Threat Database Adware Adware.Qvod

Adware.Qvod

By ESGI Advisor in Adware

Threat Scorecard

Popularity Rank: 6,663
Threat Level: 20 % (Normal)
Infected Computers: 109,317
First Seen: July 1, 2013
Last Seen: February 26, 2026
OS(es) Affected: Windows

Adware.Qvod is adware which may be generated to earn money from clicks on advertisements. Once installed on the PC, Adware.Qvod may show error messages, random pop-up advertisements or advertisements linked to the computer user's Web browsing habits. Adware.Qvod may proliferate via infectious removable devices, spam emails including malicious attachments, file sharing websites on peer-to-peer networks and many other means. Adware.Qvod may prevent the PC user from normal Internet surfing activity. Adware.Qvod may be able to trace the computer user's online sessions and collect Internet surfing information that may then be used in for targeted marketing intentions.

SpyHunter Detects & Remove Adware.Qvod

File System Details

Adware.Qvod may create the following file(s):
# File Name MD5 Detections
1. QvodAddr.dll bc63d35b91022e7dcd516ceac98c6a60 1,045
2. $REF2KPZ.exe 5eca75795122a6a102e41c0874519f72 843
3. QvodPlayer.exe 056c8bbcf4f70f892e6e07b268c33569 527
4. QvodExtend_x64.dll 37b1d854da26dcf499a34d08d5d2fc70 417
5. QvodExtend.dll 91768f287bae284da5d985ca24eb2987 305
6. QvodTerminal.exe 7167f8740b9f74d7e24b294bada964f3 282
7. qvod_online.exe 2742c1ae44429800eb4014c42f35ff50 277
8. QvodTerminal.exe.old cf6f8fe868769f2dbe0b9f7f648f037e 255
9. QvodGameExtend.dll b93db1afb881ac39d565eb7f2e25e114 244
10. qvod.exe d8b7c3af2f63db6cc542273e192b1d02 222
11. QvodTerminal.exe.vir feb6a3b3d32d6d28b44d37ea2e2ce2a5 220
12. QvodDaily.exe d59457a0e5c7e2976ea91762673a110d 148
13. qvodextend.fwd 0007d2841c97842e1c7111b8fea0c266 147
14. QvodRunEx64.dll 587ca14cabc413421895f4cdfeffbe47 132
15. QvodMon.exe 13f728c9310a50e8163df02046632c7f 121
16. QvodUpdate5.2012093000.exe 3cf8710dc26533a8d51e46b40cf4c8e8 65
17. QvodTips.exe f87cc7e84f0e2d46a4f34039fbf72e80 63
18. QvodSetup5.exe 0c2e69792055cd48ee71eca6fa78bc44 60
19. file.exe 1f4a513d24addeab0dd588c9bffbdccb 0
More files

