Virus Found – Possible Threat “Trojan downloader”
Well again I come across to a threat which is detected by few AVS, this time including Kaspersky Scanner as “Trojan.Win32.Qhost.ot“, however other front line paid scanners, such as, Norton, NOD32 (ESET) and one of the trusted Free scanner Avast fails to detect the threat….
| File Crypted.exe received on 11.05.2007 17:40:04 (CET) | |||
| Antivirus | Version | Last Update | Result |
| AhnLab-V3 | 2007.11.6.0 | 2007.11.05 | - |
| AntiVir | 7.6.0.30 | 2007.11.05 | TR/Qhost.OT.2 |
| Authentium | 4.93.8 | 2007.11.03 | - |
| Avast | 4.7.1074.0 | 2007.11.05 | - |
| AVG | 7.5.0.503 | 2007.11.05 | IRC/BackDoor.SdBot3.SWA |
| BitDefender | 7.2 | 2007.11.05 | Trojan.Loader.RBot.A |
| CAT-QuickHeal | 9.00 | 2007.11.05 | - |
| ClamAV | 0.91.2 | 2007.11.05 | Trojan.Qhost-37 |
| DrWeb | 4.44.0.09170 | 2007.11.05 | - |
| eSafe | 7.0.15.0 | 2007.10.28 | - |
| eTrust-Vet | 31.2.5264 | 2007.11.02 | - |
| Ewido | 4.0 | 2007.11.05 | - |
| FileAdvisor | 1 | 2007.11.05 | - |
| Fortinet | 3.11.0.0 | 2007.10.19 | W32/Qhost.OT!tr |
| F-Prot | 4.4.2.54 | 2007.11.05 | - |
| F-Secure | 6.70.13030.0 | 2007.11.05 | Trojan.Win32.Qhost.ot |
| Ikarus | T3.1.1.12 | 2007.11.05 | Backdoor.Win32.Rbot.eab |
| Kaspersky | 7.0.0.125 | 2007.11.05 | Trojan.Win32.Qhost.ot |
| McAfee | 5155 | 2007.11.02 | - |
| Microsoft | 1.2908 | 2007.11.05 | VirTool:Win32/DelfInject.gen!S |
| NOD32v2 | 2637 | 2007.11.05 | - |
| Norman | 5.80.02 | 2007.11.05 | - |
| Panda | 9.0.0.4 | 2007.11.04 | Trj/Spambot.C |
| Prevx1 | V2 | 2007.11.05 | - |
| Rising | 20.17.01.00 | 2007.11.05 | Trojan.Win32.QHost.nn |
| Sophos | 4.23.0 | 2007.11.05 | Mal/Behav-154 |
| Sunbelt | 2.2.907.0 | 2007.11.02 | - |
| Symantec | 10 | 2007.11.05 | - |
| TheHacker | 6.2.9.116 | 2007.11.05 | - |
| VBA32 | 3.12.2.4 | 2007.11.05 | Backdoor.Win32.Rbot.eab |
| VirusBuster | 4.3.26:9 | 2007.11.05 | - |
| Webwasher-Gateway | 6.6.1 | 2007.11.05 | Trojan.Qhost.OT.2 |
| Additional information | |||
| File size: 140800 bytes | |||
| MD5: 72a5fb844082d8cf31c6a86c023cc591 | |||
| SHA1: 202e8c9bffb05deda5325bc7939ccfcc9749b36f | |||

I have tried to upload the file at Yahoo eMail account of mine, and I can successfully upload the file there, which is a clear indication that Norton AntiVirus 2007 also failed to detect the file…

As usual, I have notified NOD32 and Avast by sending them the infected file… Will update the post with their reply !!!
akshat on June 3rd, 2008
my pc is infected with 6123t.exe . could u plz hlp me out in ny way…
thanks