楼主: sam.to
收起左侧

[病毒样本] 大量伪快播(Qvod.exe,click.exe,duogua.exe),天天更新 (637 楼有新)

  [复制链接]
jason_jiang
发表于 2010-8-20 06:42:13 | 显示全部楼层
583 to xandora(panda)
思齐鼠
发表于 2010-8-20 07:22:06 | 显示全部楼层
to 金山卫士
sam.to
 楼主| 发表于 2010-8-20 15:44:05 | 显示全部楼层
本帖最后由 sam.to 于 2010.8.21 15:26 编辑

9ceb538223cb171d3604adff4d67c5cb  click.e$xe
b288b5cff4f8724b63f759000bf1581c  click.exe2
563667bef0ab01abffbad4233a848147  click.ex_e
6a4715d5069be0adc4486c8a9a461512  duogua.ex+e
6e5888191b24a814097b0e46fb4f78c2  Qvodplayer.e&xe
4bb023e7749f10cfc3f341a37f3bbf5b  Qvodplayer.e0xe
cb8d77527a47b7b13396d27cba242bc8  Qvodplayer.e;xe
c52511bc13824642fbf717bf5ccf4eca  Qvodplayer.e@xe
ea6f5579938e1efadceef4d3983ca620  Qvodplayer.ex+e
1c084c3d27ca1f6fbfdaddc795e5bef5  Qvodplayer.ex5e
08b4fbe10508b2c537ef869d32347826  Qvodplayer.exe0
48880d46bb071b3ff173036e419e4988  Qvodplayer.exe3
2e6d7481af1c929b6ea3c95f048bdabe  Qvodplayer.exe=
e7b0564939c61ac025023124e6424a70  Qvodplayer.exe_
0a0ca95b5677ec0baa8269499243fe00  Qvodplayer.ex^e
93ef8e354937e8e062d71abb2df8e9ea  Qvodplayer.ex`e
6f971399e8b22e0e21b11d41c6a9ecfe  Qvodplayer.e_xe
36c49fffd54defb8a20fa96b5dce37fe  Qvodplayer.e{xe


to kl,ll,mcafee,comodo,avira


A listing of files contained inside archives alongside their results can be found below:
File ID
Filename
Size (Byte)
Result
25854873
click.e$xe
86.77 KB
MALWARE
25854874
Qvodplayer.e&xe
88.77 KB
UNDER ANALYSIS
25854875
Qvodplayer.e;xe
88.77 KB
UNDER ANALYSIS
25854876
Qvodplayer.e@xe
88.77 KB
UNDER ANALYSIS
25854877
Qvodplayer.e_xe
88.77 KB
UNDER ANALYSIS
25854878
Qvodplayer.e{xe
88.77 KB
UNDER ANALYSIS
25854879
Qvodplayer.e0xe
88.77 KB
UNDER ANALYSIS
25854880
Qvodplayer.ex^e
88.77 KB
UNDER ANALYSIS
25854881
click.ex_e
86.77 KB
MALWARE
25854882
Qvodplayer.ex`e
88.77 KB
UNDER ANALYSIS
25854883
duogua.ex+e
84.21 KB
UNDER ANALYSIS
25854884
Qvodplayer.ex+e
88.77 KB
UNDER ANALYSIS
25854885
Qvodplayer.ex5e
88.77 KB
UNDER ANALYSIS
25854886
Qvodplayer.exe_
88.77 KB
UNDER ANALYSIS
25854887
Qvodplayer.exe=
88.77 KB
UNDER ANALYSIS
25854888
Qvodplayer.exe0
88.77 KB
UNDER ANALYSIS
25854889
click.exe2
86.77 KB
MALWARE
25854890
Qvodplayer.exe3
88.77 KB
UNDER ANALYSIS






Please find a detailed report concerning each individual sample below:
Filename
Result
click.e$xe
MALWARE

The file 'click.e$xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agen.ehdi.1.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.226.
Filename
Result
Qvodplayer.e&xe
MALWARE

The file 'Qvodplayer.e&xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.e;xe
MALWARE

