video_player_upgrade.exe

The executable video_player_upgrade.exe has been detected as malware by 40 anti-virus scanners. This is a setup program which is used to install the application. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from www.4shared.com and multiple other hosts.
MD5:
f7ee60494368e2caf46dcca67eb55734

SHA-1:
0b75619c03b4805e9711a0ba4d5258cb72c3918e

SHA-256:
a660e751cd35bb5cc34f6d928a024d9b24fcb3e51822983180bd0d391af1b6f5

Scanner detections:
40 / 68

Status:
Malware

Analysis date:
8/7/2025 12:52:05 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.APV
356

Agnitum Outpost
Backdoor.Napolar
7.1.1

AhnLab V3 Security
Spyware/Win32.Zbot
2015.06.28

Avira AntiVirus
BDS/Napolar.bo
8.3.1.6

Arcabit
Trojan.Inject.APV
1.0.0.425

avast!
Win32:Downloader-UYL [Trj]
2014.9-160213

AVG
Generic35
2017.0.2834

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.16213

Bitdefender
Trojan.Inject.APV
1.0.20.220

Bkav FE
W32.OnuquikLTAAAAG.Trojan
1.3.0.6979

Comodo Security
UnclassifiedMalware
22597

Dr.Web
Trojan.DownLoader9.21632
9.0.1.044

Emsisoft Anti-Malware
Trojan.Inject.APV
8.16.02.13.08

ESET NOD32
Win32/Injector.AWQR (variant)
10.11853

Fortinet FortiGate
W32/Ransom.CE!tr
2/13/2016

F-Prot
W32/Trojan3.HJC
v6.4.7.1.166

F-Secure
Trojan.Inject.APV
11.2016-13-02_7

G Data
Trojan.Inject.APV
16.2.25

IKARUS anti.virus
Virus.Win32.CeeInject
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.205.16383

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.666

Malwarebytes
Trojan.Inject.ED
v2016.02.13.08

McAfee
Dowloader-FEX
5600.6490

Microsoft Security Essentials
VirTool:Win32/CeeInject
1.1.11804.0

MicroWorld eScan
Trojan.Inject.APV
17.0.0.132

NANO AntiVirus
Trojan.Win32.Inject.csxwxw
0.30.24.2266

nProtect
Trojan.Inject.APV
15.06.26.01

Panda Antivirus
Trj/Zbot.M
16.02.13.08

Qihoo 360 Security
Win32/Trojan.e6d
1.0.0.1015

Quick Heal
TrojanPWS.Zbot.A4
2.16.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.16772E93!376909459
23.00.65.16211

Sophos
Mal/Zbot-OA
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Zbot
9325

Total Defense
Win32/Gamarue.PC
37.1.62.1

Trend Micro House Call
TROJ_SPNR.06B414
7.2.44

Trend Micro
TROJ_SPNR.06B414
10.465.13

Vba32 AntiVirus
SScope.Malware-Cryptor.FCM.3913
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Fareit.if
41496

ViRobot
Trojan.Win32.S.Agent.152377.C[h]
2014.3.20.0

Zillya! Antivirus
Trojan.ZBot.Win32.106
2.0.0.2255

File size:
148.8 KB (152,377 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\video_player_upgrade.exe

File PE Metadata
Compilation timestamp:
1/29/2014 5:16:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:8G+N5SMpJc4FO00Bn38Vkb1VCSEgcvxDh5uKwicf5v:8G+t6qO0q3C7gc/gKgN

Entry address:
0x18B2

Entry point:
55, 8B, EC, 6A, FF, 68, 30, 26, 40, 00, 68, C2, 1A, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, C8, 21, 40, 00, 59, 83, 0D, B4, 33, 40, 00, FF, 83, 0D, B8, 33, 40, 00, FF, FF, 15, C4, 21, 40, 00, 8B, 0D, A8, 33, 40, 00, 89, 08, FF, 15, C0, 21, 40, 00, 8B, 0D, A4, 33, 40, 00, 89, 08, A1, BC, 21, 40, 00, 8B, 00, A3, B0, 33, 40, 00, E8, 9E, 01, 00, 00, 39, 1D, C0, 30, 40, 00, 75, 0C, 68, BE, 1A, 40, 00, FF, 15...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
4 KB (4,096 bytes)

The file video_player_upgrade.exe has been seen being distributed by the following 2 URLs.

Remove video_player_upgrade.exe - Powered by Reason Core Security