楼主: sam.to
收起左侧

[病毒样本] 大量伪快播(Qvod.exe,click.exe,duogua.exe),天天更新 (637 楼有新)

  [复制链接]
sam.to
 楼主| 发表于 2010-8-18 23:16:06 | 显示全部楼层
我上报红伞他说
已确定“Qvodplayer.exe”文件是“DAMAGED FILE (UNKNOWN)”。 具体而言,这意味着此 ...
网名丢失 发表于 2010.8.18 22:15


我不是已上报嗎?
saskecn
发表于 2010-8-19 09:25:45 | 显示全部楼层
sam.to
 楼主| 发表于 2010-8-19 12:01:45 | 显示全部楼层
本帖最后由 sam.to 于 2010.8.19 22:09 编辑

f7a42d5e98df9509e906e3e90b136e72  Qvodplayer.exe2
f0b8bd9821c9e0b01555745610859efb  Qvodplayer.exe0
d4d61c0fbdc6cb307425cf9a498e82da  Qvodplayer.e8xe
ad0ec02501cab852751c7b32a9ff786a  Qvodplayer.ex'e
a3334700ef47e2e4ea2379738fe2ae5f  click.ex2e
7eb61490b361c63e6342b0a25fe0337e  duogua.e0xe
5674e41666299ae25f2fbff7559efe01  click.e=xe
4d5fadf5e85b2277950b25424c269ec4  click.exe&
381934694f09209cf40014bdec4f3d5c  Qvodplayer.ex_e
30586506042fc18def5c6ac81c4ce6ab  Qvodplayer.e{xe
28e952f3b16eb1ec15b7d73665edb064  Qvodplayer.exe]
1b50ec5ce8b8fd2dd739e5e13fd73f44  Qvodplayer.exe+


to kl,ll,comodo,avira


A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25852795
Qvodplayer.e{xe
88.77 KB
UNDER ANALYSIS
25852796
click.e=xe
86.77 KB
UNDER ANALYSIS
25852797
duogua.e0xe
84.21 KB
UNDER ANALYSIS
25852798
Qvodplayer.e8xe
88.77 KB
UNDER ANALYSIS
25852799
Qvodplayer.ex'e
88.77 KB
UNDER ANALYSIS
25852800
Qvodplayer.ex_e
88.77 KB
UNDER ANALYSIS
25852801
click.ex2e
86.77 KB
UNDER ANALYSIS
25852802
click.exe&
86.77 KB
UNDER ANALYSIS
25852803
Qvodplayer.exe]
88.77 KB
UNDER ANALYSIS
25852804
Qvodplayer.exe+
88.77 KB
UNDER ANALYSIS
25852805
Qvodplayer.exe0
88.77 KB
UNDER ANALYSIS
25852806
Qvodplayer.exe2
88.77 KB
UNDER ANALYSIS







Hello,

80177952_273756170_click.e=xe, 80177952_273756171_click.ex2e, 80177952_273756172_click.exe&, 80177952_273756173_duogua.e0xe - Trojan-Downloader.Win32.Agent.eicv,
80177952_273756174_Qvodplayer.e8xe, 80177952_273756175_Qvodplayer.ex'e, 80177952_273756176_Qvodplayer.exe+, 80177952_273756177_Qvodplayer.exe0, 80177952_273756178_Qvodplayer.exe2, 80177952_273756179_Qvodplayer.exe], 80177952_273756182_Qvodplayer.ex_e, 80177952_273756185_Qvodplayer.e{xe - Trojan-Downloader.Win32.Agent.eicw

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.


Please quote all when answering.
-----------------
Regards, Kirill Kruglov
Virus Analyst, Kaspersky Lab.







25848538
001.scr
94.38 KB
MALWARE
25853102
1fc179a9f94b135d5...lp.exe
140 KB
MALWARE
25840259
baidu32.dll
68 KB
MALWARE
25853104
df5725a6172c72d03...32.exe
101.5 KB
MALWARE

Please find a detailed report concerning each individual sample below:
Filename
Result
Qvodplayer.e{xe
MALWARE

The file 'Qvodplayer.e{xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.ahzef.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
click.e=xe
MALWARE

The file 'click.e=xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.adrq.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
duogua.e0xe
MALWARE

The file 'duogua.e0xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.adrb.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.Please note that Avira's proactive heuristic detection module AHeAD detected this threat up front without the latest VDF update as: HEUR/Malware.
Filename
Result
Qvodplayer.e8xe
MALWARE

The file 'Qvodplayer.e8xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.90904.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.ex'e
MALWARE

The file 'Qvodplayer.ex'e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.arvn.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.ex_e
MALWARE

The file 'Qvodplayer.ex_e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.arvy.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
click.ex2e
MALWARE

The file 'click.ex2e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agen.ehdi.1.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.226.
Filename
Result
click.exe&
MALWARE

The file 'click.exe&' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agen.ehdi.1.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.226.
Filename
Result
Qvodplayer.exe]
MALWARE

The file 'Qvodplayer.exe]' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.adrx.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe+
MALWARE

The file 'Qvodplayer.exe+' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.arvu.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe0
MALWARE

The file 'Qvodplayer.exe0' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.adnx.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe2
MALWARE

The file 'Qvodplayer.exe2' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agent.adnr.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
蝉鸣时
发表于 2010-8-19 12:03:20 | 显示全部楼层
583

To ESET.
hj5abc
发表于 2010-8-19 12:26:22 | 显示全部楼层
#583
9× to Fs
思齐鼠
发表于 2010-8-19 12:30:01 | 显示全部楼层
回复 571楼 sam.to  的帖子


    这个压缩包貌似有密码,密码是多少?
ablhr
发表于 2010-8-19 20:02:01 | 显示全部楼层
583
to mp
ssama
发表于 2010-8-19 20:03:58 | 显示全部楼层
669964-583
avast! 清空

评分

参与人数 1人气 +1 收起 理由
hj5abc + 1 avast的基因码还坚挺着@..

查看全部评分

ssama
发表于 2010-8-19 20:05:02 | 显示全部楼层
回复 587楼 思齐鼠  的帖子

infected
   
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 05:50 , Processed in 0.095071 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表