An exception occurred when a friend opened an xls file in his mailbox: whether to save the file is displayed every time the xls file is closed:
This is true even if no changes are made.
Ask a friend to check the security settings in Excel (the menu "tools/macros/Security") has been set to "medium ".
I suspected that my friend had a virus on his computer and asked him to send the suspicious xls file to me for examination. Upload the file to a multi-engine online scan website for detection. Results:
Http://r.virscan.org/report/5b962c07bf4e8890d8ed50d63f8e1833.html
| Scan results: |
75% of soft killer (27/36) reports detected viruses |
| Time: |
11:02:05 (CST) |
| Software name |
Engine Version |
Virus database version |
Virus database time |
Scan results |
Time |
| A-squared |
5.1.0.4 |
20120120060237 |
2012-01-20 |
Virus. x97m. laroux! Ik |
0.417 |
| AntiVir |
8.2.8.34 |
7.11.21.106 |
2012-01-19 |
X2000m/laroux. Ja |
0.323 |
| Arcavir |
2011 |
201201191419 |
2012-01-19 |
- |
3.484 |
| Authentium |
5.1.1 |
201201191513 |
2012-01-19 |
X97m/escop. A (exact) |
1.678 |
| Avast! |
4.7.4 |
120119-2 |
2012-01-19 |
- |
0.012 |
| AVG |
10.0.1405 |
2090/4754 |
2012-01-19 |
X97m/laroux |
0.086 |
| BitDefender |
7.90123.7902459 |
7.40668 |
2012-01-20 |
X97m. Escape. d |
4.075 |
| ClamAV |
0.97.1 |
14327 |
2012-01-20 |
- |
0.011 |
| Comodo |
5.1 |
11315 |
2012-01-19 |
Unclassifiedmalware |
2.114 |
| CP secure |
1.3.0.5 |
2012.01.19 |
2012-01-19 |
- |
0.015 |
| Dr. Web |
7.0.0.000050 |
2012.01.20 |
2012-01-20 |
X97m. escape.4 |
11.257 |
| F-Prot |
4.6.2.117 |
20120119 |
2012-01-19 |
X97m/escop. A (exact) |
0.789 |
| F-Secure |
7.02.73807 |
2012.01.10.04 |
2012-01-10 |
Virus. MSExcel. laroux. Ja [AVP] |
0.162 |
| Gdata |
22.3553 |
20120120 |
2012-01-20 |
X97m. Escape. d [Engine: A] |
4.798 |
| Ikarus |
T3.1.32.20.0 |
2012.01.19.80282 |
2012-01-19 |
Virus. x97m. laroux |
5.068 |
| Microsoft |
1.8001 |
2012.01.20 |
2012-01-20 |
Virus: XM/Manalo. B |
3.362 |
| NOD32 |
3.0.21 |
6809 |
2012-01-19 |
X97m/escop. A virus |
0.018 |
| Nprotect |
20120119.01 |
11825533 |
2012-01-19 |
X97m. Escape. d |
1.269 |
| Quick heal |
11.00 |
2012.01.18 |
2012-01-18 |
Xm97.laroux. Ja |
0.912 |
| Sophos |
3.27.0 |
4.73 |
2012-01-20 |
XM/laroux-AP |
4.635 |
| Sunbelt |
3.9.2526.2 |
11424 |
2012-01-19 |
- |
0.697 |
| The hacker |
6.7.0.1 |
V00383 |
2012-01-19 |
X97m/generico |
0.505 |
| Vba32 |
3.12.16.4 |
20120119.1207 |
2012-01-19 |
- |
3.706 |
| ViRobot |
20120119 |
2012.01.19 |
2012-01-19 |
- |
0.346 |
| Virusbuster |
5.4.0.10 |
14.1.177.0/7439040 |
2012-01-20 |
Excel.97.escop. |
0.042 |
| Kaspersky |
5.5.10 |
2012.01.20 |
2012-01-20 |
Virus. MSExcel. laroux. Ja |
0.040 |
| Dr. an v3 |
2012.01.19.03 |
2012.01.19 |
2012-01-19 |
X97m/ecsys |
3.852 |
| CERT |
2.0.18 |
20120119.15862973 |
2012-01-19 |
- |
0.017 |
| Jiangmin Anti-Virus |
13.0.900 |
2011.11.26 |
2011-11-26 |
XM/laroux. ZB |
1.913 |
| Panda guard |
9.05.01 |
2012.01.19 |
2012-01-19 |
X97m/laroux. Oy |
2.494 |
| Rising |
20.0 |
23.93.02.01 |
2012-01-18 |
Macro. Excel. Manalo. |
0.908 |
| Symantec |
1.3.0.24 |
20120119.002 |
2012-01-19 |
X97m. laroux. gen |
0.061 |
| Trend Micro |
9.500-1005 |
8.722.01 |
2012-01-19 |
X97m_micro.a |
0.021 |
| McAfee |
5400.1158 |
6594 |
2012-01-19 |
X97m/laroux |
11.055 |
| Kingsoft drug overlord |
2009.2.5.15 |
2012.1.20.9 |
2012-01-20 |
Macro. Excel. agent.644 |
0.944 |
| Apsara Stack |
4.2.257 |
15.116 |
2012-01-19 |
- |
0.105 |
■ Heuristic/suspicious ■ exact
Note: even if a virus is detected in the report, it may be a soft false positive. You can determine the virus based on the virus detection results.
The macro virus is included. The 360 antivirus software on a friend's computer ignores the macro virus!