Malware virus xp pro
j'ai un soucis avec mon portable.
j'ai essayé de revenir a une version anterieure cad dernire bonne config reconnu mais j'ai toujours le meme probleme.
XP internet secutité alert
stealth threat
spyware intusion detected
severe system damage.
trojan spy html.bankfrad.
avant de poster j ai telecharger malwarebyte's.
il m'a trouvé des infections qui'il a corrifé .
cependant il m'a dit qu'il ne pouvait pas tout vire .
apre le reboot j ai tjs les messages.
voici le log
je ne sais plus vraiment quoi faire .apparemment cela semble etre arrivé a d autres
sauriez vous que faire de +.
merci
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3510
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
21/03/2010 21:16:06
mbam-log-2010-03-21 (21-16-06).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 233368
Temps écoulé: 52 minute(s), 41 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 7
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 3
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\TypeLib\{4d25f920-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4d25f923-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f924-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Delete on reboot.
Fichier(s) infecté(s):
C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot.
112 réponses
Infection Windows XP accompagnée d’alertes de sécurité et de menaces comme Adware.MyWebSearch, Rogue.MultipleAV et Trojan.Agent, détectées par Malwarebytes lors d’un examen complet et persistantes après reboot. Des mesures essentielles apparaissent: démarrer en mode sans échec, mettre à jour Malwarebytes et lancer un examen complet pour supprimer ou quarantiner les éléments infectés, y compris fichiers et clés de registre. D’autres outils, comme SUPERAntiSpyware ou UsbFix, ont été proposés pour nettoyer les résidus et relancer le système, avec des rapports montrant des éléments neutralisés mais des traces possibles dans les paramètres de sécurité.
-
salut,
voici le log , apparemment il a supprimé avec succes.
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
Quarantined & Deleted !! : c:\windows\system32\DWRCS.EXE -
salut,
voici le log , apparemment il a supprimé avec succes.
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
¤¤¤¤¤¤¤¤¤¤ File | Folder
Quarantined & Deleted !! : c:\windows\system32\DWRCS.EXE -
hello,
coupe tes protections, relance List_Kill'em , option "Manuel delete"
un fichier texte vide va s'ouvrir , colle ca dedans :
C:\WINDOWS\SYSTEM32\DWRCS.EXE
ensuite , clic sur l'onglet fichier puis enregistrer , puis ferme la fenetre , une autre va s ouvrir , avec quelque chose d'ecrit , communique-le -
bonjour,
impossible de supprimer un fichier systeme -
bonjour,
le fichier doit etre utilisé par windows car il refuse la suppression du dwrcs.exe
,et ses propriétés ne sont pas cohées , (cachée et lecture seule). -
oui
-
je dois supprimer quoi ?
le DWRCS.EXE ? -
supprime-le
-
voici le log
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.50 2010.01.29 -
AhnLab-V3 5.0.0.2 2010.01.29 -
AntiVir 7.9.1.154 2010.01.29 -
Antiy-AVL 2.0.3.7 2010.01.28 -
Authentium 5.2.0.5 2010.01.30 -
Avast 4.8.1351.0 2010.01.30 -
AVG 9.0.0.730 2010.01.29 -
BitDefender 7.2 2010.01.30 -
CAT-QuickHeal 10.00 2010.01.29 -
ClamAV 0.96.0.0-git 2010.01.30 -
Comodo 3757 2010.01.30 -
DrWeb 5.0.1.12222 2010.01.30 -
eSafe 7.0.17.0 2010.01.28 -
eTrust-Vet 35.2.7271 2010.01.29 -