Registry Details

Adware.Qvod may create the following registry entry or registry entries:
CLSID
{02E2D748-67F8-48B4-8AB4-0A085374BB99}
{11CC93E4-0BE6-4f8f-82AA-D577FB955B05}
{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}
{1E7A1DF1-5EF7-43CB-A96E-BCC28B2289D5}
{20E9DE6B-87D5-4E85-8BB0-038284A6C44D}
{2462C5DB-27C6-4CE8-81EF-3204D612A421}
{329C81B5-1C8D-404E-BDC4-975046C1F878}
{3750E58C-845E-4E2A-8CAE-06DC61C93F8B}
{453ED6EE-F2B8-48F0-B593-109CDAF88347}
{490E61A7-0767-4CB2-BD78-C8944902CB4F}
{4D89001B-5B5B-4E76-A1F5-638E49DB7A58}
{53AC8551-0DE0-4606-8A1E-A51AF20ADD60}
{7C6D5EE5-C859-4B49-8F7B-DE0927D1C3E9}
{7C74161C-EB97-4258-B9F8-E9283E00ED21}
{91878E42-FC03-4785-B513-1F9E613D1027}
{9F44453E-1E46-4D5C-B57C-112FF2EDAE82}
{A8502600-B272-4F68-A67B-A0305D46D297}
{A8502600-B272-4F68-A67B-A0305D46D298}
{AD461A96-4DB8-4C6E-BF23-84D682ADC382}
{B0E53EBC-0867-4225-BE81-A7F2B4AF43D3}
{C50D35A7-2515-4219-BC15-CBD2955EAE68}
{D02E3AB9-7796-40CB-BDFC-20D834FE1F75}
{D6065CEC-BDEE-4C6D-BE53-DD27DFED2E75}
{E3DEC0EB-13E4-45EE-8F2E-577A3ECAFCBD}
{F3D0D36F-23F8-4682-A195-74C92B03D4AF}
{F9BC0421-BB5C-447D-8547-BB45AFA80A4D}
{FA677CC1-D6FA-4B55-825D-6C493F56ED84}
{FACA2063-0A8D-4470-B1D3-1696D265EE16}
{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86}
{FCB380C4-D350-44BE-8791-50216F4747AC}
{FE575A61-09BD-4F3A-B8B5-B55B813B44EC}
File name without path
QvodPlayer.lnk
Software\AppDataLow\Software\baiduAddr
SOFTWARE\Classes\*\shellex\ContextMenuHandlers\QvodMenu
SOFTWARE\Classes\.3g2\qvodplayerbak
SOFTWARE\Classes\.3gp2\qvodplayerbak
SOFTWARE\Classes\.3gp\qvodplayerbak
SOFTWARE\Classes\.3gpp\qvodplayerbak
SOFTWARE\Classes\.aif\qvodplayerbak
SOFTWARE\Classes\.aifc\qvodplayerbak
SOFTWARE\Classes\.aiff\qvodplayerbak
SOFTWARE\Classes\.amr\qvodplayerbak
SOFTWARE\Classes\.amv\qvodplayerbak
SOFTWARE\Classes\.asf\qvodplayerbak
SOFTWARE\Classes\.asx\qvodplayerbak
SOFTWARE\Classes\.avi\qvodplayerbak
SOFTWARE\Classes\.bik\qvodplayerbak
SOFTWARE\Classes\.csf\qvodplayerbak
SOFTWARE\Classes\.cue\qvodplayerbak
SOFTWARE\Classes\.d2v\qvodplayerbak
SOFTWARE\Classes\.dsa\qvodplayerbak
SOFTWARE\Classes\.dss\qvodplayerbak
SOFTWARE\Classes\.dsv\qvodplayerbak
SOFTWARE\Classes\.dvd\qvodplayerbak
SOFTWARE\Classes\.evo\qvodplayerbak
SOFTWARE\Classes\.f4v\qvodplayerbak
SOFTWARE\Classes\.flc\qvodplayerbak
SOFTWARE\Classes\.fli\qvodplayerbak
SOFTWARE\Classes\.flv\qvodplayerbak
SOFTWARE\Classes\.IVF\qvodplayerbak
SOFTWARE\Classes\.m1v\qvodplayerbak
SOFTWARE\Classes\.m2p\qvodplayerbak
SOFTWARE\Classes\.M2T\qvodplayerbak
SOFTWARE\Classes\.M2TS\qvodplayerbak
SOFTWARE\Classes\.M2V\qvodplayerbak
SOFTWARE\Classes\.m3u\qvodplayerbak
SOFTWARE\Classes\.m4b\qvodplayerbak
SOFTWARE\Classes\.m4p\qvodplayerbak
SOFTWARE\Classes\.m4v\qvodplayerbak
SOFTWARE\Classes\.mkv\qvodplayerbak
SOFTWARE\Classes\.MOD\qvodplayerbak
SOFTWARE\Classes\.mov\qvodplayerbak
SOFTWARE\Classes\.mp4\qvodplayerbak
SOFTWARE\Classes\.mpe\qvodplayerbak
SOFTWARE\Classes\.mpeg\qvodplayerbak
SOFTWARE\Classes\.mpg\qvodplayerbak
SOFTWARE\Classes\.MTS\qvodplayerbak
SOFTWARE\Classes\.ogm\qvodplayerbak
SOFTWARE\Classes\.pm2\qvodplayerbak
SOFTWARE\Classes\.pmp2\qvodplayerbak
SOFTWARE\Classes\.pmp\qvodplayerbak
SOFTWARE\Classes\.pss\qvodplayerbak
SOFTWARE\Classes\.pva\qvodplayerbak
SOFTWARE\Classes\.qmv\qvodplayerbak
SOFTWARE\Classes\.qmvb\qvodplayerbak
SOFTWARE\Classes\.qpl\qvodplayerbak
SOFTWARE\Classes\.qsed\qvodplayerbak
SOFTWARE\Classes\.qt\qvodplayerbak
SOFTWARE\Classes\.rat\qvodplayerbak
SOFTWARE\Classes\.rm\qvodplayerbak
SOFTWARE\Classes\.rmvb\qvodplayerbak
SOFTWARE\Classes\.roq\qvodplayerbak
SOFTWARE\Classes\.rp\qvodplayerbak
SOFTWARE\Classes\.rpm\qvodplayerbak
SOFTWARE\Classes\.rsc\qvodplayerbak
SOFTWARE\Classes\.rt\qvodplayerbak
SOFTWARE\Classes\.smil\qvodplayerbak
SOFTWARE\Classes\.smk\qvodplayerbak
SOFTWARE\Classes\.swf\qvodplayerbak
SOFTWARE\Classes\.tim\qvodplayerbak
SOFTWARE\Classes\.torrent\qvodplayerbak
SOFTWARE\Classes\.tp\qvodplayerbak
SOFTWARE\Classes\.tpr\qvodplayerbak
SOFTWARE\Classes\.TS\qvodplayerbak
SOFTWARE\Classes\.ttpl\qvodplayerbak
SOFTWARE\Classes\.vg2\qvodplayerbak
SOFTWARE\Classes\.vid\qvodplayerbak
SOFTWARE\Classes\.vob\qvodplayerbak
SOFTWARE\Classes\.vp6\qvodplayerbak
SOFTWARE\Classes\.vp7\qvodplayerbak
SOFTWARE\Classes\.wm\qvodplayerbak
SOFTWARE\Classes\.wmp\qvodplayerbak
SOFTWARE\Classes\.wmv\qvodplayerbak
SOFTWARE\Classes\.wpl\qvodplayerbak
SOFTWARE\Classes\.wv\qvodplayerbak
SOFTWARE\Classes\AddressSearch.JsObject
SOFTWARE\Classes\AddressSearch.JsObject.1
SOFTWARE\Classes\AddressSearch.SnavHttpProtocol
SOFTWARE\Classes\AddressSearch.SnavHttpProtocol.1
