Alors tout d'abord :
Master G a écrit :
Va sur VirusTOTAL et inspecte ces fichiers :
C:\Windows\System32\GEARAspi.dll
aucun pb :
Information additionnelle
File size: 107368 bytes
MD5...: 005ee82babf1d2d32188a75bedf500a4
SHA1..: 97d30f06a806a2208bcb89958b6017e24122e816
SHA256: 47a1ccbce460fc833afe4992f55452227dc70d46434d2c95582c78abb6539a50
SHA512: a0b5bc37e1abd99453e3f354446a3c109cae30667130f2bdaa996400d178af17
975953bee843808bc704297dffa896170c2a974b6f84c1961db57e94d212a840
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x10008bfb
timedatestamp.....: 0x479f07c4 (Tue Jan 29 11:02:28 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x12403 0x12600 6.46 77e504aa8940a5a26f5500e2d6387f68
.rdata 0x14000 0x32af 0x3400 5.27 a827d3d0b2c987e220961bde9856846d
.data 0x18000 0x2e20 0x1000 2.62 76824f0f64ec7b0b8a598ffc4c8d2dbd
.rsrc 0x1b000 0x5c0 0x600 4.26 f46024b1b145174ce012311a72782954
.reloc 0x1c000 0x195c 0x1a00 4.37 c0a68991bd3624eb79ad3ec2ccb83217
( 2 imports )
> KERNEL32.dll: CreateFileA, SetEvent, GetLastError, FreeLibrary, GlobalAlloc, CreateFileW, QueryDosDeviceA, GetDriveTypeA, GlobalLock, CreateMutexA, WaitForSingleObject, ReleaseMutex, DeviceIoControl, GlobalUnlock, GlobalFree, CloseHandle, LoadLibraryA, GetVersionExA, RaiseException, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapFree, RtlUnwind, WideCharToMultiByte, HeapAlloc, GetCurrentThreadId, GetCommandLineA, GetModuleHandleW, GetProcAddress, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, InterlockedDecrement, HeapCreate, HeapDestroy, VirtualFree, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, HeapReAlloc, Sleep, HeapSize, ExitProcess, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, WriteFile, GetStdHandle, GetModuleFileNameA, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, LCMapStringA, MultiByteToWideChar, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, SetFilePointer, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, FlushFileBuffers
> ADVAPI32.dll: OpenServiceA, StartServiceA, CloseServiceHandle, RegOpenKeyExW, RegCreateKeyExA, RegQueryValueExA, RegCloseKey, RegQueryValueExW, OpenSCManagerA
( 8 exports )
GASPIBlockDevice, GASPIGetDriveLetter, GASPIGetMaxTransferSize, GASPINotifyMediaChange, GASPISetTimeout, GetASPI32SupportInfo, InstallDevices, SendASPI32Command
C:\Windows\System32\drivers\GEARAspiWDM.sys
No pb :
Information additionnelle
File size: 15464 bytes
MD5...: ab8a6a87d9d7255c3884d5b9541a6e80
SHA1..: dcd8ca6f82db7938e30c0d4dd9a2a9f1253ed5d7
SHA256: d073b5d8a06efa6415e8f22dfe486de913113ae23f59cfc5eef1b3e694ce86f3
SHA512: d93a70e88c1dddbe8538edcfb2682a40a4e5f8c841f7bcf6a0d1963d63dd8fd9
9a0fef658cce14ca242405111b011f6a4b4c58b57e6b506fc664ecacbebe4943
PEiD..: -
TrID..: File type identification
Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x11e09
timedatestamp.....: 0x47fbc45a (Tue Apr 08 19:15:38 2008)
machinetype.......: 0x14c (I386)
( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x480 0x1014 0x1080 6.25 084d1ba76d916157fa224cffd68c8803
.rdata 0x1500 0x123 0x180 4.05 c01b510f09605daec5354013fa9ef80e
.data 0x1680 0x19c 0x200 0.24 cea5497367bdba8ba5441970535272b4
PAGE 0x1880 0x48a 0x500 5.64 7d405f278a8031fc4f69c113a9e2c90f