F-Prot 4.5.1.85 2010.01.29 -
F-Secure 9.0.15370.0 2010.01.29 -
Fortinet 4.0.14.0 2010.01.30 -
GData 19 2010.01.30 -
Ikarus T3.1.1.80.0 2010.01.29 -
Jiangmin 13.0.900 2010.01.28 -
K7AntiVirus 7.10.960 2010.01.29 -
Kaspersky 7.0.0.125 2010.01.30 -
McAfee 5876 2010.01.29 potentially unwanted program RemAdm-DWRC
McAfee+Artemis 5876 2010.01.29 potentially unwanted program RemAdm-DWRC
McAfee-GW-Edition 6.8.5 2010.01.30 Heuristic.BehavesLike.Win32.Downloader.H
Microsoft 1.5406 2010.01.30 -
NOD32 4819 2010.01.30 -
Norman 6.04.03 2010.01.29 -
nProtect 2009.1.8.0 2010.01.29 -
Panda 10.0.2.2 2010.01.29 Suspicious file
PCTools 7.0.3.5 2010.01.30 -
Prevx 3.0 2010.01.30 -
Rising 22.32.05.01 2010.01.30 -
Sophos 4.50.0 2010.01.30 -
Sunbelt 3.2.1858.2 2010.01.30 -
Symantec 20091.2.0.41 2010.01.30 Supicious.Insight
TheHacker 6.5.1.0.171 2010.01.30 -
TrendMicro 9.120.0.1004 2010.01.30 -
VBA32 3.12.12.1 2010.01.29 -
ViRobot 2010.1.30.2163 2010.01.30 -
VirusBuster 5.0.21.0 2010.01.29 -
Information additionnelle
File size: 241664 bytes
MD5 : 3d3cecdd903954f7c5859bac109c2d36
SHA1 : 779a9256473d4935670136f88260f162093283e5
SHA256: 6f86fd77a5c553a6afef652111d19832a34d78145f1f8368407d7e02275be828
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x1E1D3<BR>timedatestamp.....: 0x3F007ABD (Mon Jun 30 20:00:29 2003)<BR>machinetype.......: 0x14C (Intel I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x256F5 0x26000 6.48 88a5d1607150163b4187f52bbfb71a71<BR>.rdata 0x27000 0x3C78 0x4000 5.63 2275d0b2328ff3a644d8b82abc5a57bd<BR>.data 0x2B000 0xC5C4 0x9000 4.78 51d81beacbcb602154483e4b1a76e99f<BR>.rsrc 0x38000 0x6710 0x7000 3.48 320294101e3f34ecf8c436fd63171705<BR><BR>( 8 imports )<BR><BR>> advapi32.dll: InitializeAcl, CreateProcessAsUserA, RegDeleteKeyA, RegisterEventSourceA, ReportEventA, DeregisterEventSource, SetServiceStatus, OpenServiceA, ControlService, QueryServiceStatus, DeleteService, RegDeleteValueA, OpenSCManagerA, CreateServiceA, CloseServiceHandle, RegCreateKeyA, RegSetValueExA, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, SetThreadToken, OpenThreadToken, FreeSid, PrivilegedServiceAuditAlarmA, AccessCheck, IsValidSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, AddAccessAllowedAce, RegQueryValueExA, GetLengthSid, InitializeSecurityDescriptor, AllocateAndInitializeSid, GetUserNameW, RegCloseKey, RegOpenKeyA<BR>> gdi32.dll: DeleteDC, CreateSolidBrush, SetBkMode, SetBkColor, GetStockObject, CreateCompatibleDC, GetSystemPaletteEntries, CreateHalftonePalette, GetPaletteEntries, DeleteObject, CreatePalette, SelectPalette, RealizePalette, GdiFlush, CreateDIBSection, SelectObject, BitBlt, GetBitmapBits, GetObjectA, GetDeviceCaps<BR>> kernel32.dll: GlobalUnlock, GlobalLock, GlobalAlloc, GetCurrentThreadId, WritePrivateProfileStringA, CreateProcessA, ResumeThread, SetThreadPriority, GetExitCodeThread, GetModuleFileNameA, SetProcessShutdownParameters, CreateFileMappingA, GetCurrentThread, LocalFree, LocalAlloc, HeapFree, HeapAlloc, lstrlenW, lstrcmpiW, lstrcatW, lstrcpyW, MultiByteToWideChar, lstrcmpA, WaitForSingleObject, GetTickCount, CreateEventA, SetEvent, TerminateThread, ResetEvent, GetPrivateProfileStringA, GetComputerNameA, SetFilePointer, WideCharToMultiByte, GetCurrentProcessId, lstrcpynA, UnhandledExceptionFilter, TerminateProcess, IsBadWritePtr, HeapReAlloc, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, GetEnvironmentVariableA, TlsGetValue