楼主: sam.to
收起左侧

[病毒样本] 大量伪快播(Qvod.exe,click.exe,duogua.exe),天天更新 (637 楼有新)

  [复制链接]
jason_jiang
发表于 2010-7-31 14:53:58 | 显示全部楼层
484, 487 to xandora(panda)
sam.to
 楼主| 发表于 2010-7-31 18:04:00 | 显示全部楼层
本帖最后由 sam.to 于 2010.7.31 20:05 编辑

fe3303cae893c2f276a80d6cac5eeca0  Qvodplayer.ex6e
fa77c1f37781424a803d61905718c6a6  Qvodplayer.exe2
db6b5cf46bbb4afda0bb0add555b7de6  Qvodplayer.ex2e
c5171b51707cafd92ae084cfdbed73fa  Qvodplayer.e1xe
b2758a2a00dff44ff67dd3981a3f4fef  Qvodplayer.exe9
813d2b246cee8cd7a7ff46527dc0ea55  Qvodplayer.ex1e
7dfef042db4e59da47b5e6d36e2c9cd9  Qvodplayer.ex5e
6fc723f18af7fe22ef04f23ea52749da  Qvodplayer.e2xe
660fc97b4c2a16ec18521df0596bc4c4  Qvodplayer.exe$
3b72622abf40cbf2901301134c467c76  Qvodplayer.ex%e
2e5dea76a237293c8f4c55ae74937ae7  Qvodplayer.exe@
2494ac46ac1da013ea87a1b3270add32  Qvodplayer.ex!e
1fd15947cdcca939ab38e25f49a44f6c  Qvodplayer.exe1


to kl,ll,comodo





Hello,

Qvodplayer.e1xe, Qvodplayer.e2xe, Qvodplayer.ex!e, Qvodplayer.ex%e, Qvodplayer.ex1e, Qvodplayer.ex2e, Qvodplayer.ex5e, Qvodplayer.ex6e, Qvodplayer.exe$, Qvodplayer.exe1, Qvodplayer.exe2, Qvodplayer.exe9, Qvodplayer.exe@ - Trojan-Downloader.Win32.Agent.eczc

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

Regards, Kuskov Vladimir
Virus Analyst
jason_jiang
发表于 2010-7-31 18:18:11 | 显示全部楼层
491 to xandora(panda)
8073176430
发表于 2010-7-31 19:18:10 | 显示全部楼层
491 eset 清空
sam.to
 楼主| 发表于 2010-7-31 22:57:23 | 显示全部楼层
049c29bbe6c7a08ce2071cfbee3099b2  Qvodplayer.e1xe
099c9fb88fc00d55b2081d53da7cac31  Qvodplayer.exe3
1fd15947cdcca939ab38e25f49a44f6c  Qvodplayer.exe4
3b72622abf40cbf2901301134c467c76  Qvodplayer.exe6
6fc723f18af7fe22ef04f23ea52749da  Qvodplayer.ex8e
7521e899625da9aba56748e06bcfb676  Qvodplayer.exe1
7dfef042db4e59da47b5e6d36e2c9cd9  Qvodplayer.e3xe
813d2b246cee8cd7a7ff46527dc0ea55  Qvodplayer.ex1e
9f76ac79b6aa023d68189ef1ecc37dbc  Qvodplayer.ex3e
b2758a2a00dff44ff67dd3981a3f4fef  Qvodplayer.e#xe
c5171b51707cafd92ae084cfdbed73fa  Qvodplayer.exe^
db6b5cf46bbb4afda0bb0add555b7de6  Qvodplayer.e#e
fe3303cae893c2f276a80d6cac5eeca0  Qvodplayer.ex#e

to kl,ll,comodo
jayavira
发表于 2010-8-1 06:00:04 | 显示全部楼层
回复 495楼 sam.to  的帖子

ess 清空

ssama
发表于 2010-8-1 09:36:54 | 显示全部楼层
669964-491
669964-495
avast! 清空
jason_jiang
发表于 2010-8-1 10:54:43 | 显示全部楼层
495 to xandora(panda)
sam.to
 楼主| 发表于 2010-8-1 20:46:07 | 显示全部楼层
本帖最后由 sam.to 于 2010.8.3 18:39 编辑

