[09-19]关于双击*.exe就生成*~.exe(第2版)

endurer 原创

2006-09-19 第2

2006-09-13 第1



有位网友的电脑出现了一个奇怪的现象,关于双击*.exe就生成*~.exe,如双击a.exe就生成a~.exe。

并发来了四个文件:setup.exe、setup~.exe、Frozen Throne.exe 和 Frozen Throne~.exe。


2006-09-13 22:33 203,261 setup.exe
2006-09-13 22:37 107,513 setup~.exe

增加95748=0x17604字节


2006-09-13 22:29 370,181 Frozen Throne.exe
2006-09-13 22:28 274,433 Frozen Throne~.exe

增加95748=0x17604字节



1、setup.exe

Rising 报为 Worm.Cnt.a

STATUS: FINISHED

Complete scanning result of "setup.exe", received in VirusTotal at 09.13.2006, 16:54:44 (CET).

AntivirusVersionUpdateResult
AntiVir7.2.0.1609.13.2006HEUR/Malware
Authentium4.93.809.13.2006 no virus found
Avast4.7.844.009.13.2006 no virus found
AVG38609.12.2006Downloader.Generic2.OFO
BitDefender7.209.13.2006Trojan.Downloader.Agent.AJY
CAT-QuickHeal8.0009.13.2006 no virus found
ClamAVdevel-2006042609.13.2006 no virus found
DrWeb4.3309.13.2006Trojan.DownLoader.12699
eTrust-InoculateIT23.72.12309.13.2006 no virus found
eTrust-Vet30.3.307609.13.2006 no virus found
Ewido4.009.13.2006Downloader.Delf.awy
Fortinet2.77.0.009.13.2006 no virus found
F-Prot3.16f09.13.2006 no virus found
F-Prot44.2.1.2909.13.2006 no virus found
Ikarus0.2.65.009.12.2006 no virus found
Kaspersky4.0.2.2409.13.2006Trojan-Downloader.Win32.Delf.awy
McAfee485009.12.2006 no virus found
Microsoft1.156009.13.2006 no virus found
NOD32v21.175409.13.2006probably unknown NewHeur_PE virus
Norman5.90.2309.13.2006W32/DLoader.AVLV
Panda9.0.0.409.12.2006Suspicious file
Sophos4.09.009.13.2006 no virus found
Symantec8.009.13.2006Downloader
TheHacker5.9.8.21009.13.2006 no virus found
UNA1.8309.11.2006 no virus found
VBA323.11.109.12.2006 no virus found
VirusBuster4.3.7:909.13.2006 no virus found

Aditional Information
File size: 203261 bytes
MD5: 745daa5ca7e831936a94c598ec485695
SHA1: aa89187dd286106840d8f125fd99dde4b3a364f3

2、setup~1.exe

STATUS: FINISHED
Complete scanning result of "setup_.exe", received in VirusTotal at 09.13.2006, 17:04:48 (CET).

AntivirusVersionUpdateResult
AntiVir7.2.0.1609.13.2006 no virus found
Authentium4.93.809.13.2006 no virus found
Avast4.7.844.009.13.2006 no virus found
AVG38609.12.2006 no virus found
BitDefender7.209.13.2006 no virus found
CAT-QuickHeal8.0009.13.2006 no virus found
ClamAVdevel-2006042609.13.2006 no virus found
eTrust-InoculateIT23.72.12309.13.2006 no virus found
eTrust-Vet30.3.307609.13.2006 no virus found
DrWeb4.3309.13.2006 no virus found
Ewido4.009.13.2006 no virus found
Fortinet2.77.0.009.13.2006suspicious
F-Prot3.16f09.13.2006 no virus found
F-Prot44.2.1.2909.13.2006 no virus found
Ikarus0.2.65.009.12.2006 no virus found
Kaspersky4.0.2.2409.13.2006 no virus found
McAfee485009.12.2006 no virus found
Microsoft1.156009.13.2006 no virus found
NOD32v21.175409.13.2006 no virus found
Norman5.80.0209.13.2006 no virus found
Panda9.0.0.409.12.2006 no virus found
Sophos4.09.009.13.2006 no virus found
Symantec8.009.13.2006 no virus found
TheHacker5.9.8.21009.13.2006 no virus found
UNA1.8309.11.2006 no virus found
VBA323.11.109.12.2006 no virus found
VirusBuster4.3.7:909.13.2006 no virus found

Aditional Information
File size: 107513 bytes
MD5: e4e9e999ab14699cd0277c0c552a2aa8
SHA1: bf2501e95d100595b72401689b3e10093f05da2c



3、Frozen_Throne.exe

Rising 报为 Worm.Cnt.a

STATUS: FINISHED
Complete scanning result of "Frozen_Throne.exe", received in VirusTotal at 09.13.2006, 17:15:37 (CET).

