I had send this file to virus (at) avast (dot) com at 2010/6/12, but Avast dosen’t say that the files in the zipped file are trojan.
The password of this file is “virus” (quotes excluded).
http://www.sendspace.com/file/cyorqj
I recheck it by VirusTotal, some famous AVs say it is a trojan. I don’t know why AVAST think it is safe.
Antivirus Version Last Update Result a-squared 5.0.0.30 2010.06.21 Trojan-Dropper.MSExcel.Agent!IK AhnLab-V3 2010.06.20.00 2010.06.19 - AntiVir 8.2.2.6 2010.06.21 - Antiy-AVL 2.0.3.7 2010.06.18 - Authentium 5.2.0.5 2010.06.21 MSExcel/Dropper.B!Camelot Avast 4.8.1351.0 2010.06.21 - Avast5 5.0.332.0 2010.06.21 - AVG 9.0.0.787 2010.06.21 - BitDefender 7.2 2010.06.21 - CAT-QuickHeal 10.00 2010.06.18 - ClamAV 0.96.0.3-git 2010.06.21 - Comodo 5172 2010.06.21 TrojWare.MSExcel.TrojanDropper.Agent.bc DrWeb 5.0.2.03300 2010.06.21 - eSafe 7.0.17.0 2010.06.20 - eTrust-Vet 36.1.7650 2010.06.19 - F-Prot 4.6.1.107 2010.06.20 - F-Secure 9.0.15370.0 2010.06.21 - Fortinet 4.1.133.0 2010.06.20 - GData 21 2010.06.21 - Ikarus T3.1.1.84.0 2010.06.21 Trojan-Dropper.MSExcel.Agent Jiangmin 13.0.900 2010.06.15 Heur:Exploit.CVE-2009-3129 Kaspersky 7.0.0.125 2010.06.21 Trojan-Dropper.MSExcel.Agent.bc McAfee 5.400.0.1158 2010.06.21 Exploit-MSExcel.u McAfee-GW-Edition 2010.1 2010.06.21 Exploit-MSExcel.u Microsoft 1.5902 2010.06.21 Exploit:Win32/CVE-2009-3129 NOD32 5214 2010.06.21 - Norman 6.05.06 2010.06.20 - nProtect 2010-06-21.01 2010.06.21 - Panda 10.0.2.7 2010.06.20 - PCTools 7.0.3.5 2010.06.21 HeurEngine.MaliciousExploit Rising 22.53.00.04 2010.06.21 - Sophos 4.54.0 2010.06.21 - Sunbelt 6482 2010.06.21 - Symantec 20101.1.0.89 2010.06.21 Bloodhound.Exploit.306 TheHacker 6.5.2.0.302 2010.06.20 - TrendMicro 9.120.0.1004 2010.06.20 TROJ_EXELDROP.A TrendMicro-HouseCall 9.120.0.1004 2010.06.21 TROJ_EXELDROP.A VBA32 3.12.12.5 2010.06.21 - ViRobot 2010.6.21.3896 2010.06.21 - VirusBuster 5.0.27.0 2010.06.21 -