Worm

UDS:Worm.Win32.Qvod.pkl (file analysis)

Malware Removal

The UDS:Worm.Win32.Qvod.pkl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Worm.Win32.Qvod.pkl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine UDS:Worm.Win32.Qvod.pkl?


File Info:

name: A44D1FDCD611A873ACF7.mlw
path: /opt/CAPEv2/storage/binaries/6a414635c60eca3b07db06383242f536b18281a9dea8b921b38fec4fcc8ec72b
crc32: 4D7D3ED6
md5: a44d1fdcd611a873acf7b31066b6c334
sha1: 339edd2064a13e12772e160eadc8b90fc2d9423b
sha256: 6a414635c60eca3b07db06383242f536b18281a9dea8b921b38fec4fcc8ec72b
sha512: ebbd00db138c503cb20897a407fcee0334f7ba180719a3ba2edd1c6cabf0389babc3dcc5c07fab422a5ce0107e915c47c65d2b27973327c19f7216408faeed81
ssdeep: 49152:U6KaNfUp/cOxbyg/fGCVLBblMKTe1g3dGqb6iumB:pfU5cTgXzV9lMKd3dGqWiR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3A5AE415BF7D1BEE013363347B6A3316139686816174BDE2AD8D72E3453EA01CEE6E8
sha3_384: dc0519f4c9a6afe6f696065d372d2977ebcbef6b6d0e108e1160faef72bd5afc94d5a00600f6f67e036d44912f5ce040
ep_bytes: 558bec6aff68e8dd46006890b3440064
timestamp: 2015-04-15 10:09:35

Version Info:

Comments:
CompanyName:
FileDescription: STC-ISP
FileVersion: 0, 6, 0, 85
InternalName: STC-ISP
LegalCopyright: CopyRight (C) 2010
LegalTrademarks:
OriginalFilename: STC-ISP.exe
PrivateBuild:
ProductName: STC-ISP application
ProductVersion: 0, 6, 0, 85
SpecialBuild:
Translation: 0x0409 0x04b0

UDS:Worm.Win32.Qvod.pkl also known as:

LionicTrojan.Win32.Qvod.4!c
DrWebTrojan.DownLoader12.61994
MicroWorld-eScanGen:Win32.QVod.A
ClamAVWin.Worm.Wapomi-9882044-0
FireEyeGeneric.mg.a44d1fdcd611a873
ALYacGen:Win32.QVod.A
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Win32.QVod.A
SangforTrojan.Win32.Agent.Vvhd
AlibabaWorm:Win32/Viking.14ec5026
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.36196.fqueaS12Nacb
VirITTrojan.Win32.DownLoader12.DNSK
CyrenW32/Pikorms.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 99)
KasperskyUDS:Worm.Win32.Qvod.pkl
BitDefenderGen:Win32.QVod.A
NANO-AntivirusTrojan.Win32.Hostar.vizob
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Win32.QVod.A (B)
F-SecureMalware.W32/Viking.atdc.109
BaiduWin32.Worm.Qvod.c
McAfee-GW-EditionArtemis!Virus
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Win32.QVod.A
AviraW32/Viking.atdc.109
MAXmalware (ai score=88)
Antiy-AVLVirus/Win32.Qvod.b
ArcabitGen:Win32.QVod.A
ZoneAlarmUDS:Worm.Win32.Qvod.pkl
MicrosoftProgram:Win32/Wacapew.C!ml
McAfeeArtemis!A44D1FDCD611
VBA32BScope.Trojan.Downloader
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CEN23
RisingTrojan.Generic@AI.86 (RDMK:cmRtazrOEWNBPmei0iHKkFvrLxVr)
YandexTrojan.GenAsa!lve5S0fl5NI
IkarusWorm.Win32.Qvod
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.cd611a
DeepInstinctMALICIOUS

How to remove UDS:Worm.Win32.Qvod.pkl?

UDS:Worm.Win32.Qvod.pkl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment