Erster Test:
Programm SlideShow aus PNG_Shot:
STATUS: FINISHEDComplete scanning result of "SlideShow.exe", received in VirusTotal at 04.29.2007, 21:52:52 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.28.0 04.27.2007 no virus found
AntiVir 7.4.0.15 04.29.2007 TR/Crypt.ULPM.Gen
Authentium 4.93.8 04.27.2007 no virus found
Avast 4.7.981.0 04.26.2007 no virus found
AVG 7.5.0.467 04.29.2007 no virus found
BitDefender 7.2 04.29.2007 no virus found
CAT-QuickHeal 9.00 04.28.2007 (Suspicious) - DNAScan
ClamAV devel-20070416 04.29.2007 no virus found
DrWeb 4.33 04.29.2007 no virus found
eSafe 7.0.15.0 04.29.2007 suspicious Trojan/Worm
eTrust-Vet 30.7.3601 04.27.2007 no virus found
Ewido 4.0 04.29.2007 no virus found
FileAdvisor 1 04.29.2007 no virus found
Fortinet 2.85.0.0 04.29.2007 suspicious
F-Prot 4.3.2.48 - no virus found
F-Secure 6.70.13030.0 04.29.2007 no virus found
Ikarus T3.1.1.5 04.29.2007 Backdoor.Win32.Agent.JV
Kaspersky 4.0.2.24 04.29.2007 no virus found
McAfee 5019 04.27.2007 no virus found
Microsoft 1.2405 04.29.2007 no virus found
NOD32v2 2227 04.29.2007 no virus found
Norman 5.80.02 04.27.2007 no virus found
Panda 9.0.0.4 04.29.2007 no virus found
Prevx1 V2 04.29.2007 no virus found
Sophos 4.17.0 04.28.2007 Mal/Packer
Sunbelt 2.2.907.0 04.19.2007 VIPRE.Suspicious
Symantec 10 04.29.2007 Bloodhound.Overpacked
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.29.2007 no virus found
VirusBuster 4.3.7:9 04.29.2007 no virus found
Webwasher-Gateway 6.0.1 04.29.2007 Trojan.Crypt.ULPM.Gen
Aditional Information
File size: 71680 bytes
MD5: 3b11c16549fac0236f7dd681eea78589
SHA1: 9589f081c3319eb30f968aede0c24b24da60b826
packers: UPX
packers: PECRYPT, UPX
packers: UPX
Zweiter Test:
ImagePrinter.exe, das war das letzte Ereignis vor rund einer Woche.
File ist fast 1 1/2 Jahre alt und nicht geändert worden.
STATUS: FINISHEDComplete scanning result of "ImagePrinter.exe", received in VirusTotal at 04.29.2007, 22:09:30 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.28.0 04.27.2007 no virus found
AntiVir 7.4.0.15 04.29.2007 no virus found
Authentium 4.93.8 04.27.2007 no virus found
Avast 4.7.981.0 04.26.2007 no virus found
AVG 7.5.0.467 04.29.2007 no virus found
BitDefender 7.2 04.29.2007 no virus found
CAT-QuickHeal 9.00 04.28.2007 (Suspicious) - DNAScan
ClamAV devel-20070416 04.29.2007 no virus found
DrWeb 4.33 04.29.2007 no virus found
eSafe 7.0.15.0 04.29.2007 suspicious Trojan/Worm
eTrust-Vet 30.7.3601 04.27.2007 no virus found
Ewido 4.0 04.29.2007 no virus found
FileAdvisor 1 04.29.2007 no virus found
Fortinet 2.85.0.0 04.29.2007 suspicious
F-Prot 4.3.2.48 04.27.2007 no virus found
F-Secure 6.70.13030.0 04.29.2007 no virus found
Ikarus T3.1.1.5 04.29.2007 no virus found
Kaspersky 4.0.2.24 04.29.2007 no virus found
McAfee 5019 04.27.2007 no virus found
Microsoft 1.2405 04.29.2007 no virus found
NOD32v2 2227 04.29.2007 no virus found
Norman 5.80.02 04.27.2007 no virus found
Panda 9.0.0.4 04.29.2007 no virus found
Prevx1 V2 04.29.2007 no virus found
Sophos 4.17.0 04.28.2007 Mal/Packer
Sunbelt 2.2.907.0 04.19.2007 VIPRE.Suspicious
Symantec 10 04.29.2007 Bloodhound.Overpacked
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.29.2007 no virus found
VirusBuster 4.3.7:9 04.29.2007 no virus found
Webwasher-Gateway 6.0.1 04.29.2007 Win32.Malware.gen (suspicious)
Aditional Information
File size: 87552 bytes
MD5: 6e7754b83e28f3d4789b4e06e431f646
SHA1: 84171318d790fd794c01d14f2f4902687293029f
packers: UPX
packers: PECRYPT, UPX
packers: UPX
Dritter Test:
(damit hat es eigentlich angefangen) RkAUnInst.exe
STATUS: FINISHEDComplete scanning result of "RkAUnInst.exe", received in VirusTotal at 04.29.2007, 22:21:39 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.28.0 04.27.2007 no virus found
AntiVir 7.4.0.15 04.29.2007 TR/Crypt.ULPM.Gen
Authentium 4.93.8 04.27.2007 no virus found
Avast 4.7.981.0 04.26.2007 no virus found
AVG 7.5.0.467 04.29.2007 no virus found
BitDefender 7.2 04.29.2007 no virus found
CAT-QuickHeal 9.00 04.28.2007 (Suspicious) - DNAScan
ClamAV devel-20070416 04.29.2007 no virus found
DrWeb 4.33 04.29.2007 no virus found
eSafe 7.0.15.0 04.29.2007 suspicious Trojan/Worm
eTrust-Vet 30.7.3601 04.27.2007 no virus found
Ewido 4.0 04.29.2007 no virus found
FileAdvisor 1 04.29.2007 no virus found
Fortinet 2.85.0.0 04.29.2007 suspicious
F-Prot 4.3.2.48 - no virus found
F-Secure 6.70.13030.0 04.29.2007 no virus found
Ikarus T3.1.1.5 04.29.2007 no virus found
Kaspersky 4.0.2.24 04.29.2007 no virus found
McAfee 5019 04.27.2007 no virus found
Microsoft 1.2405 04.29.2007 no virus found
NOD32v2 2227 04.29.2007 no virus found
Norman 5.80.02 04.27.2007 no virus found
Panda 9.0.0.4 04.29.2007 no virus found
Prevx1 V2 04.29.2007 no virus found
Sophos 4.17.0 04.28.2007 Mal/Packer
Sunbelt 2.2.907.0 04.19.2007 VIPRE.Suspicious
Symantec 10 04.29.2007 Bloodhound.Overpacked
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.29.2007 no virus found
VirusBuster 4.3.7:9 04.29.2007 no virus found
Webwasher-Gateway 6.0.1 04.29.2007 Trojan.Crypt.ULPM.Gen
Aditional Information
File size: 7680 bytes
MD5: d408c53b942ad836e1ef3da8586b9572
SHA1: 27d72013985551c06c42ed3f668e916a6f3e9a54
packers: UPX
packers: PECRYPT, UPX
packers: UPX
Test Nummer 4:
WBahnUpdater, seit fast 2 Jahren nicht geändert. Kam nur durch Zufall drauf:
STATUS: FINISHEDComplete scanning result of "wbup.exe", received in VirusTotal at 04.29.2007, 22:32:24 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.28.0 04.27.2007 no virus found
AntiVir 7.4.0.15 04.29.2007 TR/Crypt.ULPM.Gen
Authentium 4.93.8 04.27.2007 no virus found
Avast 4.7.981.0 04.26.2007 no virus found
AVG 7.5.0.467 04.29.2007 no virus found
BitDefender 7.2 04.29.2007 no virus found
CAT-QuickHeal 9.00 04.28.2007 (Suspicious) - DNAScan
ClamAV devel-20070416 04.29.2007 no virus found
DrWeb 4.33 04.29.2007 no virus found
eSafe 7.0.15.0 04.29.2007 suspicious Trojan/Worm
eTrust-Vet 30.7.3601 04.27.2007 no virus found
Ewido 4.0 04.29.2007 no virus found
FileAdvisor 1 04.29.2007 no virus found
Fortinet 2.85.0.0 04.29.2007 suspicious
F-Prot 4.3.2.48 - no virus found
F-Secure 6.70.13030.0 04.29.2007 no virus found
Ikarus T3.1.1.5 04.29.2007 no virus found
Kaspersky 4.0.2.24 04.29.2007 no virus found
McAfee 5019 04.27.2007 no virus found
Microsoft 1.2405 04.29.2007 no virus found
NOD32v2 2227 04.29.2007 no virus found
Norman 5.80.02 04.27.2007 no virus found
Panda 9.0.0.4 04.29.2007 Suspicious file
Prevx1 V2 04.29.2007 no virus found
Sophos 4.17.0 04.28.2007 Mal/Packer
Sunbelt 2.2.907.0 04.19.2007 VIPRE.Suspicious
Symantec 10 04.29.2007 Bloodhound.Overpacked
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.29.2007 no virus found
VirusBuster 4.3.7:9 04.29.2007 no virus found
Webwasher-Gateway 6.0.1 04.29.2007 Trojan.Crypt.ULPM.Gen
Aditional Information
File size: 9216 bytes
MD5: 24e736623b01e76827e4cdd1ffa31e57
SHA1: 70bfca87c198866960951d2de247a943400a0cd5
packers: UPX
packers: PECRYPT, UPX
packers: UPX
Und die Quintessenz: Es sind immer die Gleichen die "Alarm" brüllen
obwohl nicht los ist.