AntivirusVersionUpdateResult
AntiVir7.2.0.1609.13.2006HEUR/Malware
Authentium4.93.809.13.2006 no virus found
Avast4.7.844.009.13.2006 no virus found
AVG38609.12.2006Downloader.Generic2.OFO
BitDefender7.209.13.2006Trojan.Downloader.Agent.AJY
CAT-QuickHeal8.0009.13.2006 no virus found
ClamAVdevel-2006042609.13.2006 no virus found
DrWeb4.3309.13.2006Trojan.DownLoader.12699
eTrust-InoculateIT23.72.12309.13.2006 no virus found
eTrust-Vet30.3.307609.13.2006 no virus found
Ewido4.009.13.2006Downloader.Delf.awy
Fortinet2.77.0.009.13.2006suspicious
F-Prot3.16f09.13.2006 no virus found
F-Prot44.2.1.2909.13.2006 no virus found
Ikarus0.2.65.009.12.2006 no virus found
Kaspersky4.0.2.2409.13.2006Trojan-Downloader.Win32.Delf.awy
McAfee485009.12.2006 no virus found
Microsoft1.156009.13.2006 no virus found
NOD32v21.175409.13.2006probably unknown NewHeur_PE virus
Norman5.90.2309.13.2006W32/DLoader.AVLV
Panda9.0.0.409.12.2006Suspicious file
Sophos4.09.009.13.2006 no virus found
Symantec8.009.13.2006Downloader
TheHacker5.9.8.21009.13.2006 no virus found
UNA1.8309.11.2006 no virus found
VBA323.11.109.12.2006 no virus found
VirusBuster4.3.7:909.13.2006 no virus found

Aditional Information
File size: 370181 bytes
MD5: 87db7215d1e4d67de45dc297628f847a
SHA1: 83522edab281e6791de9fce663a5123d0e55b623




4、Frozen Throne~.exe

STATUS: FINISHED
Complete scanning result of "Frozen_Throne_.exe", received in VirusTotal at 09.13.2006, 16:43:48 (CET).

AntivirusVersionUpdateResult
AntiVir7.2.0.1609.13.2006 no virus found
Authentium4.93.809.13.2006 no virus found
Avast4.7.844.009.13.2006 no virus found
AVG38609.12.2006 no virus found
BitDefender7.209.13.2006 no virus found
CAT-QuickHeal8.0009.13.2006 no virus found
ClamAVdevel-2006042609.13.2006 no virus found
DrWeb4.3309.13.2006 no virus found
eTrust-InoculateIT23.72.12309.13.2006 no virus found
eTrust-Vet30.3.307609.13.2006 no virus found
Ewido4.009.13.2006 no virus found
Fortinet2.77.0.009.13.2006 no virus found
F-Prot3.16f09.13.2006 no virus found
F-Prot44.2.1.2909.13.2006 no virus found
Ikarus0.2.65.009.12.2006 no virus found
Kaspersky4.0.2.2409.13.2006 no virus found
McAfee485009.12.2006 no virus found
Microsoft1.156009.13.2006 no virus found
NOD32v21.175409.13.2006 no virus found
Norman5.90.2309.13.2006 no virus found
Panda9.0.0.409.12.2006 no virus found
Sophos4.09.009.13.2006 no virus found
Symantec8.009.13.2006 no virus found
TheHacker5.9.8.21009.13.2006 no virus found
UNA1.8309.11.2006 no virus found
VBA323.11.109.12.2006Backdoor.Win32.Ciadoor.13
VirusBuster4.3.7:909.13.2006 no virus found

Aditional Information
File size: 274433 bytes
MD5: 5c3d0c4e0696e694654ccd8ce4773e8e
SHA1: f9d825469f72c6207133b5902c3715da8f37c0f8
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值