SOFTWARE\Classes\AppID\ASBarBroker.EXE
SOFTWARE\Classes\AppID\QvodInsert.DLL
SOFTWARE\Classes\AppID\QvodInsert.EXE
SOFTWARE\Classes\AppID\ShareModule.DLL
SOFTWARE\Classes\ASBarBroker.BDBroker
SOFTWARE\Classes\ASBarBroker.BDBroker.1
SOFTWARE\Classes\DVD\shell\Play with QvodPlayer
SOFTWARE\Classes\DVD\shell\QVOD
SOFTWARE\Classes\DVD\shell\qvodplayerbak
SOFTWARE\Classes\MIME\Database\Content Type\application/qvod-plugin
SOFTWARE\Classes\MIME\Database\Content Type\application/QvodShare-plugin
SOFTWARE\Classes\QGameInsert.WebGameCtrl
SOFTWARE\Classes\QGameInsert.WebGameCtrl.1
SOFTWARE\Classes\QVBFILE
SOFTWARE\Classes\QVOD
SOFTWARE\Classes\Qvodbt
SOFTWARE\Classes\QvodInsert.QvodCtrl
SOFTWARE\Classes\QvodInsert.QvodCtrl.1
SOFTWARE\Classes\ShareModule.QvodShare
SOFTWARE\Classes\ShareModule.QvodShare.1
SOFTWARE\Classes\Wow6432Node\AppID\ASBarBroker.EXE
Software\Classes\Wow6432Node\CLSID\{02E2D748-67F8-48B4-8AB4-0A085374BB99}
Software\Classes\Wow6432Node\CLSID\{F3D0D36F-23F8-4682-A195-74C92B03D4AF}
Software\Classes\Wow6432Node\QvodInsert.QvodCtrl
Software\Classes\Wow6432Node\QvodInsert.QvodCtrl.1
Software\Classes\Wow6432Node\TypeLib\{7C74161C-EB97-4258-B9F8-E9283E00ED21}
Software\Classes\Wow6432Node\Xbdyy.PlayCtrl
Software\Classes\Wow6432Node\Xbdyy.PlayCtrl.1
Software\Microsoft\Internet Explorer\Approved Extensions\{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}
Software\Microsoft\Internet Explorer\Approved Extensions\{A8502600-B272-4F68-A67B-A0305D46D297}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONEVENTS\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONEVENTS\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TABBED_BROWSING\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TABBED_BROWSING\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER\QvodWeb.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\QvodPlayer.exe
Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\QvodWeb.exe
SOFTWARE\Microsoft\Internet Explorer\NavigatorPluginsList\QvodInsert
Software\Microsoft\Internet Explorer\SearchScopes\{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QvodPlayer.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A8502600-B272-4F68-A67B-A0305D46D297}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8502600-B272-4F68-A67B-A0305D46D298}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\OpenWithProgids\qvodplayer.3g2
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\OpenWithProgids\qvodplayer.3gp2
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\OpenWithProgids\qvodplayer.3gp
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\OpenWithProgids\qvodplayer.3gpp
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amv\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\OpenWithProgids\qvodplayer.asf
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\OpenWithProgids\qvodplayer.avi
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bik\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csf\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.d2v\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsa\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dss\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsv\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dvd\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.evo\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.f4v\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IVF\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2p\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\OpenWithProgids\qvodplayer.m2t
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2T\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\OpenWithProgids\qvodplayer.m2ts
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2TS\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\OpenWithProgids\qvodplayer.m3u
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\OpenWithProgids\qvodplayer.m4v
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\OpenWithProgids\qvodplayer.mkv
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\OpenWithProgids\qvodplayer.mod
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\OpenWithProgids\qvodplayer.mov
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithProgids\qvodplayer.mp4
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\OpenWithProgids\qvodplayer.mpeg
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\OpenWithProgids\qvodplayer.mpg
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\OpenWithProgids\qvodplayer.mts
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MTS\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pm2\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pmp2\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pmp\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pss\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pva\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qmv\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qmvb\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qpl\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qsed\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rat\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.roq\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rpm\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsc\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smk\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.swf\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tim\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tp\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tpr\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\OpenWithProgids\qvodplayer.ts
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttpl\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vg2\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vid\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp6\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vp7\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\OpenWithProgids\qvodplayer.wm
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmp\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\OpenWithProgids\qvodplayer.wmv
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WPL\OpenWithProgids\qvodplayer.wpl
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\qvodplayerbak
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv\qvodplayerbak
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7C6D5EE5-C859-4B49-8F7B-DE0927D1C3E9}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94C3E4BB-A261-4a83-B437-EA6F7A28CA68}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A8502600-B272-4F68-A67B-A0305D46D297}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A8502600-B272-4F68-A67B-A0305D46D298}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F3D0D36F-23F8-4682-A195-74C92B03D4AF}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A8502600-B272-4F68-A67B-A0305D46D297}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8502600-B272-4F68-A67B-A0305D46D297}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8502600-B272-4F68-A67B-A0305D46D298}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3D0D36F-23F8-4682-A195-74C92B03D4AF}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1745A7F0-3FA0-369D-C34A-F8CA62484E99}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{B039BFB5-03A3-DB9E-45F8-0722CDC150F4}
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QvodTerminal
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QvodPlayer
SOFTWARE\MozillaPlugins\@qvod.com/QvodInsert
SOFTWARE\MozillaPlugins\@qvod.com/QvodShare
Software\QvodPlayer
SOFTWARE\Wow6432Node\Classes\AppID\ASBarBroker.EXE
SOFTWARE\Wow6432Node\Classes\AppID\QvodInsert.DLL
SOFTWARE\Wow6432Node\Classes\AppID\QvodInsert.EXE
SOFTWARE\Wow6432Node\Classes\AppID\ShareModule.DLL
SOFTWARE\Wow6432Node\Classes\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}
SOFTWARE\Wow6432Node\Classes\AppID\{2462C5DB-27C6-4CE8-81EF-3204D612A421}
SOFTWARE\Wow6432Node\Classes\AppID\{453ED6EE-F2B8-48F0-B593-109CDAF88347}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}
SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\NavigatorPluginsList\QvodInsert
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\QvodPlayer.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A8502600-B272-4F68-A67B-A0305D46D297}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7C6D5EE5-C859-4B49-8F7B-DE0927D1C3E9}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94C3E4BB-A261-4a83-B437-EA6F7A28CA68}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A8502600-B272-4F68-A67B-A0305D46D297}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F3D0D36F-23F8-4682-A195-74C92B03D4AF}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3D0D36F-23F8-4682-A195-74C92B03D4AF}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\QvodTerminal
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\QvodPlayer
SOFTWARE\Wow6432Node\MozillaPlugins\@qvod.com/QvodInsert
SOFTWARE\Wow6432Node\MozillaPlugins\@qvod.com/QvodShare
SOFTWARE\Wow6432Node\QvodPlayer
SYSTEM\ControlSet001\QUID
SYSTEM\ControlSet002\QUID

