Select local site

| Japanese | Simplified Chinese | Traditional Chinese (Hong Kong) | Traditional Chinese (Taiwan)

F-Secure Hoax Information Pages: EYES.EXE

[Summary] | [Detailed Description]

Name : EYES.EXE
Alias:EYES.EXE false alarm
Type:Hoax
Category:Hoax
Platform:Win32
Radar

Summary
EYES.EXE or WINEYES.EXE caused alarms similar to GHOST and SHEEP.
Back to the Top

Detailed Description
It is a simple demo program which has created a lot of warnings. This program was analyzed and found harmless.

Naturally, whenever any program is declared clean, there is a risk that somebody will take the file and infect it - since people will now trust it. To overcome this problem, you can verify the files against the 32-bit CRC's of the confirmed clean versions (as displayed by PKUNZIP):

Length Method Size Ratio Date Time CRC-32 Attr Name
------ ------ ----- ----- ---- ---- -------- ---- ----
317792 DeflatN 117014 64% 09-12-96 08:25 683ae9da --w- SHEEP.EXE
317088 DeflatN 116749 64% 03-12-96 22:17 3662678a --w- SCMPOO16.EXE
28096 DeflatN 14145 50% 30-10-96 13:20 5dce8738 --w- GHOST.EXE
28064 DeflatN 14142 50% 13-11-96 13:45 a6839c30 --w- GHOST2.EXE
28065 DeflatX 14121 50% 11-22-96 12:11 f47d5cbd --w- GHOST3.EXE
54048 DeflatX 9157 84% 11-15-96 14:42 ba2cda0b --w- EYES.EXE

------ ------ --- -------

Read this: As speculated above, a malicious person can easily infect any of these programs and make them harmful. In June 1997, we received a samples of the above SHEEP.EXE infected with the Windows-based Tentacle virus.

Here is the CRC of the infected version (as displayed by PKUNZIP):

Length Method Size Ratio Date Time CRC-32 Attr Name
------ ------ ----- ----- ---- ---- -------- ---- ----
319750 DeflatN 118568 63% 26-06-97 18:16 60a4617a --w- ESHEEP.EXE
------ ------ --- -------


It is recommended not to run any programs that you receive from people you do not know.
Back to the Top



F-Secure Corporation

Last Modified: January 01, 2006