, TlsAlloc, GetVersion, GetCommandLineA, GetStartupInfoA, GetModuleHandleA, InterlockedIncrement, InterlockedDecrement, ExitThread, TlsSetValue, CreateThread, GetSystemTime, GetTimeZoneInformation, GetLocalTime, RtlUnwind, GetVersionExA, GetSystemDirectoryA, CopyFileA, MoveFileExA, GetCurrentProcess, DuplicateHandle, FreeLibrary, LoadLibraryA, GetProcAddress, SetLastError, WriteFile, SetFileTime, SetFileAttributesA, RemoveDirectoryA, DeleteFileA, CreateDirectoryA, lstrlenA, MoveFileA, GetLastError, CreateFileA, ReadFile, FindFirstFileA, FindNextFileA, FindClose, GetLogicalDrives, GetDriveTypeA, lstrcmpiA, lstrcatA, lstrcpyA, CloseHandle, Sleep, DeleteCriticalSection, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, LCMapStringA, LCMapStringW, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, SetUnhandledExceptionFilter, IsBadReadPtr, IsBadCodePtr, GetStringTypeA, GetStringTypeW, GetCPInfo, GetACP, GetOEMCP, SetStdHandle, FlushFileBuffers, CompareStringA, CompareStringW, ExitProcess, SetEnvironmentVariableA<BR>> ole32.dll: StringFromIID, CoGetMalloc<BR>> shell32.dll: ShellExecuteA, Shell_NotifyIconA, DragAcceptFiles, DragQueryFileA<BR>> user32.dll: GetDlgItem, MessageBeep, GetWindowLongA, KillTimer, PostQuitMessage, SetTimer, IsClipboardFormatAvailable, LoadMenuA, GetSubMenu, SetMenuDefaultItem, EnableMenuItem, DeleteMenu, SetForegroundWindow, TrackPopupMenu, GetMenuItemID, DestroyMenu, CreateDialogParamA, SetDlgItemTextA, UpdateWindow, GetWindowRect, GetDesktopWindow, SetWindowPos, GetClipboardOwner, GetClipboardData, RegisterClipboardFormatA, DefWindowProcA, GetUserObjectInformationA, OpenInputDesktop, SetWindowTextA, OpenDesktopA, EnumDisplaySettingsA, ChangeClipboardChain, LoadIconA, RegisterClassExA, CreateWindowExA, SetWindowLongA, SetClipboardViewer, SystemParametersInfoA, GetWindowDC, PostThreadMessageA, DestroyWindow, GetWindowThreadProcessId, LoadCursorA, AttachThreadInput, GetCaretPos, ClientToScreen, GetClassNameA, GetCursor, GetIconInfo, VkKeyScanA, CharUpperBuffA, GetMessageA, IsWindow, IsDialogMessageA, TranslateMessage, DispatchMessageA, PeekMessageA, EndDialog, FlashWindow, GetDlgItemTextA, SetThreadDesktop, ReleaseDC, GetDC, GetSystemMetrics, CloseDesktop, MessageBoxA, ExitWindowsEx, GetThreadDesktop, SendMessageA, PostMessageA, GetKeyboardState, MapVirtualKeyA, OpenClipboard, EmptyClipboard, SetClipboardData, CloseClipboard, GetCursorPos, WindowFromPoint, GetForegroundWindow, mouse_event, GetAsyncKeyState, keybd_event, DialogBoxParamA, GetKeyboardLayoutNameA, wsprintfA, LoadStringA, CopyRect, EnumWindows<BR>> version.dll: VerQueryValueA, GetFileVersionInfoA, GetFileVersionInfoSizeA<BR>> wsock32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR><BR>( 0 exports )<BR>
TrID : File type identification<BR>Win64 Executable Generic (54.6%)<BR>Win32 Executable MS Visual C++ (generic) (24.0%)<BR>Windows Screen Saver (8.3%)<BR>Win32 Executable Generic (5.4%)<BR>Win32 Dynamic Link Library (generic) (4.8%)
ssdeep: 6144:RnB0f76xN7QAMDulk5R4e8Ab685NGYq0F6OznCbjt:RnBI76sDEk5R+MdrG9qVnC
PEiD : -
RDS : NSRL Reference Data Set<BR>- -
salut un fichier me fait me poser des questions
? Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
* - Coche Afficher les fichiers et dossiers cachés
* - Décoche Masquer les extensions des fichiers dont le type est connu
* - Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)
? clique sur Appliquer, puis OK.