INIT 0x1d80 0x44a 0x480 5.50 bf3d6de31388526773e2ca3a70fc71bd
.rsrc 0x2200 0x380 0x380 3.36 56242084ab6df59edaef1cd0a63b2693
.reloc 0x2580 0x15c 0x180 4.99 4034516e24d27fb2edd4d9795c7bf270
( 1 imports )
> ntoskrnl.exe: KeInitializeEvent, IoCreateSymbolicLink, IoCreateDevice, RtlInitUnicodeString, IoAttachDeviceToDeviceStack, RtlCompareUnicodeString, IoGetDeviceProperty, KeSetEvent, InterlockedIncrement, InterlockedDecrement, IofCompleteRequest, IoGetCurrentProcess, IofCallDriver, KeWaitForSingleObject, IoReportTargetDeviceChange, IoBuildDeviceIoControlRequest, ExFreePool, ExAllocatePoolWithTag, memcpy, RtlQueryRegistryValues, memset, IoDeleteDevice, IoAttachDevice, ZwClose, _wcsnicmp, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, swprintf, IoFreeIrp, IoAllocateIrp, IoDetachDevice, PoStartNextPowerIrp, PoCallDriver, KeTickCount, KeBugCheckEx
( 0 exports )
C:\Windows\System32\dataclen.dll
No pb :
Information additionnelle
File size: 45056 bytes
MD5...: e4c2a84bc3ed47da2958614dd3e1d181
SHA1..: e06b0fdfcaf28a60bd319ca40cdc9d752acea737
SHA256: fa27f1649935cc001aa9cde1d99b6b0048aa0155d8290967ce1aedadf26ba4aa
SHA512: 72d0d8b87dd148730a1a58493bb133c9de9cdefd0acc8108c98a9d9562cad33a
2b2e15f517c1c6051ffc88eb1ba871700575e587fab7a4e91df2013a6f7117ce
PEiD..: -
TrID..: File type identification
DirectShow filter (90.9%)
Win32 Executable Generic (3.8%)
Win32 Dynamic Link Library (generic) (3.4%)
Generic Win/DOS Executable (0.9%)
DOS Executable Generic (0.9%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x23a834b8
timedatestamp.....: 0x48630b5c (Thu Jun 26 03:22:04 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x322b 0x3400 6.25 d7bdbc758cdafcef0ae84e813dcb5079
.data 0x5000 0x364 0x200 0.28 38a465ab13e516ac4d90e19854e125b5
.rsrc 0x6000 0x71f8 0x7200 5.70 5d124ef2a73af61d932aa9f86a7d5d3f
.reloc 0xe000 0x3b0 0x400 4.86 04b75ef88d4218b133bf4a0d6be73883
( 9 imports )
> msvcrt.dll: _initterm, _amsg_exit, _adjust_fdiv, malloc, _except_handler4_common, _XcptFilter, free, memcpy, memset
> POWRPROF.dll: CallNtPowerInformation, IsPwrHibernateAllowed
> KERNEL32.dll: FindResourceExW, LoadResource, GetCurrentProcessId, GetLastError, HeapAlloc, GetProcessHeap, HeapFree, InterlockedIncrement, InterlockedDecrement, CompareFileTime, DeleteFileW, RemoveDirectoryW, SetFileAttributesW, CompareStringW, GetSystemDirectoryW, GlobalMemoryStatusEx, CloseHandle, CreateProcessW, SystemTimeToFileTime, GetSystemTime, lstrlenW, lstrcmpW, FindClose, FindNextFileW, FindFirstFileW, GetFileAttributesW, InterlockedExchange, Sleep, InterlockedCompareExchange, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, SetUnhandledExceptionFilter, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, LockResource
> USER32.dll: LoadStringW
> ADVAPI32.dll: RegQueryValueExW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegCloseKey, QueryServiceStatus, RegOpenKeyExW, RegEnumKeyExW
> ole32.dll: CoInitializeEx, CoCreateInstance, CoUninitialize, CoTaskMemFree, CoTaskMemAlloc
> OLEAUT32.dll: -
> SHELL32.dll: SHGetFolderPathW
> SHLWAPI.dll: StrCmpNIW, -, -, PathAppendW, StrCmpW, -, PathCombineW, SHGetValueW
( 2 exports )
DllCanUnloadNow, DllGetClassObject
C:\Windows\System32\cdd.dll
