.0 2011.05.20 -
Rising 23.58.04.03 2011.05.20 -
Sophos 4.65.0 2011.05.20 -
SUPERAntiSpyware 4.40.0.1006 2011.05.20 -
TheHacker 6.7.0.1.202 2011.05.20 -
TrendMicro 9.200.0.1012 2011.05.20 -
TrendMicro-HouseCall 9.200.0.1012 2011.05.20 -
VBA32 3.12.16.0 2011.05.20 -
VIPRE 9337 2011.05.20 Trojan.Crypt.Krap (v)
ViRobot 2011.5.20.4470 2011.05.20 -
Additional information
MD5 : ff384cdfa75ff8821086883158d04081
SHA1 : d9b2fd5beda427d737b1bea1d0dc54e61b6e5460
SHA256: e4d104a1c4831e3135ae4365cc5e8c393ffa7424a9d8a094ec695ccb00302f22
ssdeep: 196608:qjx6Qj7+h4r6inZJie/V4ijwaTqj1TkM:qjAg3GiZJJ/Vf8N
File size : 7502848 bytes
First seen: 2010-07-18 19:57:22
Last seen : 2011-05-20 19:40:47
TrID:
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher....: Related Designs Software GmbH
copyright....: Copyright (C) 2006
product......: Anno 1701
description..: Anno 1701
original name: Anno1701.exe
internal name: Anno 1701
file version.: V1.02
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0xCEC577
timedatestamp....: 0x4C51 (Thu Jan 01 05:25:37 1970)
machinetype......: 0x14c (I386)
[[ 10 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.CODE , 0x1000, 0xCB8000, 0x485800, 8.00, 6e425060c402933c57aa411fd3e330c6
.rsrc, 0xCB9000, 0x2FE28, 0x30000, 7.47, c5f3de26dc11ac3b0387437f5bdfa1e0
HC09 , 0xCE9000, 0x3000, 0x3000, 6.67, 724c9deca90b0ed0dc1e7afe6167e9e2
.dcrtext, 0xCEC000, 0xE7000, 0xE7000, 7.99, 14c856be756c84447eda5135bc531c7f
HC08 , 0xDD3000, 0x2000, 0x2000, 6.32, 66a5fdf2182b2f2d94cca032a6324f8f
HC01 , 0xDD5000, 0xC4000, 0xC4000, 7.99, 4b9424300abcc9a46c932aa448d4f11a
HC07 , 0xE99000, 0xB6000, 0xB6000, 8.00, 84c009f3658dad38b7a3f81d9cbd33d8
HC03 , 0xF4F000, 0x8000, 0x8000, 7.99, 402b2b1ee39d57bd86ff7d4ea3a0f8c1
HC02 , 0xF57000, 0x3000, 0x3000, 7.98, 93930dbd59a0ba63718c21958b58c095
.edata , 0xF5A000, 0x1000, 0x1000, 0.38, e23ec179682a0f11edc7f96d3a17a6f4
[[ 1 import(s) ]]
kernel32.dll: VirtualProtect
[[ 2 export(s) ]]
__0IntelLaptopGamingTDKInterface@@IAE@XZ, __4IntelLaptopGamingTDKInterface@@QAEAAV0@ABV0@@Z
F-Secure DeepGuard:Suspicious:W32/Malware!Gemini