Packed MD5 0a05b99e8f57a6c36ad343598556f8ae 
Priority
First 01/21/2010 
Last 01/22/2010 
Count  
History  
Unpacked MD5 6f87541765c45de778fa45172aa52847  
AV Hits 8 0 4 11 0 20 14 26 
AV Count 32 
CC Servers 88.198.228.238:65520 218.93.201.51:65520 
DNS Lookups CN:proxim.ircgalaxy.pl CN:down1130.iwillhavesexygirls.com EU:pozeml.com CN:1130.kfgrtjer.cn :pozemle.cn CN:ty.lnlycnc.cn :wws.mobiec.net :xz.ub9.net :in.7cy.net :in1.7cy.net :patchcar.com US:i.nuseek.com US:rc10.overture.com US:m1549.ic-live.com DE:proxim.ircgalaxy.pl US:microsoft.com CN:av.lometr.pl :bfkq.com :jsactivity.com US:search.toptravellingtips.com DE:proxima.ircgalaxy.pl :commerceclick.co.uk :www.toptravellingtips.com US:exceptionprinciple.net :dci-press.com US:as.casalemedia.com :hf.davinci.com US:activex.microsoft.com US:codecs.microsoft.com :yeuku.com 
Failed Connects 1.1.1.1:80 US:206.16.45.171:80 DE:88.198.228.238:65520 204.27.57.154:8392 CN:61.235.117.71:80 173.45.105.218:8392 US:204.2.133.105:80 US:64.95.64.197:80 
AV Name AhnLab-V3:Win-Xema.variant, AntiVir:TRDrop.Puzlice.A, Authentium:MISSED, Avast:_VB-LYG, AVG:Clicker.ACJF, BitDefender:Generic.2527032, CAT-QuickHeal:MISSED, ClamAV:MISSED, DrWeb:MulDrop.34065, eSafe:TrojanDropperP, eTrust-Vet:MISSED, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:PossibleThreat, F-Prot:MISSED, F-Secure:Generic.2527032, Ikarus:Trojan-Spy.VB, Kaspersky:Trojan-Dropper.VB.afbw, McAfee:MISSED, Microsoft:TrojanDropper_Puzlice.A, NOD32v2:MISSED, Norman:Smalltroj.SXCH, Panda:TrjCI.A, Prevx1:MISSED, Rising:MISSED, Sophos:TrojVB-EJN, Sunbelt:MISSED, Symantec:Downloader, TheHacker:MISSED, VBA32:MISSED, VirusBuster:MISSED, Webwasher-Gateway:MISSED  
WinXP Files 3.tmp, 8986475.exe, accwiz.exe, achxqy, actmovie.exe, agentsvr.exe, ahui.exe, alg.exe, arp.exe, asr_fmt.exe, asr_ldm.exe, at.exe, atmadm.exe, attrib.exe, bootcfg.exe, bootok.exe, bootvrfy.exe, cacls.exe, calc.exe, charmap.exe, chkdsk.exe, chkntfs.exe, cidaemon.exe, cipher.exe, cisvc.exe, ckcnv.exe, cleanmgr.exe, cliconfg.exe, clipbrd.exe, clipsrv.exe, cmdl32.exe, cmmon32.exe, cmstp.exe, compact.exe, comp.exe, comrepl.exe, conime.exe, control.exe, convert.exe, cooper.mine, cscript.exe, ctfmon.exe, dcomcnfg.exe, ddeshare.exe, defrag.exe, dfrgfat.exe, dfrgntfs.exe, diantz.exe, diskpart.exe, diskperf.exe, dllhost.exe, dllhst3g.exe, dmadmin.exe, dmremote.exe, doskey.exe, dplaysvr.exe, dpnsvr.exe, dpvsetup.exe, driverquery.exe, drwtsn32.exe, dumprep.exe, dvdplay.exe, dvdupgrd.exe, dxdiag.exe, esentutl.exe, eudcedit.exe, eventcreate.exe, eventtriggers.exe, eventvwr.exe, expand.exe, extrac32.exe, fc.exe, find.exe, findstr.exe, finger.exe, fixmapi.exe, fontview.exe, forcedos.exe, freecell.exe, fsutil.exe, ftp.exe, getmac.exe, gpresult.exe, gpupdate.exe, grpconv.exe, HelpCtr.exe, help.exe, HelpHost.exe, HelpSvc.exe, hh.exe, hostname.exe, ie4uinit.exe, iexpress.exe, imapi.exe, Install.txt, ipconfig.exe, ipsec6.exe, ipv6.exe, ipxroute.exe, kzp.4e, label.exe, lights.exe, lnkstub.exe, locator.exe, lodctr.exe, logagent.exe, logman.exe, logoff.exe, logon.scr, logonui.exe, lpq.exe, lpr.exe, lsm32.sys, magnify.exe, makecab.exe, migload.exe, migpwd.exe, migwiz_a.exe, migwiz.exe, mmc.exe, mnmsrvc.exe, mobsync.exe, mofcomp.exe, mofcomp.log, mountvol.exe, mplay32.exe, mpnotify.exe, mqbkup.exe, mqsvc.exe, mqtgsvc.exe, mrinfo.exe, msconfig.exe, msdtc.exe, msg.exe, mshearts.exe, mshta.exe, msiexec.exe, msoobe.exe, mspaint.exe, mspyebhv.dll, msswchx.exe, mstinit.exe, mstsc.exe, narrator.exe, nbtstat.exe, nddeapir.exe, net1.exe, netdde.exe, net.exe, netsetup.exe, netsh.exe, netstat.exe, NOTEPAD.EXE, notiflag.exe, nppagent.exe, nslookup.exe, ntbackup.exe, ntload.dll, ntsd.exe, ntvdm.exe, nwscript.exe, odbcad32.exe, odbcconf.exe, oobebaln.exe, openfiles.exe, osk.exe, osuninst.exe, packager.exe, pathping.exe, pentnt.exe, perfmon.exe, ping6.exe, print.exe, progman.exe, proquota.exe, proxycfg.exe, qappsrv.exe, qprocess.exe, qwinsta.exe, rasautou.exe, rasdial.exe, rasphone.exe, rcimlby.exe, rcp.exe, rdpclip.exe, rdsaddin.exe, rdshost.exe, recover.exe, relog.exe, replace.exe, reset.exe, rexec.exe, routemon.exe, rsh.exe, rsm.exe, rsmsink.exe, rsmui.exe, rsnotify.exe, rsopprov.exe, rstrui.exe, rsvp.exe, rtcshare.exe, rth.gde, runas.exe, runonce.exe, rwinsta.exe, savedump.exe, scardsvr.exe, schtasks.exe, scrcons.exe, scrnsave.scr, sdbinst.exe, secedit.exe, sessmgr.exe, sethc.exe, sfc.exe, shadow.exe, shmgrate.exe, shrpubw.exe, shutdown.exe, sigverif.exe, skeys.exe, smlogsvc.exe, sndrec32.exe, sndvol32.exe, sol.exe, sort.exe, spider.exe, srdiag.exe, ss3dfo.scr, ssbezier.scr, ssflwbox.scr, ssmarque.scr, ssmypics.scr, ssmyst.scr, sspipes.scr, ssstars.scr, sstext3d.scr, stimon.exe, subst.exe, SVCHOST.EXE, syncapp.exe, syskey.exe, sysocmgr.exe, systeminfo.exe, systray.exe, taskkill.exe, tasklist.exe, taskman.exe, taskmgr.exe, tcmsetup.exe, tcpsvcs.exe, telnet.exe, tftp.exe, tlntadmn.exe, tlntsess.exe, tlntsvr.exe, tourstart.exe, tracerpt.exe, tracert6.exe, tracert.exe, tscon.exe, tscupgrd.exe, tsdiscon.exe, tskill.exe, tsshutdn.exe, twunk_32.exe, typeperf.exe, unlodctr.exe, unsecapp.exe, UploadM.exe, upnpcont.exe, ups.exe, user32.DLL, userinit.exe, usrmlnka.exe, usrprbda.exe, usrshuta.exe, utilman.exe, verifier.exe, VRT5.tmp, vssadmin.exe, vssvc.exe, w32tm.exe, wbemtest.exe, wextract.exe, wiaacmgr.exe, winhlp32.exe, winmgmt.exe, winmine.exe, winmsd.exe, winver.exe, wmiadap.exe, wmiapsrv.exe, wmic.exe, wmpstub.exe, wpabaln.exe, wpnpinst.exe, write.exe, wuauclt.exe, wupdmgr.exe, x1c51626.dll, xcopy.exe  
WinXP Processes 8986475.exe, CMD.EXE, CSRSS.EXE, DLLHOST.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, Rundll32.exe, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, VRT5.tmp, WINLOGON.EXE, wmiprvse.exe  
WinXP Registries HKEY_LOCAL_MACHINE@...Microsoft\\DownloadManager, HKEY_LOCAL_MACHINE@...Software\\1, HKEY_LOCAL_MACHINE@...Software\\9, HKEY_LOCAL_MACHINE@...WBEM\\WMIC, HKEY_USERS@...InternetExplorer\\International  
WinXP Ports 1031, 1035, 1047, 1061, 1062, 1064, 1067, 3389, 1034, 1046, 1051  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys  
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 StarForce 
Packer ID2  
Embedded DNS  
String Count  
String Link text
String MD5  
Timerange 365 Days 
Unpack Status unknown () 
Countries
Unpacked Link  
Callgraph  
API Resolution  
Comment none