Hello dédétraqué, merci pour ton aide une fois encore. Voici les rapports, d'abord celui de virustotal :
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
Xromia.exe
Submission date:
2010-10-04 05:39:36 (UTC)
Current status:
finished
Result:
19/ 43 (44.2%)
Antivirus Version Last Update Result
AhnLab-V3 2010.10.03.01 2010.10.03 Win-Trojan/Mdob.183296.V
AntiVir 7.10.12.112 2010.10.03 -
Antiy-AVL 2.0.3.7 2010.10.04 -
Authentium 5.2.0.5 2010.10.04 W32/Renos.A!Generic
Avast 4.8.1351.0 2010.10.03 -
Avast5 5.0.594.0 2010.10.03 -
AVG 9.0.0.851 2010.10.04 -
BitDefender 7.2 2010.10.04 Gen:Variant.Kazy.1181
CAT-QuickHeal 11.00 2010.10.04 -
ClamAV 0.96.2.0-git 2010.10.04 -
Comodo 6277 2010.10.04 -
DrWeb 5.0.2.03300 2010.10.04 Trojan.DownLoader1.18078
Emsisoft 5.0.0.50 2010.10.04 -
eSafe 7.0.17.0 2010.10.03 -
eTrust-Vet 36.1.7889 2010.10.02 Win32/Renos.D!generic
F-Prot 4.6.2.117 2010.10.04 W32/Renos.A!Generic
F-Secure 9.0.15370.0 2010.10.04 Gen:Variant.Kazy.1181
Fortinet 4.1.143.0 2010.10.03 W32/CodecPack.fam!tr.dldr
GData 21 2010.10.04 Gen:Variant.Kazy.1181
Ikarus T3.1.1.90.0 2010.10.04 -
Jiangmin 13.0.900 2010.10.03 -
K7AntiVirus 9.63.2662 2010.10.02 Virus
Kaspersky 7.0.0.125 2010.10.03 -
McAfee 5.400.0.1158 2010.10.04 -
McAfee-GW-Edition 2010.1C 2010.10.03 Heuristic.BehavesLike.Win32.Suspicious.H
Microsoft 1.6201 2010.10.03 -
NOD32 5500 2010.10.03 a variant of Win32/Kryptik.HCL
Norman 6.06.07 2010.10.03 W32/Obfuscated.M
nProtect 2010-10-04.01 2010.10.04 Gen:Variant.Kazy.1181
Panda 10.0.2.7 2010.10.03 Suspicious file
PCTools 7.0.3.5 2010.10.02 -
Prevx 3.0 2010.10.04 Medium Risk Malware
Rising 22.67.02.07 2010.09.30 -
Sophos 4.58.0 2010.10.04 Mal/FakeAV-CX
Sunbelt 6976 2010.10.04 VirTool.Win32.Obfuscator.hg!b1 (v)
SUPERAntiSpyware 4.40.0.1006 2010.10.04 -
Symantec 20101.2.0.161 2010.10.04 -
TheHacker 6.7.0.1.048 2010.10.04 -
TrendMicro 9.120.0.1004 2010.10.04 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.04 -
VBA32 3.12.14.1 2010.10.01 -
ViRobot 2010.10.4.4074 2010.10.04 Trojan.Win32.Downloader.183296.AL
VirusBuster 12.66.12.0 2010.10.03 -
Additional information
Show all
MD5 : 4f1ca0355ba8fa25cb29d75e5ab00188
SHA1 : 019e8511e7d12c7f1ef799280c914c1f73f3cf5b
SHA256: 507890e836e7ba9f774aa9fc70b2a84c88a70db607ca3664f57d614deae5c342
ssdeep: 3072:7Rn2hwxwl1vHPN3WgDZr3Zb0SeN1w4cyZ0j4uTPJLHwyXnlV8UEFIcc/GSpZ:7w+6zvHPr
3Zb0SeNG4Dc4qPJLHwyX1EA
File size : 183296 bytes
First seen: 2010-10-04 05:39:36
Last seen : 2010-10-04 05:39:36
TrID:
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: Simon Tatham
copyright....: GoldG ver3
product......: GoldG
description..: GoldG
original name: GoldG.exe
internal name: GoldG
file version.: 3.1.1.1
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x7AD7
timedatestamp....: 0x4B60C85C (Wed Jan 27 23:12:28 2010)
machinetype......: 0x14c (I386)
[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
CODE, 0x1000, 0x967E, 0x9800, 5.35, 03ceafe123b3b808383807a1be4288e7
.rdata, 0xB000, 0x2E9D4, 0x1DA00, 7.59, 9628eb4dfedd440db73dd51f7c76f307
.data, 0x3A000, 0x2652, 0x2800, 4.04, d23b6a234bd1387181dc40315915fc76
.bss, 0x3D000, 0x946, 0xA00, 4.21, 181bfdda2a1968a78251a8e6eb9216ca
.rsrc, 0x3E000, 0x220C, 0x2400, 3.42, 6aaaaeb577b09776986189696b9fe6ed
[[ 6 import(s) ]]
OLEAUT32.dll: SafeArrayCreate, OleLoadPicture, SysReAllocStringLen, SafeArrayGetUBound, SysStringLen, GetErrorInfo, SafeArrayGetElement, SafeArrayUnaccessData, SysAllocStringLen, SafeArrayPtrOfIndex
comdlg32.dll: GetOpenFileNameA, ChooseColorA, GetFileTitleA, FindTextA
shlwapi.dll: PathFileExistsA, SHDeleteKeyA, SHStrDupA, PathGetCharTypeA, SHGetValueA, SHSetValueA, SHDeleteValueA, PathIsContentTypeA, PathIsDirectoryA, SHQueryInfoKeyA
comctl32.dll: ImageList_Create, ImageList_GetBkColor, ImageList_Remove, ImageList_Write, ImageList_Draw, ImageList_Add, ImageList_Read, ImageList_Destroy, ImageList_DragShowNolock, ImageList_DrawEx