N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important
Fais analyser le(s) fichier(s) suivants sur Virustotal :
Virus Total
* Clique sur Parcourir en haut, choisis Poste de travail et cherche ces fichiers :
C:\WINDOWS\SYSTEM32\DWRCS.EXE
* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
* Une nouvelle fenêtre de ton navigateur va apparaître
* Clique alors sur les deux fleches
* Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
* Enfin colle le résultat dans ta prochaine réponse.
Note : Pour analyser un autre fichier, clique en bas sur Autre fichier.
?G3?-?@¢??@?(TM)©®? -
salut,
désolé pour le delai .
voici le rapport :
.
======= RAPPORT D'AD-REMOVER 2.0.0.0,B | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 23/03/10 à 14:00
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 11:43:00 le 15/04/2010 | Mode normal | Option: SCAN
Exécuté de: C:\Ad-Remover\ADR.exe
SE: Microsoft® Windows XP(TM) Service Pack 3 - X86
Nom du PC: PT102060 | Utilisateur actuel: YDerrien (Administrateur)
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
.
.
============== SCAN ADDITIONNEL ==============
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKCU\Software\Microsoft\Internet Explorer\Main]
.
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
Use Search Asst: no
.
[HKLM\Software\Microsoft\Internet Explorer\Main]
.
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
.
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
.
========================================
.
C:\DOCUME~1\YDerrien\LOCALS~1\Temp: 86 Fichier(s), 9 Dossier(s)
C:\WINDOWS\temp: 6 Fichier(s), 0 Dossier(s)
Temporary Internet Files: 622 Fichier(s), 22 Dossier(s)
.
C:\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Ad-Remover\Backup: 0 Fichier(s)
.
C:\Ad-Report-SCAN[2].txt - 1785 Octet(s)
.
Fin à: 11:52:30, 15/04/2010
.
============== E.O.F - SCAN[2] ============== -
Contributeur sécuritéBonsoir,
Il te reste une infection Infection BT (MyWebSearch.Spy)
▶ Désactiver vos logiciels de sécurité tel qu'antivirus...
▶ Rends-toi à cette adresse afin de télécharger AD-Remover (créé par C_XX) :
https://www.androidworld.fr/
▶ Ou là :
https://www.androidworld.fr/
/!\ Déconnecte-toi d'internet et ferme toutes applications en cours /!\
▶ Double-clique sur l'icône Ad-remover située sur ton Bureau.
▶ Sur la page, clique sur le bouton « Scanner »
▶ Confirme lancement du scan
▶ Laisse travailler l'outil.
▶ Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report.)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller) -
salut,
voici le lien
http://www.cijoint.fr/cjlink.php?file=cj201004/cijFwIpw56.txt -
Contributeur sécuritéok merci beaucoup.
Peux tu me faire ceci stp tournemine :
==> Télécharge ZHPDiag (de Nicolas Coolman)
ou :ZHPDiag
==> Enregistre le sur ton Bureau.
Une fois le téléchargement achevé,
==> Lance ZHPDiag.exe et clique sur suivant pour lancer l'installation dans la fenêtre qui s'ouvre.
==> Clique sur le tournevis en haut à droite (option) puis cocher toutes les cases des options.
==> Clique sur la loupe pour lancer l'analyse.
A la fin de l'analyse,
==> Clique sur l'appareil photo et enregistre le rapport sur ton Bureau.
Pour me le transmettre clique sur ce lien :
http://www.cijoint.fr/
==> Clique sur Parcourir et cherche le fichier ZHPDiag.txt
==> Clique sur Ouvrir.
==> Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt
est ajouté dans la page.