no pb :
Information additionnelle
File size: 36864 bytes
MD5...: 99d8d5af1826a4cb454b865223540449
SHA1..: ab77d9bae47ed907722ff5abe3918d4093ab90e2
SHA256: bb79dbd0b387c0ad54c21dc55db72a0be4074a1f86387ae468416ce0b5b1025c
SHA512: 573011daf823b3e4aec41650eb2f318d57fb954418f1c2315cd2c175e3a7a205
223aea1fead2d77d1d4bc7767b1509b904ac717c129e7bebb892314db747e272
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x6f407b7a
timedatestamp.....: 0x4893d3d9 (Sat Aug 02 03:26:17 2008)
machinetype.......: 0x14c (I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x71f8 0x7200 6.32 e2e5c014e024635d7896ca53d4fb6f67
.rdata 0x9000 0x1b0 0x200 3.33 4279efd7740abacb312019a496ba7741
.data 0xa000 0x30c 0x400 4.19 2e7574b080de4942c21be913429d7488
INIT 0xb000 0x710 0x800 4.88 abd88b0dbf0cf09b31f44d388e2d16af
.rsrc 0xc000 0x3f0 0x400 3.34 0b1d684c35869e2e09c83f27206a1e06
.reloc 0xd000 0x624 0x800 5.30 fd58b6441f6ebbf88598d7daf77156b0
( 4 imports )
> WIN32K.SYS: EngDeleteRgn, CLIPOBJ_bEnum, CLIPOBJ_cEnumStart, EngGetRgnData, EngCombineRgn, EngSetRectRgn, EngRectInRgn, EngGetRgnBox, EngCreateRectRgn, EngQueryW32kCddInterface, EngDeleteSurface, EngUnlockSurface, EngAssociateSurface, EngCreateDeviceSurface, EngLockSurface, EngCreateBitmap, EngDeletePalette, EngCreatePalette, EngAllocMem, EngCopyBits, EngEqualRgn, EngStrokePath, PATHOBJ_vGetBounds, EngTransparentBlt, EngAlphaBlend, EngGradientFill, EngStretchBlt, EngOffsetRgn, EngBitBlt, EngTextOut, EngLineTo, EngFillPath, EngStrokeAndFillPath, EngStretchBltROP, EngPlgBlt, EngBugCheckEx, PALOBJ_cGetColors, EngFreeMem
> ntoskrnl.exe: ExFreePoolWithTag, MmFreePagesFromMdl, MmMapLockedPagesSpecifyCache, MmAllocatePagesForMdl, KeInitializeEvent, KeGetCurrentThread, ExReleaseFastMutexUnsafeAndLeaveCriticalRegion, ExEnterCriticalRegionAndAcquireFastMutexUnsafe, KeWaitForSingleObject, KeSetEvent, IofCallDriver, IoBuildDeviceIoControlRequest, IoGetDeviceObjectPointer, RtlInitUnicodeString, ExAllocatePoolWithTag, PsGetProcessImageFileName, PsGetCurrentProcess, MmUnmapLockedPages, KeSetActualBasePriorityThread, ZwClose, PsCreateSystemThread, ObOpenObjectByPointer, KeClearEvent, ObfDereferenceObject, ZwQuerySystemInformation
> HAL.dll: KeGetCurrentIrql
> watchdog.sys: WdLogEvent5, SMgrGdiCallout, WdLogServiceEntry5
( 0 exports )
C:\Windows\System32\Apphlpdm.dll
no pb :
Information additionnelle
File size: 28160 bytes
MD5...: 860c0fec03daa99bed61791aa6da232e
SHA1..: a40e905b8ccafe60f534fba961700e6f9e8ec905
SHA256: cdacace79842f2081de3d8f1b20b5e612a37d803e8ed8faee8d3af5fabda8671
SHA512: 3fa761f6e005b8bd8c4a6c0b63bd918fe8987dd0e07dc5fb21ecc2b35ea19c16
9962c20992422b2f04a5fea94dd2757aa5657db00ece792f873f72e29fb882c2
PEiD..: -
TrID..: File type identification
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x26403573
timedatestamp.....: 0x48913071 (Thu Jul 31 03:24:33 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x33b4 0x3400 6.40 40afd3b24ef6f0f286a41fe0bb8a2b47
.data 0x5000 0x380 0x200 0.28 8f276bc8493006369d128a007b63541f
.rsrc 0x6000 0x2e58 0x3000 5.10 fc62262d7ae143d3016fd2018702ee41
.reloc 0x9000 0x36a 0x400 4.82 10f426a62b824f30e92bbca8920bb111
( 11 imports )