The file 'Qvodplayer.e;xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.e@xe
MALWARE

The file 'Qvodplayer.e@xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.e_xe
MALWARE

The file 'Qvodplayer.e_xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.e{xe
MALWARE

The file 'Qvodplayer.e{xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.e0xe
MALWARE

The file 'Qvodplayer.e0xe' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.ex^e
MALWARE

The file 'Qvodplayer.ex^e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
click.ex_e
MALWARE

The file 'click.ex_e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agen.ehdi.1.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.226.
Filename
Result
Qvodplayer.ex`e
MALWARE

The file 'Qvodplayer.ex`e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
duogua.ex+e
MALWARE

The file 'duogua.ex+e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Adload.P.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.Please note that Avira's proactive heuristic detection module AHeAD detected this threat up front without the latest VDF update as: HEUR/Malware.
Filename
Result
Qvodplayer.ex+e
MALWARE

The file 'Qvodplayer.ex+e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.ex5e
MALWARE

The file 'Qvodplayer.ex5e' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.exe_
MALWARE

The file 'Qvodplayer.exe_' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Adload.Q.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection will be added to our virus definition file (VDF) with one of the next updates.
Filename
Result
Qvodplayer.exe=
MALWARE

The file 'Qvodplayer.exe=' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
Qvodplayer.exe0
MALWARE

The file 'Qvodplayer.exe0' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.
Filename
Result
click.exe2
MALWARE

The file 'click.exe2' has been determined to be 'MALWARE'.
Our analysts named the threat TR/Dldr.Agen.ehdi.1.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.226.
Filename
Result
Qvodplayer.exe3
MALWARE

The file 'Qvodplayer.exe3' has been determined to be 'MALWARE'.
Our analysts named the threat TR/FraudPack.hub.15.The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.10.235.






Hello,

click.e$xe - Trojan-Downloader.Win32.Agent.eihj,
click.exe2, click.ex_e - Trojan-Downloader.Win32.Agent.eihk,
duogua.ex+e - Trojan-Downloader.Win32.Agent.eihm,
Qvodplayer.e&xe, Qvodplayer.e0xe, Qvodplayer.e;xe, Qvodplayer.e@xe, Qvodplayer.ex+e, Qvodplayer.ex5e, Qvodplayer.exe0, Qvodplayer.exe3, Qvodplayer.exe=, Qvodplayer.exe_, Qvodplayer.ex^e, Qvodplayer.ex`e, Qvodplayer.e_xe, Qvodplayer.e{xe - Trojan-Downloader.Win32.Agent.eirc

New malicious software was found in these files. Detection will be included in the next update. Thank you for your help.

Please quote all when answering.
The answer is relevant to the latest bases from update sources.

-------------------------------------------
Regards, Ivan Kargapoltsev.
Virus analyst , Kaspersky Lab.
_____________________________
Ph.: +7(095)797-8700
Fax.: +7 (495) 948-43-31
newvirus@kaspersky.com
http://www.kaspersky.com  http://www.viruslist.com
--------------------------------------------
http://www.kaspersky.ru/virusscanner - online scan
http://www.kaspersky.com/helpdesk.html - technical support

BitDefender
发表于 2010-8-20 15:46:00 | 显示全部楼层
回复 593楼 sam.to  的帖子

密码多少 =  =
   
sololp 该用户已被删除
发表于 2010-8-20 15:50:01 | 显示全部楼层
submit to f-secure
wangyuli100
发表于 2010-8-20 15:52:21 | 显示全部楼层
回复 594楼 BitDefender  的帖子

infected
   
wangyuli100
发表于 2010-8-20 15:52:44 | 显示全部楼层
过咖啡,to mcafee
wangyuli100
发表于 2010-8-20 15:53:42 | 显示全部楼层
回复 595楼 sololp  的帖子

换F-Secure啦?
   
sololp 该用户已被删除
发表于 2010-8-20 15:55:07 | 显示全部楼层
回复 599楼 wangyuli100  的帖子


    嗯,咖啡已经不适合桌面防护。。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 05:37 , Processed in 0.094657 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表