ole32.dll: CreateStreamOnHGlobal, ReleaseStgMedium, CoCreateInstanceEx, CoUnmarshalInterface, OleCreateStaticFromData, CLSIDFromProgID, CoDisconnectObject, PropVariantClear, CoFreeUnusedLibraries, StringFromIID
KERNEL32.dll: GetProcAddress, GetCPInfo, ExitThread, GetCommandLineA, GetCommandLineW, lstrlenW, GetModuleHandleA, LoadLibraryA, ExitProcess, LocalReAlloc, GlobalAlloc, GetModuleHandleW, VirtualAlloc, IsBadReadPtr, lstrlenA, GetACP
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp?PX5=E9223583001D0667CC350283ADD81C(...)
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 38912
CompanyName: Simon Tatham
EntryPoint: 0x7ad7
FileDescription: GoldG
FileFlagsMask: 0x003f
FileOS: Win32
FileSize: 179 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 3.1.1.1
FileVersionNumber: 3.1.1.1
ImageVersion: 0.0
InitializedDataSize: 143360
InternalName: GoldG
LanguageCode: English (U.S.)
LegalCopyright: GoldG ver3
LinkerVersion: 4.8
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Executable application
OriginalFilename: GoldG.exe
PEType: PE32
ProductName: GoldG
ProductVersion: 3.1.1.1
ProductVersionNumber: 3.1.1.1
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2010:01:28 00:12:28+01:00
UninitializedDataSize: 69632
Symantec reputation:Suspicious.Insight
Et celui de Ad-Remover (xromia.exe est toujours là après vérification, mais comme je ne sais pas si c'est un fichier légitime ou un malware, je préfère le laisser jusqu'à ce que j'ai un avis là dessus) :
======= RAPPORT D'AD-REMOVER 2.0.0.1,F | UNIQUEMENT XP/VISTA/7 =======
Mis à jour par C_XX le 16/09/10 à 13:30
Contact: AdRemover.contact[AT]gmail.com
Site web:
http://www.teamxscript.org
C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 07:41:55 le 04/10/2010, Mode normal
Microsoft Windows 7 Édition Familiale Premium (X64)
Twah@TWAH-PC (Acer Aspire M3203)
============== ACTION(S) ==============
0,Dossier supprimé: C:\Program Files (x86)\Conduit
0,Dossier supprimé: C:\ProgramData\Trymedia
3,Fichier supprimé: C:\Windows\Installer\575b2.msi
(!) -- Fichiers temporaires supprimés.
0,Clé supprimée: HKLM\Software\Classes\Toolbar.CT2304157
0,Clé supprimée: HKLM\Software\Conduit
0,Clé supprimée: HKCU\Software\Conduit
0,Clé supprimée: HKCU\Software\AppDataLow\Software\Conduit
3,Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
3,Clé supprimée: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
============== SCAN ADDITIONNEL ==============
** Mozilla Firefox Version [3.6.10 (fr)] **
-- C:\Users\Twah\AppData\Roaming\Mozilla\FireFox\Profiles\ce68lxcq.default\Prefs.js --
browser.startup.homepage_override.mstone, rv:1.9.2.10
========================================
** Internet Explorer Version [8.0.7600.16385] **
[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar:
hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page:
hxxp://fr.msn.com/
Use Search Asst: no
[HKLM\Software\Microsoft\Internet Explorer\Main]
AutoHide: yes
Default_Page_URL:
hxxp://go.microsoft.com/fwlink/?LinkId=54896
Default_Search_URL:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Enable Browser Extensions: yes
Local Page: C:\Windows\SysWOW64\blank.htm
Search bar:
hxxp://search.msn.com/spbasic.htm
Search Page:
hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page:
hxxp://fr.msn.com/
Use Search Asst: no
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs:
res://ieframe.dll/tabswelcome.htm
Blank:
res://mshtml.dll/blank.htm
========================================
C:\Program Files (x86)\Ad-Remover\Quarantine: 2 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 15 Fichier(s)
C:\Ad-Report-CLEAN[1].txt - 04/10/2010 (2642 Octet(s))
Fin à: 07:43:33, 04/10/2010
============== E.O.F ==============
-------
Mort aux dialers et spywares -_-
Message édité par Stoneworld le 04/10/2010 08:06:10