Directories

Adware.Qvod may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\QVOD
%ALLUSERSPROFILE%\QvodPlayer
%PROGRAMFILES%\QvodPlayer
%PROGRAMFILES(x86)%\QvodPlayer
%USERPROFILE%\AppData\LocalLow\baiduAddr
%USERPROFILE%\Application Data\baiduAddr

Analysis Report

General information

Family Name: Adware.Qvod
Signature status: Hash Mismatch

Known Samples

MD5: 64af5b2f1b720db7554b510ec97429a1
SHA1: 4a1676233a7f45fea4be8245542398ba828b1f43
SHA256: B576F91A0B271B6022CFD8E35E5FB9B646B5EF7B20BE39028E7EE613AADB314B
File Size: 609.41 KB, 609408 bytes
MD5: 29f867f2fdd1c0ead41ea0d757ed3dc2
SHA1: 5e2411d6469659b544ee11e191799e060eab4ffe
SHA256: 20B553245707005983C46F727B900018CF828C08229F77F270A6E5A6CF6ECC7B
File Size: 626.82 KB, 626816 bytes
MD5: ed7874322b35e07356df30a0214d1a2a
SHA1: 77e7226f5a9b20ef0963e4e76d7bf85097b5f539
SHA256: E5DFF92B93B26D6DE3CD287E848D79E0C3ED2814944FDCF082C55C5DCE56F3F2
File Size: 4.21 MB, 4206464 bytes
MD5: 5998b70e2bca11cfd051b6c976393abb
SHA1: 04465df234c5e84150478341023e3332858f22f0
SHA256: B32D290E664CBEA4D0A2D409FD52A16B1B9E28D331AA56A3857854F61B82BABB
File Size: 2.62 MB, 2619312 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Shenzhen QVOD Technology Co.,Ltd
  • Shenzhen Qvod Technology Co.,Ltd
File Description
  • QvodInsert
  • 快播
  • 快播(精简版)安装程序
File Open Name QvodInsert
File Version
  • 5.0.77 精简版
  • 5, 20, 234, 0
  • 5, 17, 160, 0
  • 5, 15, 148, 0
Internal Name
  • QvodInsert
  • QvodPlayer
Legal Copyright
  • Copyright (C) 2010 - 2013 Shenzhen QVOD Technology Co.,Ltd. All rights reserved.
  • Copyright (C) 2010 - 2014 Shenzhen QVOD Technology Co.,Ltd. All rights reserved.
  • Copyright © 1997-2011 Shenzhen QVOD Technology Co.,Ltd
M I M E Type application/qvod-plugin
Original Filename
  • npQvodInsert.dll
  • QvodPlayer.exe
Product Name
  • QvodInsert
  • 快播
Product Version
  • 5, 20, 234, 0
  • 5, 17, 160, 0
  • 5, 15, 148, 0

Digital Signatures

Signer Root Status
Shenzhen QVOD Technology Co.,Ltd VeriSign Class 3 Code Signing 2010 CA Hash Mismatch
Shenzhen QVOD Technology Co.,Ltd VeriSign Class 3 Code Signing 2010 CA Self Signed
Shenzhen QVOD Technology Co.,Ltd VeriSign Class 3 Public Primary Certification Authority - G5 Root Not Trusted
Shenzhen QVOD Technology Co.,Ltd VeriSign Class 3 Public Primary Certification Authority - G5 Hash Mismatch

Block Information

Total Blocks: 9,674
Potentially Malicious Blocks: 17
Whitelisted Blocks: 5,034
Unknown Blocks: 4,623

Visual Map

? ? ? ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 x ? 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? 0 0 0 ? ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? ? ? 0 0 ? ? ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? 0 0 0 ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 ? 1 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? ? ? 0 ? ? ? 0 0 ? ? 0 ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? 0 ? ? 0 ? ? 0 ? 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 ? ? ? 0 0 0 ? ? 0 ? 0 0 0 0 ? 0 0 0 ? ? 0 ? x 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? ? ? ? 0 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? 0 ? 0 ? 0 0 ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 0 0 0 ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? 0 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? x 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 ? 0 0 ? 0 0 0 ? ? 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsfa321.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsqa361.tmp\01.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\02.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\03.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\buttonlinker.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\finish1.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\finish2.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\finish3.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsqa361.tmp\iospecial.ini Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsqa361.tmp\leftbg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\qvod1.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\qvod2.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\qvod3.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\qvodinstaller.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\qvodres.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqa361.tmp\system.dll Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Network Info Queried
  • GetAdaptersInfo
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4a1676233a7f45fea4be8245542398ba828b1f43_0000609408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5e2411d6469659b544ee11e191799e060eab4ffe_0000626816.,LiQMAxHB

Trending

Most Viewed

Loading...