> msvcrt.dll: _except_handler4_common, _adjust_fdiv, _amsg_exit, _initterm, free, malloc, _XcptFilter, memset, memcpy, _wcsnicmp, _vsnwprintf
> ntdll.dll: RtlFreeUnicodeString, RtlStringFromGUID
> KERNEL32.dll: GetSystemTimeAsFileTime, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, InterlockedCompareExchange, Sleep, InterlockedExchange, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, HeapAlloc, GetProcessHeap, HeapFree, CloseHandle, CreateDirectoryW, GetTempPathW, WaitForSingleObject, CreateProcessW
> wdi.dll: WdiSetResolution, WdiGetParameterByName, WdiGetParameterData, WdiGetDiagnosticModuleId, WdiAddParameter, WdiSetProblemDetectionResult, WdiGetEvent
> ADVAPI32.dll: GetTokenInformation
> SHELL32.dll: ShellExecuteW, Shell_NotifyIconW
> USER32.dll: SetWindowTextW, SetDlgItemTextW, SetForegroundWindow, mouse_event, SendDlgItemMessageW, LoadIconW, DestroyWindow, SetWindowLongW, EndDialog, GetWindowLongW, SendMessageW, DefWindowProcW, PostMessageW, CreateWindowExW, RegisterWindowMessageW, PostQuitMessage, GetMessageW, DispatchMessageW, DestroyIcon, RegisterClassW, UnregisterClassW, GetDlgItem, DialogBoxParamW, EnableWindow, LoadStringW
> GDI32.dll: CreateFontIndirectW, GetObjectW
> WTSAPI32.dll: WTSQueryUserToken
> wer.dll: WerReportSetUIOption, WerReportSetParameter, WerReportCreate, WerReportCloseHandle, WerReportAddFile, WerReportSubmit
> apphelp.dll: SdbGrabMatchingInfo
( 3 exports )
WdiDiagnosticModuleMain, WdiGetDiagnosticModuleInterfaceVersion, WdiHandleInstance
C:\Windows\System32\IPSECSVC.DLL
no pb :
Information additionnelle
File size: 361984 bytes
MD5...: 47b8f37aa18b74d8c2e1bc1a7a2c8f8a
SHA1..: 2b00ddf8b6bced76854ee1fb53ca6716b2aff896
SHA256: fae64867ce80439735f88a9988243667bde84486b5a768b650e55e1519c85c03
SHA512: a1f5e43246d37ea36e5a64cd754c2778d2e853311b06ac22d2b1b5a46e51ca44
5eb50f7fea293970cf6f3fb45d6d5e3690f669accc63723e1f3376da3360d9d5
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x6ef41409
timedatestamp.....: 0x4859d252 (Thu Jun 19 03:28:18 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5141d 0x51600 6.53 5da3d3fc1a264f1ed886ad054169be92
.data 0x53000 0xa60 0xa00 2.17 b4fd3917158a770ce1086d5ad2b5403c
.rsrc 0x54000 0x1240 0x1400 3.15 5754ecb46f297bcd5a171235dfae6655
.reloc 0x56000 0x4c78 0x4e00 6.78 2f633607d66729a997952efe3247b0ed
( 15 imports )
> msvcrt.dll: wcsstr, wcschr, _wtol, _snwscanf_s, _mkgmtime, memset, _wcsicmp, memcpy, _XcptFilter, malloc, free, _except_handler4_common, _onexit, _lock, __dllonexit, _unlock, _adjust_fdiv, _amsg_exit, _initterm, _vsnwprintf
> KERNEL32.dll: SetHandleInformation, CreateEventW, InitializeCriticalSectionAndSpinCount, GetModuleHandleW, GetCurrentProcess, GetLastError, CloseHandle, FormatMessageW, LeaveCriticalSection, EnterCriticalSection, ResetEvent, SetEvent, LoadLibraryA, GetTickCount, WaitForMultipleObjects, DeleteCriticalSection, GetProcAddress, FreeLibrary, InterlockedCompareExchange, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, QueryPerformanceCounter, DelayLoadFailureHook, InterlockedIncrement, HeapAlloc, GetProcessHeap, HeapFree, InterlockedDecrement, Sleep, InterlockedExchange, WideCharToMultiByte, LocalFree