Frei nach dem Motto: Ist der Ruf erst ruiniert, schreiben sich Viren vollkommen
ungeniert (Kotz, Brösel

, vor mich hin brubbel)
Und Test Nummer 5:
Der ImagePrinter, gestern neu compiliert. Hinterher mit UPX gepackt.
STATUS: FINISHEDComplete scanning result of "ImagePrinter.exe", received in VirusTotal at 04.29.2007, 22:58:40 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.28.0 04.27.2007 no virus found
AntiVir 7.4.0.15 04.29.2007 no virus found
Authentium 4.93.8 04.27.2007 no virus found
Avast 4.7.981.0 04.26.2007 no virus found
AVG 7.5.0.467 04.29.2007 no virus found
BitDefender 7.2 04.29.2007 no virus found
CAT-QuickHeal 9.00 04.28.2007 no virus found
ClamAV devel-20070416 04.29.2007 no virus found
DrWeb 4.33 04.29.2007 no virus found
eSafe 7.0.15.0 04.29.2007 suspicious Trojan/Worm
eTrust-Vet 30.7.3601 04.27.2007 no virus found
Ewido 4.0 04.29.2007 no virus found
FileAdvisor 1 04.29.2007 no virus found
Fortinet 2.85.0.0 04.29.2007 suspicious
F-Prot 4.3.2.48 04.27.2007 no virus found
F-Secure 6.70.13030.0 04.29.2007 no virus found
Ikarus T3.1.1.5 04.29.2007 no virus found
Kaspersky 4.0.2.24 04.29.2007 no virus found
McAfee 5019 04.27.2007 no virus found
Microsoft 1.2405 04.29.2007 no virus found
NOD32v2 2228 04.29.2007 no virus found
Norman 5.80.02 04.27.2007 no virus found
Panda 9.0.0.4 04.29.2007 no virus found
Prevx1 V2 04.29.2007 no virus found
Sophos 4.17.0 04.28.2007 no virus found
Sunbelt 2.2.907.0 04.19.2007 no virus found
Symantec 10 04.29.2007 no virus found
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.29.2007 no virus found
VirusBuster 4.3.7:9 04.29.2007 no virus found
Webwasher-Gateway 6.0.1 04.29.2007 no virus found
Aditional Information
File size: 90112 bytes
MD5: a890bbb05c55cf58551055bccd88f7a1
SHA1: f48b671e7fc5f784f900ef0b5085ad5dc02c64ae
packers: UPX
Test Nummer 6:
Und das gleiche noch einmal, aber diesmal ohne Packer
STATUS: FINISHEDComplete scanning result of "ImagePrinter.exe", received in VirusTotal at 04.29.2007, 23:06:24 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.4.28.0 04.27.2007 no virus found
AntiVir 7.4.0.15 04.29.2007 no virus found
Authentium 4.93.8 04.27.2007 no virus found
Avast 4.7.981.0 04.26.2007 no virus found
AVG 7.5.0.467 04.29.2007 no virus found
BitDefender 7.2 04.29.2007 no virus found
CAT-QuickHeal 9.00 04.28.2007 no virus found
ClamAV devel-20070416 04.29.2007 no virus found
DrWeb 4.33 04.29.2007 no virus found
eSafe 7.0.15.0 04.29.2007 no virus found
eTrust-Vet 30.7.3601 04.27.2007 no virus found
Ewido 4.0 04.29.2007 no virus found
FileAdvisor 1 04.29.2007 no virus found
Fortinet 2.85.0.0 04.29.2007 suspicious
F-Prot 4.3.2.48 - no virus found
F-Secure 6.70.13030.0 04.29.2007 no virus found
Ikarus T3.1.1.5 04.29.2007 no virus found
Kaspersky 4.0.2.24 04.29.2007 no virus found
McAfee 5019 04.27.2007 no virus found
Microsoft 1.2405 04.29.2007 no virus found
NOD32v2 2228 04.29.2007 no virus found
Norman 5.80.02 04.27.2007 no virus found
Panda 9.0.0.4 04.29.2007 no virus found
Prevx1 V2 04.29.2007 no virus found
Sophos 4.17.0 04.28.2007 no virus found
Sunbelt 2.2.907.0 04.19.2007 no virus found
Symantec 10 04.29.2007 no virus found
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.29.2007 no virus found
VirusBuster 4.3.7:9 04.29.2007 no virus found
Webwasher-Gateway 6.0.1 04.29.2007 Win32.Malware.gen!80 (suspicious)
Aditional Information
File size: 260096 bytes
MD5: ebf7d2202bd2aa67f37b5028105cf05b
SHA1: 860995765c7e66c3a4fc8af87f13d361433dc2ff
Zweites Fazit:
Mindestens 2 Scanner sind totaler Schrott ...
Aber ich schreibe hier noch einmal zusätzlich hin, es hat nix mit dem Packer
zu tun, weil es sich im Februar/März gezeigt hat, das die exe auch dann für Alarm
sorgt, wenn nicht gepackt ist. Zumindest war dies für Avira zutreffend.
Gruß Jens