EndurerOriginal
2Version
2006-09-131Version
A netizen's computer experienced a strange phenomenon. Double-click *. EXE to generate *~. Exe. if you double-click a.exe, A ~ is generated ~. EXE.
Four files are concurrently added: setup.exe and setup ~. EXE, frozen throne.exe, and frozen throne ~. EXE.
203,261 setup.exe
107,513 setup ~. EXE
Increase 95748 = 0x17604 bytes
370,181 frozen throne.exe
274,433 frozen throne ~. EXE
Increase 95748 = 0x17604 bytes
1、setup.exe
Rising reportsWorm. CNT.
Status: finished
Complete scanning result of "setup.exe", received in virustotal at 09.13.2006, 16:54:44 (CET ).
Antivirus |
Version |
Update |
Result |
AntiVir |
7.2.0.16 |
09.13.2006 |
Heur/malware |
Authentium |
4.93.8 |
09.13.2006 |
No virus found |
Avast |
4.7.844.0 |
09.13.2006 |
No virus found |
AVG |
386 |
09.12.2006 |
Downloader. generic2.ofo |
BitDefender |
7.2 |
09.13.2006 |
Trojan. Downloader. Agent. ajy |
Cat-quickheal |
8.00 |
09.13.2006 |
No virus found |
ClamAV |
Devel-20060426 |
09.13.2006 |
No virus found |
Drweb |
4.33 |
09.13.2006 |
Trojan. downloader.12699 |
ETrust-inoculateit |
23.72.123 |
09.13.2006 |
No virus found |
ETrust-vet |
30.3.3076 |
09.13.2006 |
No virus found |
Ewido |
4.0 |
09.13.2006 |
Downloader. Delf. awy |
Fortinet |
2.77.0.0 |
09.13.2006 |
No virus found |
F-Prot |
3.16f |
09.13.2006 |
No virus found |
F-Prot4 |
4.2.1.29 |
09.13.2006 |
No virus found |
Ikarus |
0.2.65.0 |
09.12.2006 |
No virus found |
Kaspersky |
4.0.2.24 |
09.13.2006 |
Trojan-Downloader.Win32.Delf.awy |
McAfee |
4850 |
09.12.2006 |
No virus found |
Microsoft |
1.1560 |
09.13.2006 |
No virus found |
Nod32v2 |
1.1754 |
09.13.2006 |
Probably unknown newheur_pe Virus |
Norman |
5.90.23 |
09.13.2006 |
W32/dloader. avlv |
Panda |
9.0.0.4 |
09.12.2006 |
Suspicious File |
Sophos |
4.09.0 |
09.13.2006 |
No virus found |
Symantec |
8.0 |
09.13.2006 |
Downloader |
Thehacker |
5.9.8.210 |
09.13.2006 |
No virus found |
Una |
1.83 |
09.11.2006 |
No virus found |
Vba32 |
3.11.1 |
09.12.2006 |
No virus found |
Virusbuster |
4.3.7: 9 |
09.13.2006 |
No virus found |
Aditional Information |
File Size: 203261 bytes |
MD5: 745daa5ca7e831936a94c598ec485695 |
Sha1: aa89187dd286106840d8f125fd99dde4b3a364f3 |
2. Setup ~ 1. exe
Status: finishedcomplete scanning result of "setup_.exe", initialized ed in virustotal at 09.13.2006, 17:04:48 (CET ).
Antivirus |
Version |
Update |
Result |
AntiVir |
7.2.0.16 |
09.13.2006 |
No virus found |
Authentium |
4.93.8 |
09.13.2006 |
No virus found |
Avast |
4.7.844.0 |
09.13.2006 |
No virus found |
AVG |
386 |
09.12.2006 |
No virus found |
BitDefender |
7.2 |
09.13.2006 |
No virus found |
Cat-quickheal |
8.00 |
09.13.2006 |
No virus found |
ClamAV |
Devel-20060426 |
09.13.2006 |
No virus found |
ETrust-inoculateit |
23.72.123 |
09.13.2006 |
No virus found |
ETrust-vet |
30.3.3076 |
09.13.2006 |
No virus found |
Drweb |
4.33 |
09.13.2006 |
No virus found |
Ewido |
4.0 |
09.13.2006 |
No virus found |
Fortinet |
2.77.0.0 |
09.13.2006 |
Suspicious |
F-Prot |
3.16f |
09.13.2006 |
No virus found |
F-Prot4 |
4.2.1.29 |
09.13.2006 |
No virus found |
Ikarus |
0.2.65.0 |
09.12.2006 |
No virus found |
Kaspersky |
4.0.2.24 |
09.13.2006 |
No virus found |
McAfee |
4850 |
09.12.2006 |
No virus found |
Microsoft |
1.1560 |
09.13.2006 |
No virus found |
Nod32v2 |
1.1754 |
09.13.2006 |
No virus found |
Norman |
5.80.02 |
09.13.2006 |
No virus found |
Panda |
9.0.0.4 |
09.12.2006 |
No virus found |
Sophos |
4.09.0 |
09.13.2006 |
No virus found |
Symantec |
8.0 |
09.13.2006 |
No virus found |
Thehacker |
5.9.8.210 |
09.13.2006 |
No virus found |
Una |
1.83 |
09.11.2006 |
No virus found |
Vba32 |
3.11.1 |
09.12.2006 |
No virus found |
Virusbuster |
4.3.7: 9 |
09.13.2006 |
No virus found |
Aditional Information |
File Size: 107513 bytes |
MD5: e4e9e999ab14699cd0277c0c552a2aa8 |
Sha1: bf2501e95d100595b72401689b3e10093f05da2c |
32.16frozen_throne.exe
Rising reportsWorm. CNT.
Status: finishedcomplete scanning result of "frozen_throne.exe", initialized ed in virustotal at 09.13.2006, 17:15:37 (CET ).
Antivirus |
Version |
Update |
Result |
AntiVir |
7.2.0.16 |
09.13.2006 |
Heur/malware |
Authentium |
4.93.8 |
09.13.2006 |
No virus found |
Avast |
4.7.844.0 |
09.13.2006 |
No virus found |
AVG |
386 |
09.12.2006 |
Downloader. generic2.ofo |
BitDefender |
7.2 |
09.13.2006 |
Trojan. Downloader. Agent. ajy |
Cat-quickheal |
8.00 |
09.13.2006 |
No virus found |
ClamAV |
Devel-20060426 |
09.13.2006 |
No virus found |
Drweb |
4.33 |
09.13.2006 |
Trojan. downloader.12699 |
ETrust-inoculateit |
23.72.123 |
09.13.2006 |
No virus found |
ETrust-vet |
30.3.3076 |
09.13.2006 |
No virus found |
Ewido |
4.0 |
09.13.2006 |
Downloader. Delf. awy |
Fortinet |
2.77.0.0 |
09.13.2006 |
Suspicious |
F-Prot |
3.16f |
09.13.2006 |
No virus found |
F-Prot4 |
4.2.1.29 |
09.13.2006 |
No virus found |
Ikarus |
0.2.65.0 |
09.12.2006 |
No virus found |
Kaspersky |
4.0.2.24 |
09.13.2006 |
Trojan-Downloader.Win32.Delf.awy |
McAfee |
4850 |
09.12.2006 |
No virus found |
Microsoft |
1.1560 |
09.13.2006 |
No virus found |
Nod32v2 |
1.1754 |
09.13.2006 |
Probably unknown newheur_pe Virus |
Norman |
5.90.23 |
09.13.2006 |
W32/dloader. avlv |
Panda |
9.0.0.4 |
09.12.2006 |
Suspicious File |
Sophos |
4.09.0 |
09.13.2006 |
No virus found |
Symantec |
8.0 |
09.13.2006 |
Downloader |
Thehacker |
5.9.8.210 |
09.13.2006 |
No virus found |
Una |
1.83 |
09.11.2006 |
No virus found |
Vba32 |
3.11.1 |
09.12.2006 |
No virus found |
Virusbuster |
4.3.7: 9 |
09.13.2006 |
No virus found |
Aditional Information |
File Size: 370181 bytes |
MD5: 87db7215d1e4d67de45dc297628f847a |
Sha1: 83522edab281e6791de9fce663a5123d0e55b623 |
4. Frozen throne ~. EXE
Status: finishedcomplete scanning result of "frozen_throne_.exe", initialized ed in virustotal at 09.13.2006, 16:43:48 (CET ).
Antivirus |
Version |
Update |
Result |
AntiVir |
7.2.0.16 |
09.13.2006 |
No virus found |
Authentium |
4.93.8 |
09.13.2006 |
No virus found |
Avast |
4.7.844.0 |
09.13.2006 |
No virus found |
AVG |
386 |
09.12.2006 |
No virus found |
BitDefender |
7.2 |
09.13.2006 |
No virus found |
Cat-quickheal |
8.00 |
09.13.2006 |
No virus found |
ClamAV |
Devel-20060426 |
09.13.2006 |
No virus found |
Drweb |
4.33 |
09.13.2006 |
No virus found |
ETrust-inoculateit |
23.72.123 |
09.13.2006 |
No virus found |
ETrust-vet |
30.3.3076 |
09.13.2006 |
No virus found |
Ewido |
4.0 |
09.13.2006 |
No virus found |
Fortinet |
2.77.0.0 |
09.13.2006 |
No virus found |
F-Prot |
3.16f |
09.13.2006 |
No virus found |
F-Prot4 |
4.2.1.29 |
09.13.2006 |
No virus found |
Ikarus |
0.2.65.0 |
09.12.2006 |
No virus found |
Kaspersky |
4.0.2.24 |
09.13.2006 |
No virus found |
McAfee |
4850 |
09.12.2006 |
No virus found |
Microsoft |
1.1560 |
09.13.2006 |
No virus found |
Nod32v2 |
1.1754 |
09.13.2006 |
No virus found |
Norman |
5.90.23 |
09.13.2006 |
No virus found |
Panda |
9.0.0.4 |
09.12.2006 |
No virus found |
Sophos |
4.09.0 |
09.13.2006 |
No virus found |
Symantec |
8.0 |
09.13.2006 |
No virus found |
Thehacker |
5.9.8.210 |
09.13.2006 |
No virus found |
Una |
1.83 |
09.11.2006 |
No virus found |
Vba32 |
3.11.1 |
09.12.2006 |
Backdoor. win32.ciadoor. 13 |
Virusbuster |
4.3.7: 9 |
09.13.2006 |
No virus found |
Aditional Information |
File Size: 274433 bytes |
MD5: 5c3d0c4e0696e694654ccd8ce4773e8e |
Sha1: f9d825469f72c6207133b5902c3715da8f37c0f8 |