==> Copie ce lien dans ta réponse. -
apparement la mise a jour vers le SP3 a supprimé le fichier patché pour reinstaller un fichier sain signé Microsoft donc.....reste plus que le menage ^^
-
Contributeur sécuritéBonsoir à vous 2 il n'y a donc plus de rootkit GenHackman?
Si vous voyer que je ne répond pas à votre sujet, n'hésitez pas à me MP.
Parfois je ne vois pas l'alerte d'un nouveau message. -
je vous laisse finir ^^
-
ok merci pour le coup de main.
Je vous remercie tous les deux pour le temps passé a me depanner.
ai je autre chose a faire ? -
hello ok c'est bon il a recupéré sa signature microsoft ;)
-
bonjour,
voici le log:
Fichier disk.sys reçu le 2010.04.07 07:03:25 (UTC)Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.50 2010.04.07 -
AhnLab-V3 5.0.0.2 2010.04.06 -
AntiVir 7.10.6.31 2010.04.06 -
Antiy-AVL 2.0.3.7 2010.04.07 -
Authentium 5.2.0.5 2010.04.07 -
Avast 4.8.1351.0 2010.04.06 -
Avast5 5.0.332.0 2010.04.06 -
AVG 9.0.0.787 2010.04.07 -
BitDefender 7.2 2010.04.07 -
CAT-QuickHeal 10.00 2010.04.07 -
ClamAV 0.96.0.3-git 2010.04.07 -
Comodo 4525 2010.04.07 -
DrWeb 5.0.2.03300 2010.04.07 -
eSafe 7.0.17.0 2010.04.06 -
eTrust-Vet 35.2.7412 2010.04.07 -
F-Prot 4.5.1.85 2010.04.06 -
F-Secure 9.0.15370.0 2010.04.07 -
Fortinet 4.0.14.0 2010.04.06 -
GData 19 2010.04.07 -
Ikarus T3.1.1.80.0 2010.04.07 -
Jiangmin 13.0.900 2010.04.07 -
Kaspersky 7.0.0.125 2010.04.07 -
McAfee-GW-Edition 6.8.5 2010.04.06 -
Microsoft 1.5605 2010.04.07 -
NOD32 5005 2010.04.06 -
Norman 6.04.11 2010.04.06 -
nProtect 2009.1.8.0 2010.04.06 -
Panda 10.0.2.2 2010.04.06 -
PCTools 7.0.3.5 2010.04.07 -
Prevx 3.0 2010.04.07 -
Rising 22.42.02.02 2010.04.07 -
Sophos 4.52.0 2010.04.07 -
Sunbelt 6146 2010.04.07 -
Symantec 20091.2.0.41 2010.04.07 -
TheHacker 6.5.2.0.256 2010.04.07 -
TrendMicro 9.120.0.1004 2010.04.07 -
VBA32 3.12.12.4 2010.04.05 -
ViRobot 2010.4.7.2264 2010.04.07 -
VirusBuster 5.0.27.0 2010.04.06 -
Information additionnelle
File size: 36352 bytes
MD5...: 044452051f3e02e7963599fc8f4f3e25
SHA1..: a19652b689c06a116cf889823979669327de109f
SHA256: 584bddb074618be76454cf90e74829cff588b5b5faeb793e2f7aad26352dd689
ssdeep: 768:0geJpBApQnLs/oGMjZYEY/kETW/VbwTCJFgQgkV/p:0geJpBAinQAGMjZYpk<BR>tu+JFgQgkV/p<BR>
PEiD..: -
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x78ad<BR>timedatestamp.....: 0x480253ae (Sun Apr 13 18:40:46 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 8 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x300 0x202a 0x2080 6.30 4658ae57e106314e04866a3b281b5cd2<BR>.rdata 0x2380 0x4c9 0x500 4.27 0cea6ed228086d02c0e011a5a8259950<BR>.data 0x2880 0x108 0x180 2.87 12a95a395606d307c2fadbcd88715b36<BR>PAGE 0x2a00 0x44a5 0x4500 6.50 07e80ff4e8114ed146fa42285774305e<BR>PAGE 0x6f00 0x150 0x180 2.35 99b0ea69b39e7288164916a1b22848ef<BR>INIT 0x7080 0x141c 0x1480 6.01 