> ADVAPI32.dll: EventWrite, RegSetValueExW, RegDeleteValueW, RegEnumKeyExW, RegDeleteKeyW, RegOpenKeyExW, RegisterServiceCtrlHandlerExW, RegCreateKeyExW, SetServiceStatus, EventRegister, EventUnregister, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegOpenKeyW, RegQueryValueExW, RegCloseKey, AllocateAndInitializeSid, FreeSid, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetLengthSid, InitializeAcl, AddAccessAllowedAce, AddAccessDeniedAce, GetAce, SetSecurityDescriptorDacl, GetSecurityDescriptorLength, MakeSelfRelativeSD, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, TraceMessage
> AUTHZ.dll: AuthziInitializeAuditEvent, AuthziInitializeAuditEventType, AuthziInitializeAuditParams, AuthziFreeAuditEventType, AuthzFreeAuditEvent, AuthziLogAuditEvent, AuthzAccessCheck
> ole32.dll: CoInitializeEx, CoCreateInstance, CoUninitialize
> RPCRT4.dll: UuidCreate, RpcRevertToSelf, RpcImpersonateClient, RpcEpUnregister, RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, RpcServerUseProtseqW, RpcServerRegisterIfEx, UuidIsNil, RpcEpRegisterW, NdrServerCall2, RpcGetAuthorizationContextForClient, RpcFreeAuthorizationContext, RpcStringFreeW, RpcBindingInqAuthClientW, RpcStringBindingParseW, RpcBindingToStringBindingW, RpcServerInqBindings, RpcServerUnregisterIfEx, RpcBindingVectorFree, I_RpcBindingIsClientLocal
> IPHLPAPI.DLL: NhGetInterfaceNameFromGuid, GetAdaptersAddresses
> WS2_32.dll: -, WSASocketW, WSACreateEvent, -, WSAIoctl, WSAEventSelect, WSAResetEvent, -, -, WSACloseEvent, -, -, -
> CRYPT32.dll: CertStrToNameW
> USERENV.dll: FreeGPOListW, GetGPOListW, RefreshPolicy
> fwpuclnt.dll: IPsecGetStatistics0, FwpmEngineClose0, IkeextGetConfigParameters0, IkeextSetConfigParameters0, FwpmEngineOpen0, IkeextGetStatistics0, IkeextSaDestroyEnumHandle0, FwpmFreeMemory0, IkeextSaEnum0, IkeextSaCreateEnumHandle0, IPsecSaDestroyEnumHandle0, IPsecSaEnum0, IPsecSaCreateEnumHandle0, IkeextSaDeleteById0, IPsecSaContextDeleteById0, IPsecSaContextEnum0, IPsecSaContextCreateEnumHandle0, FwpmIPsecTunnelAdd0, FwpmTransactionAbort0, FwpmProviderAdd0, FwpmTransactionBegin0, FwpmTransactionCommit0, FwpmProviderContextAdd0, FwpmProviderContextDeleteByKey0, FwpmFilterAdd0, FwpmFilterDeleteByKey0, FwpmIPsecTunnelDeleteByKey0
> OLEAUT32.dll: -, -
> FirewallAPI.dll: FWChangeNotificationDestroy, FWChangeNotificationCreate
> FwRemoteSvr.DLL: FwRpcAPIsShutdown, FwRpcAPIsInitialize
> WLDAP32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
( 1 exports )
SpdServiceMain
C:\Windows\System32\FwRemoteSvr.dll
no pb :
Information additionnelle
File size: 28672 bytes
MD5...: 988963e9e07787e1d8f99dc1f452213d
SHA1..: 934fa735102a02a656c79966afb8aae477d4adc5
SHA256: da549366a0529a9b6378889599d3ffa57201f598c27c7527bba36046c3f09d23
SHA512: 50fd7b05ccba7922474af185caec52de6ad531407f1644ade99d3b94f8857023
d138db516bbece4566fc063b801f2fdec38d1434c373a87e92474f19ab76f22c
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4a391230
timedatestamp.....: 0x4791a6b1 (Sat Jan 19 07:28:49 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5988 0x5a00 6.12 96bec92d351f42c634f67eaac9bc02aa
.data 0x7000 0x458 0x600 0.89 07fbcb13e509c2312e848e8ff54f5a54
.rsrc 0x8000 0x438 0x600 2.58 67f7d01b04d410c650a71e0948e8d4a3
.reloc 0x9000 0x568 0x600 6.29 fdf5b7e89848f4c1773e87e6ca6bc3e9