03d46ac345aba7894d965ee0491ee579  click.exe2
21b2a1d84cb1182c30ccb6509a8e95fd  Qvodplayer.exe_
2b924f64c0bc72763af8d0357b93f32e  Qvodplayer.exe$
2f9d78829a2fa417537c0334d0a27ce5  Qvodplayer.e@xe
3fc03619ee97b50686a6bcaa89a092f5  click.ex1e
510e0355e210da290777c1983aea668a  Qvodplayer.exe#
51c29d9d24c898a5fba55a9e721532c2  Qvodplayer.exe!
7732f7d42fdc0f08bf3def82ac0879c5  Qvodplayer.exe1
7f36321669224f55306a052eedd09d90  Qvodplayer.e1xe
9830eba7c303c02146ccc3e884051ea7  Qvodplayer.ex@e
b6bd9e8f092b1e92b94465a5c06cf657  Qvodplayer.exe%
bead2f8d7c8bde696aedf57c2fbefa73  Qvodplayer.exe0
cf56c6bed22ba64108ba5b894226f833  Qvodplayer.exe9
d87e298ab5b495ae4b06c1a4a3a8cb1c  Qvodplayer.ex3e
e30da76da50469cb06c89e0a7598e37a  Qvodplayer.exe7

TO KL,LL,ESET,COMODO,AVIRA



A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25830541
Qvodplayer.e@xe
88.71 KB
UNDER ANALYSIS
25830542
Qvodplayer.e1xe
88.71 KB
UNDER ANALYSIS
25830543
Qvodplayer.ex@e
88.71 KB
UNDER ANALYSIS
25830544
click.ex1e
87.21 KB
UNDER ANALYSIS
25830545
Qvodplayer.ex3e
88.71 KB
UNDER ANALYSIS
25830546
Qvodplayer.exe!
88.71 KB
UNDER ANALYSIS
25830547
Qvodplayer.exe#
88.71 KB
UNDER ANALYSIS
25830548
Qvodplayer.exe$
88.71 KB
UNDER ANALYSIS
25830549
Qvodplayer.exe%
88.71 KB
UNDER ANALYSIS
25830550
Qvodplayer.exe_
88.71 KB
UNDER ANALYSIS
25830551
Qvodplayer.exe0
88.71 KB
UNDER ANALYSIS
25830552
Qvodplayer.exe1
88.71 KB
UNDER ANALYSIS
25830553
click.exe2
87.21 KB
UNDER ANALYSIS
25830554
Qvodplayer.exe7
88.71 KB
UNDER ANALYSIS
25830555
Qvodplayer.exe9
88.71 KB
UNDER ANALYSIS




http://samples.nod32.com.hk/index.php?a=query〈=2&md5=be1164c47ee99a8c3f04eb073be12b9e




Hello,

click.ex1e - Trojan-Downloader.Win32.Agent.edbj,
click.exe2 - Trojan-Downloader.Win32.Agent.edbk,
Qvodplayer.e1xe, Qvodplayer.exe%, Qvodplayer.exe0, Qvodplayer.exe7, Qvodplayer.exe9 - Trojan-Downloader.Win32.Agent.edbo,
Qvodplayer.e@xe, Qvodplayer.ex3e, Qvodplayer.ex@e, Qvodplayer.exe!, Qvodplayer.exe#, Qvodplayer.exe$, Qvodplayer.exe1, Qvodplayer.exe_ - Trojan-Downloader.Win32.Agent.edbn

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

Please quote all when answering.
-----------------
Regards, Kirill Kruglov
Virus Analyst, Kaspersky Lab.






Please find a detailed report concerning each individual sample below:
Filename
Result
Qvodplayer.e@xe
MALWARE

The file 'Qvodplayer.e@xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbn.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.
Filename
Result
Qvodplayer.e1xe
MALWARE

The file 'Qvodplayer.e1xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbo.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.
Filename
Result
Qvodplayer.ex@e
MALWARE

The file 'Qvodplayer.ex@e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Adload.ahg.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
click.ex1e
MALWARE

The file 'click.ex1e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Click.B.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.ex3e
MALWARE

The file 'Qvodplayer.ex3e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe!
MALWARE

The file 'Qvodplayer.exe!' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe#
MALWARE

The file 'Qvodplayer.exe#' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe$
MALWARE

The file 'Qvodplayer.exe$' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe%
MALWARE

The file 'Qvodplayer.exe%' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Adload.Q.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe_
MALWARE

The file 'Qvodplayer.exe_' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe0
MALWARE

The file 'Qvodplayer.exe0' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe1
MALWARE

The file 'Qvodplayer.exe1' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
click.exe2
MALWARE

The file 'click.exe2' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Click.A.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe7
MALWARE

The file 'Qvodplayer.exe7' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe9
MALWARE

The file 'Qvodplayer.exe9' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.edbm.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
ssama
发表于 2010-8-1 20:47:24 | 显示全部楼层
669964-499
avast! 清空
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 09:38 , Processed in 0.107585 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表