b4c908e30b3ab6da8f4e5cfdf9576da1<BR>.rsrc 0x8500 0x3e0 0x400 3.33 ee43648b7c9abd51b9d19bb51fa2abd1<BR>.reloc 0x8900 0x4ec 0x500 6.13 7449d155384ccd3bf438f5ad13f048c2<BR><BR>( 2 imports ) <BR>> ntoskrnl.exe: IoFreeIrp, IoFreeMdl, IoWMIRegistrationControl, ExfInterlockedPopEntryList, KeInitializeSpinLock, ExQueueWorkItem, ExfInterlockedPushEntryList, MmBuildMdlForNonPagedPool, IoAllocateMdl, ZwQueryValueKey, RtlUnicodeStringToInteger, IoReadDiskSignature, ZwOpenKey, IoReadPartitionTable, DbgPrint, IoReadPartitionTableEx, IoWritePartitionTableEx, IoSetPartitionInformationEx, IoSetPartitionInformation, IoRegisterBootDriverReinitialization, IoGetConfigurationInformation, RtlQueryRegistryValues, IoOpenDeviceRegistryKey, RtlxAnsiStringToUnicodeSize, NlsMbCodePageTag, RtlAnsiStringToUnicodeString, RtlInitAnsiString, sprintf, IoCreateSymbolicLink, IoDeleteSymbolicLink, RtlFreeUnicodeString, IoSetDeviceInterfaceState, KeInitializeMutex, InitSafeBootMode, IoRegisterDeviceInterface, HalExamineMBR, KeTickCount, KeBugCheckEx, _allmul, _allrem, IoAllocateWorkItem, IoQueueWorkItem, IoReportTargetDeviceChangeAsynchronous, IoBuildDeviceIoControlRequest, IoBuildSynchronousFsdRequest, IoInvalidateDeviceRelations, memmove, IoCreateDisk, IoAllocateErrorLogEntry, IoWriteErrorLogEntry, IoAllocateIrp, IofCallDriver, _allshr, IoFreeWorkItem, KeWaitForSingleObject, KeReleaseMutex, ExAllocatePoolWithTag, KeSetEvent, strncmp, IoSetHardErrorOrVerifyDevice, swprintf, RtlInitUnicodeString, ZwCreateDirectoryObject, IoGetAttachedDeviceReference, ZwMakeTemporaryObject, ZwClose, ExFreePoolWithTag, IoAttachDeviceToDeviceStack, IoDeleteDevice, KeInitializeEvent, IoVerifyPartitionTable, ObfDereferenceObject<BR>> CLASSPNP.SYS: ClassQueryTimeOutRegistryValue, ClassUpdateInformationInRegistry, ClassInitializeMediaChangeDetection, ClassGetDeviceParameter, ClassDeleteSrbLookasideList, ClassReadDriveCapacity, ClassSignalCompletion, ClassMarkChildMissing, ClassInitializeSrbLookasideList, ClassNotifyFailurePredicted, ClassSetFailurePredictionPoll, ClassWmiCompleteRequest, ClassInterpretSenseInfo, ClassSpinDownPowerHandler, ClassInitialize, ClassInitializeEx, ClassSendDeviceIoControlSynchronous, ClassAcquireChildLock, ClassReleaseChildLock, ClassDeviceControl, ClassInvalidateBusRelations, ClassSetDeviceParameter, ClassModeSense, ClassFindModePage, ClassAcquireRemoveLockEx, ClassAsynchronousCompletion, ClassSendSrbSynchronous, ClassIoComplete, ClassReleaseRemoveLock, ClassCompleteRequest, ClassClaimDevice, ClassCreateDeviceObject, ClassScanForSpecial<BR><BR>( 0 exports ) <BR>
RDS...: NSRL Reference Data Set<BR>-
pdfid.: -
trid..: Generic Win/DOS Executable (49.9%)<BR>DOS Executable Generic (49.8%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
packers (Kaspersky): PE_Patch
