Créé les fichiers :
%Windir%\cftxith.exe
%System%\dllcache\explorer.exe
%Windir%\explorer.exe.tmp
%System%\image.jpg
%System%\tmp.txt
Réponse de Kaspersky :Fichier naked164.com reçu le 2008.01.24 21:59:51 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 5/30 (16.67%)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.1.25.10 2008.01.24 -
AntiVir 7.6.0.48 2008.01.24 DR/Delphi.Gen
Authentium 4.93.8 2008.01.24 -
Avast 4.7.1098.0 2008.01.23 -
AVG 7.5.0.516 2008.01.24 -
BitDefender 7.2 2008.01.24 -
CAT-QuickHeal 9.00 2008.01.24 -
ClamAV 0.91.2 2008.01.24 -
DrWeb 4.44.0.09170 2008.01.24 -
eSafe 7.0.15.0 2008.01.16 -
eTrust-Vet 31.3.5482 2008.01.24 -
Ewido 4.0 2008.01.24 -
FileAdvisor 1 2008.01.24 -
Fortinet 3.14.0.0 2008.01.24 -
F-Prot 4.4.2.54 2008.01.24 -
Ikarus T3.1.1.20 2008.01.24 Trojan-PWS.Win32.LdPinch.ajz
Kaspersky 7.0.0.125 2008.01.24 Heur.Trojan.Generic
McAfee 5215 2008.01.24 -
Microsoft 1.3109 2008.01.24 -
NOD32v2 2820 2008.01.24 -
Norman 5.80.02 2008.01.24 W32/Malware
Panda 9.0.0.4 2008.01.24 -
Prevx1 V2 2008.01.24 -
Rising 20.28.31.00 2008.01.24 -
Sophos 4.24.0 2008.01.24 Mal/Emogen-I
Sunbelt 2.2.907.0 2008.01.23 -
Symantec 10 2008.01.24 -
TheHacker 6.2.9.196 2008.01.23 -
VBA32 3.12.2.5 2008.01.21 -
VirusBuster 4.3.26:9 2008.01.24 -
Information additionnelle
File size: 73728 bytes
MD5: f2e71f5c61669632b682ca37efdb563f
SHA1: d8932d4e18aa4e516f7fa6ce02ae000a466cb753
PEiD: -
norman sandbox: [ General information ]<br /> * **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: [email protected] - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.<br /> * File length: 73728 bytes.<br /><br /> [ Process/window information ]<br /> * Modifies other process memory.<br /> * Modifies execution flow of a remote process.<br /><br />
Hello,
naked164.com - Packed.Win32.CPEX-based.ao
New malicious software was found in this file. It's detection will be included
in the next update. Thank you for your help.
Please quote all when answering.