Holy shit, quadruple post..
File deleted!Quote:
Complete scanning result of "_Valve__Aimbot_v3.exe", received in VirusTotal at 04.22.2007, 07:37:42 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.21.0 04.20.2007 no virus found
AntiVir 7.3.1.53 04.20.2007 no virus found
Authentium 4.93.8 04.20.2007 no virus found
Avast 4.7.981.0 04.21.2007 no virus found
AVG 7.5.0.464 04.21.2007 no virus found
BitDefender 7.2 04.22.2007 no virus found
CAT-QuickHeal 9.00 04.21.2007 W32.Brontok.Q
ClamAV devel-20070416 04.21.2007 no virus found
DrWeb 4.33 04.21.2007 no virus found
eSafe 7.0.15.0 04.19.2007 suspicious Trojan/Worm
eTrust-Vet 30.7.3585 04.21.2007 no virus found
Ewido 4.0 04.21.2007 no virus found
FileAdvisor 1 04.22.2007 no virus found
Fortinet 2.85.0.0 04.22.2007 PossibleThreat!020622
F-Prot 4.3.2.48 04.20.2007 no virus found
F-Secure 6.70.13030.0 04.21.2007 W32/Suspicious_M.gen.dropper
Ikarus T3.1.1.5 04.22.2007 IM-Worm.Win32.Sumom.C
Kaspersky 4.0.2.24 04.22.2007 no virus found
McAfee 5014 04.20.2007 no virus found
Microsoft 1.2405 04.22.2007 no virus found
NOD32v2 2209 04.21.2007 no virus found
Norman 5.80.02 04.21.2007 Bofra.C@mm.dropper
Panda 9.0.0.4 04.21.2007 Suspicious file
Prevx1 V2 04.22.2007 Trojan.Keylogger
Sophos 4.16.0 04.20.2007 Mal/Packer
Sunbelt 2.2.907.0 04.19.2007 W32/MEWpacked.gen
Symantec 10 04.22.2007 no virus found
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.21.2007 no virus found
VirusBuster 4.3.7:9 04.21.2007 Packed/MEW
Webwasher-Gateway 6.0.1 04.22.2007 Win32.Malware.gen#MEW (suspicious)
Aditional Information
File size: 140731 bytes
MD5: c737ae1ebacbdeaa5a6bc9e492ca3ea9
SHA1: fbc7b2c0c661c2dfbc22d2793d9eaa755d40aa1c
packers: MEW, BINARYRES, MEW
packers: MEW
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: [Only registered and activated users can see links. Click Here To Register...] - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Decompressing Mew.
* Accesses executable file from resource section.
* File length: 140731 bytes.
[ Changes to filesystem ]
* Creates file convhd8.exe.
[ Process/window information ]
* Attemps to NULL convhd8.exe .
[ Signature Scanning ]
* convhd8.exe (127426 bytes) : Bofra.C@mm.
Prevx info: [Only registered and activated users can see links. Click Here To Register...]