( 5 imports )
> msvcrt.dll: malloc, free, _initterm, _amsg_exit, _adjust_fdiv, _XcptFilter, memcpy, memset, _except_handler4_common
> KERNEL32.dll: Sleep, CloseHandle, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, LocalFree, GetTickCount, QueryPerformanceCounter, InterlockedCompareExchange, InterlockedExchange, GetCurrentThread, GetLastError
> ADVAPI32.dll: OpenThreadToken, ConvertStringSecurityDescriptorToSecurityDescriptorW, TraceMessage, AccessCheck
> RPCRT4.dll: RpcEpUnregister, RpcBindingToStringBindingW, I_RpcBindingIsClientLocal, RpcBindingInqAuthClientW, RpcServerUseProtseqW, NdrServerCall2, RpcRevertToSelf, RpcImpersonateClient, RpcServerUnregisterIfEx, RpcBindingVectorFree, RpcStringBindingParseW, RpcStringFreeW, RpcServerRegisterAuthInfoW, RpcServerInqDefaultPrincNameW, RpcEpRegisterW, RpcServerInqBindings, RpcServerRegisterIfEx
> FirewallAPI.dll: FWEnumPhase1SAs, FWEnumCryptoSets, FWEnumPhase2SAs, FWDeleteCryptoSet, FWSetCryptoSet, FWAddCryptoSet, FWEnumAuthenticationSets, FWSetAuthenticationSet, FWDeleteAuthenticationSet, FWAddAuthenticationSet, FWEnumConnectionSecurityRules, FWDeleteAllConnectionSecurityRules, FWDeleteConnectionSecurityRule, FWSetConnectionSecurityRule, FWAddConnectionSecurityRule, FWDeletePhase1SAs, FWDeletePhase2SAs, FWDeleteAllCryptoSets, FWDeleteAllAuthenticationSets, FWClosePolicyStore, FWOpenPolicyStore, FWSetGlobalConfig, FWGetGlobalConfig, FWSetConfig, FWGetConfig, FWSetFirewallRule, FWAddFirewallRule, FWDeleteAllFirewallRules, FWDeleteFirewallRule, FWEnumFirewallRules, FWRestoreDefaults, FwFree, FwAlloc
( 2 exports )
FwRpcAPIsInitialize, FwRpcAPIsShutdown
Télécharge OTMoveIt (de Old_Timer) sur ton bureau :
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
# Redémarre le PC en mode sans échec :
Tu n' auras pas accès à Internet pendant le "mode sans échec". Aussi, copie/colle toute cette procédure dans un fichier texte et mets-la sur le "bureau" pour l'avoir à ta disposition.
Ferme toutes les fenêtres et applications.
Redémarre ton ordinateur, puis tapote sur la touche F8 (F5 sur certains PC) avant l’apparition du logo Windows, un menu va apparaître, tu devra choisir de démarrer en mode sans échec.
# Double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée !!!
Copie le texte ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved.
C:\Users\Laurene\AppData\Roaming\GTek
C:\Windows\System32\ZFYE
C:\Program Files\Axon Data
C:\Users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
C:\Windows\unins000.exe
C:\Windows\unins000.dat
C:\Windows\System32\SRSWOW.dll
C:\Program Files\No-Folder-Created
C:\Windows\Setup1.exe
C:\Windows\ST6UNST.EXE
C:\Windows\HideWin.exe
C:\ProgramData\ma-config.com
C:\Program Files\ma-config.com
C:\Program Files\Common Files\xing shared
C:\Windows\System32\NaturalLanguage6.dll
C:\Users\Laurene\AppData\Local\Temp\JMPXQUQYVX.exe
C:\Users\Laurene\AppData\Local\Temp\SERVWZCPVM.exe
Clique sur MoveIt! pour lancer la suppression.
Lorsque un résultat apparaît dans le cadre Results, clique sur Exit et redémarre ton PC.
Copie-colle le rapport dans ta réponse : il est situé sur --> C:\_OTMoveIt\MovedFiles.
Pour cette partie je le ferais ce soir là j'ai pas le temps...