New VBS/Agent QJ not is detected (Solved)

False email JBS
We do not identify the payment for the invoices that were 3819621 for the day 10/12/2015.
Please ask a payment forecast.
Remembering the same can no longer be extended.

Detection 3/55

https://www.virustotal.com/en/file/b346c5a858357f3aa2f243a1615cf6b123057a1244ba85f3110058e76ea9b1e5/analysis/1450485319/

Suspicious Threat Score: 27/100 AV Detection: 5% Agent

https://www.hybrid-analysis.com/sample/b346c5a858357f3aa2f243a1615cf6b123057a1244ba85f3110058e76ea9b1e5?environmentId=4

when executed on the system Trojan VBS downloaded automatically the second malware on the machine koringah.gif.zip
on the first day following url hxxp://news.noticiadodia.onedumb.com/01/koringah.gif.zip

https://www.virustotal.com/en/url/614635f446ec5f39a60c8db21b396ce0804b1f851e93fb565ee76983dfcf3eb3/analysis/1451079412/

avast not blocked and did not detect the file
although the shows try to open the message that file is damaged or corrupted

Send for analysis
Win32:Delf Inject.A.gen!Eldorado
https://www.virustotal.com/en/file/dfad95faa40a5bc2e3c4a4a5d69854d8ab895cd0b9598674aa949b24a650d5c0/analysis/1451077656/

on the second day the Trojan VBS redirected to another URL with the same file
hxxp://moendo.newslater.compress.to/01/koringah.gif.zip

https://www.virustotal.com/en/url/4cfd80f532a6c9f8f9607ab342a97c574e9583e18cd7f15a3a0e3e4e82dcb400/analysis/1451079373/

and today blocked avast just link FileRepMetagen[Malware]
but file is still corrupt and the same message failure

Tested with AVG 2015,PSafe not detected
Nano just detected the VBS

http://i.imgur.com/LdoKO4l.png

so far avast nothing
It was sent to virus@avast.com and also virus chest

thank you at last, it almost two weeks
is now added in VPS 151231-0

is detected VBS:Banker-DM [Trj]