Complete scanning result of "amigo.scr", received in VirusTotal at 07.04.2006, 14:05:02 (CET). Antivirus Version Update Result AntiVir 6.35.0.20 07.04.2006 TR/Dldr.Ba.any.44.D Authentium 4.93.8 07.03.2006 no virus found Avast 4.7.844.0 07.03.2006 no virus found AVG 386 07.03.2006 no virus found BitDefender 7.2 07.04.2006 BehavesLike:Trojan.Downloader CAT-QuickHeal 8.00 07.03.2006 (Suspicious) - DNAScan ClamAV devel-20060426 07.03.2006 no virus found DrWeb 4.33 07.04.2006 no virus found eTrust-InoculateIT 23.72.57 07.04.2006 no virus found eTrust-Vet 12.6.2285 07.04.2006 no virus found Ewido 3.5 07.04.2006 no virus found Fortinet 2.77.0.0 07.03.2006 suspicious F-Prot 3.16f 07.03.2006 no virus found F-Prot4 4.2.1.29 07.03.2006 Possibly a new unknown PE_Virus!Maximus Ikarus 0.2.65.0 07.03.2006 no virus found Kaspersky 4.0.2.24 07.04.2006 no virus found McAfee 4798 07.03.2006 no virus found Microsoft 1.1481 07.01.2006 no virus found NOD32v2 1.1642 07.04.2006 no virus found Norman 5.90.23 07.04.2006 W32/Downloader Panda 9.0.0.4 07.04.2006 Trj/Downloader.JKF Sophos 4.07.0 07.04.2006 no virus found Symantec 8.0 07.04.2006 no virus found TheHacker 5.9.8.168 07.03.2006 no virus found UNA 1.83 07.03.2006 no virus found VBA32 3.11.0 07.04.2006 no virus found VirusBuster 4.3.7:9 07.03.2006 no virus found Aditional Information File size: 18776 bytes MD5: d4673e661e5cbbe50886685338d9ade7 SHA1: 74a7cb1339583eea3cda3d8c84c9e7743cf4ce8f packers: UPack Norman SandBox: [ General information ] * **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**. * File length: 18776 bytes. [ Changes to filesystem ] * Creates file C:88770.txt. * Creates file C:9273.scr. * Deletes file c:88770.txt. [ Network services ] * Downloads file from http://www.parkeerplan.nl/config/.../humor.scr as c:88770.txt. [ Security issues ] * Starting downloaded file - potential security problem. [ Process/window information ] * Attemps to open http://cts.uol.com.br/formulario.html?imagem=6148&sec=amizade|Abra%E7o NULL. * Attemps to open c:9273.scr NULL.