sigcheck:<BR>publisher....: Microsoft Corporation<BR>copyright....: (c) Microsoft Corporation. All rights reserved.<BR>product......: Microsoft_ Windows_ Operating System<BR>description..: PnP Disk Driver<BR>original name: scsidisk.sys<BR>internal name: scsidisk.sys<BR>file version.: 5.1.2600.5512 (xpsp.080413-2108)<BR>comments.....: n/a<BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.50 2010.04.07 -
AhnLab-V3 5.0.0.2 2010.04.06 -
AntiVir 7.10.6.31 2010.04.06 -
Antiy-AVL 2.0.3.7 2010.04.07 -
Authentium 5.2.0.5 2010.04.07 -
Avast 4.8.1351.0 2010.04.06 -
Avast5 5.0.332.0 2010.04.06 -
AVG 9.0.0.787 2010.04.07 -
BitDefender 7.2 2010.04.07 -
CAT-QuickHeal 10.00 2010.04.07 -
ClamAV 0.96.0.3-git 2010.04.07 -
Comodo 4525 2010.04.07 -
DrWeb 5.0.2.03300 2010.04.07 -
eSafe 7.0.17.0 2010.04.06 -
eTrust-Vet 35.2.7412 2010.04.07 -
F-Prot 4.5.1.85 2010.04.06 -
F-Secure 9.0.15370.0 2010.04.07 -
Fortinet 4.0.14.0 2010.04.06 -
GData 19 2010.04.07 -
Ikarus T3.1.1.80.0 2010.04.07 -
Jiangmin 13.0.900 2010.04.07 -
Kaspersky 7.0.0.125 2010.04.07 -
McAfee-GW-Edition 6.8.5 2010.04.06 -
Microsoft 1.5605 2010.04.07 -
NOD32 5005 2010.04.06 -
Norman 6.04.11 2010.04.06 -
nProtect 2009.1.8.0 2010.04.06 -
Panda 10.0.2.2 2010.04.06 -
PCTools 7.0.3.5 2010.04.07 -
Prevx 3.0 2010.04.07 -
Rising 22.42.02.02 2010.04.07 -
Sophos 4.52.0 2010.04.07 -
Sunbelt 6146 2010.04.07 -
Symantec 20091.2.0.41 2010.04.07 -
TheHacker 6.5.2.0.256 2010.04.07 -
TrendMicro 9.120.0.1004 2010.04.07 -
VBA32 3.12.12.4 2010.04.05 -
ViRobot 2010.4.7.2264 2010.04.07 -
VirusBuster 5.0.27.0 2010.04.06 -
Information additionnelle
File size: 36352 bytes
MD5...: 044452051f3e02e7963599fc8f4f3e25
SHA1..: a19652b689c06a116cf889823979669327de109f
SHA256: 584bddb074618be76454cf90e74829cff588b5b5faeb793e2f7aad26352dd689
ssdeep: 768:0geJpBApQnLs/oGMjZYEY/kETW/VbwTCJFgQgkV/p:0geJpBAinQAGMjZYpk<BR>tu+JFgQgkV/p<BR>
PEiD..: -
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x78ad<BR>timedatestamp.....: 0x480253ae (Sun Apr 13 18:40:46 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 8 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x300 0x202a 0x2080 6.30 4658ae57e106314e04866a3b281b5cd2<BR>.rdata 0x2380 0x4c9 0x500 4.27 0cea6ed228086d02c0e011a5a8259950<BR>.data 0x2880 0x108 0x180 2.87 12a95a395606d307c2fadbcd88715b36<BR>PAGE 0x2a00 0x44a5 0x4500 6.50 07e80ff4e8114ed146fa42285774305e<BR>PAGE 0x6f00 0x150 0x180 2.35 99b0ea69b39e7288164916a1b22848ef<BR>INIT 0x7080 0x141c 0x1480 6.01 b4c908e30b3ab6da8f4e5cfdf9576da1<BR>.rsrc 0x8500 0x3e0 0x400 3.33 ee43648b7c9abd51b9d19bb51fa2abd1<BR>.reloc 0x8900 0x4ec 0x500 6.13 7449d155384ccd3bf438f5ad13f048c2<BR><BR>( 2 imports ) <BR>> ntoskrnl.exe: IoFreeIrp, IoFreeMdl, IoWMIRegistrationControl, ExfInterlockedPopEntryList, KeInitializeSpinLock, ExQueueWorkItem, ExfInterlockedPushEntryList, MmBuildMdlForNonPagedPool, IoAllocateMdl, ZwQueryValueKey, RtlUnicodeStringToInteger, IoReadDiskSignature, ZwOpenKey, IoReadPartitionTable, DbgPrint, IoReadPartitionTableEx, IoWritePartitionTableEx, IoSetPartitionInformationEx, IoSetPartitionInformation, IoRegisterBootDriverReinitialization, IoGetConfigurationInformation, RtlQueryRegistryValues, IoOpenDeviceRegistryKey, RtlxAnsiStringToUnicodeSize, NlsMbCodePageTag, RtlAnsiStringToUnicodeString, RtlInitAnsiString, sprintf, IoCreateSymbolicLink, IoDeleteSymbolicLink, RtlFreeUnicodeString, IoSetDeviceInterfaceState, KeInitializeMutex, InitSafeBootMode, IoRegisterDeviceInterface, HalExamineMBR, KeTickCount, KeBugCheckEx, _allmul, _allrem, IoAllocateWorkItem, IoQueueWorkItem, IoReportTargetDeviceChangeAsynchronous, IoBuildDeviceIoControlRequest, IoBuildSynchronousFsdRequest, IoInvalidateDeviceRelations, memmove, IoCreateDisk, IoAllocateErrorLogEntry, IoWriteErrorLogEntry, IoAllocateIrp, IofCallDriver, _allshr, IoFreeWorkItem, KeWaitForSingleObject, KeReleaseMutex, ExAllocatePoolWithTag, KeSetEvent, strncmp, IoSetHardErrorOrVerifyDevice, swprintf, RtlInitUnicodeString, ZwCreateDirectoryObject, IoGetAttachedDeviceReference, ZwMakeTemporaryObject, ZwClose, ExFreePoolWithTag, IoAttachDeviceToDeviceStack, IoDeleteDevice, KeInitializeEvent, IoVerifyPartitionTable, ObfDereferenceObject<BR>> CLASSPNP.SYS: ClassQueryTimeOutRegistryValue, ClassUpdateInformationInRegistry, ClassInitializeMediaChangeDetection, ClassGetDeviceParameter, ClassDeleteSrbLookasideList, ClassReadDriveCapacity, ClassSignalCompletion, ClassMarkChildMissing, ClassInitializeSrbLookasideList, ClassNotifyFailurePredicted, ClassSetFailurePredictionPoll, ClassWmiCompleteRequest, ClassInterpretSenseInfo, ClassSpinDownPowerHandler, ClassInitialize, ClassInitializeEx, ClassSendDeviceIoControlSynchronous, ClassAcquireChildLock, ClassReleaseChildLock, ClassDeviceControl, ClassInvalidateBusRelations, ClassSetDeviceParameter, ClassModeSense, ClassFindModePage, ClassAcquireRemoveLockEx, ClassAsynchronousCompletion, ClassSendSrbSynchronous, ClassIoComplete, ClassReleaseRemoveLock, ClassCompleteRequest, ClassClaimDevice, ClassCreateDeviceObject, ClassScanForSpecial<BR><BR>( 0 exports ) <BR>
RDS...: NSRL Reference Data Set<BR>-
pdfid.: -
trid..: Generic Win/DOS Executable (49.9%)<BR>DOS Executable Generic (49.8%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
packers (Kaspersky): PE_Patch
sigcheck:<BR>publisher....: Microsoft Corporation<BR>copyright....: (c) Microsoft Corporation. All rights reserved.<BR>product......: Microsoft_ Windows_ Operating System<BR>description..: PnP Disk Driver<BR>original name: scsidisk.sys<BR>internal name: scsidisk.sys<BR>file version.: 5.1.2600.5512 (xpsp.080413-2108)<BR>comments.....: n/a<BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
- 1
- 2
- 3
- 4
- 5
- 6