Packed MD5 474acf88e5450f969eb7dcdc41137b9c 
Priority
First 01/20/2012 
Last 02/04/2012 
Count  
History  
Unpacked MD5 1f53944b2492278956bc3856af7cd9ba  
AV Hits 38 38 
AV Count 32 
CC Servers  
DNS Lookups US:microsoft.com 
Failed Connects  
AV Name AhnLab-V3:Virut, AntiVir:Virut.AT, Authentium:Virut.AG, Avast:_Virtob, AVG:Virut, BitDefender:Virtob.7.Gen, CAT-QuickHeal:Virut.Y, ClamAV:Small-4287, DrWeb:Virut.27, eSafe:MISSED, eTrust-Vet:Virut.6640, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:Virut.AT, F-Prot:Virut.AG, F-Secure:Virut.at, Ikarus:Virut, Kaspersky:Virut.at, McAfee:Virut.gen.a, Microsoft:Virut.AA, NOD32v2:MISSED, Norman:Virut.BL, Panda:Virutas.AH, Prevx1:MISSED, Rising:Virut.al, Sophos:Virut-Gen, Sunbelt:MISSED, Symantec:Virut.W, TheHacker:Virut.genS, VBA32:Virut.2, VirusBuster:Virut.Gen.4, Webwasher-Gateway:MISSED  
WinXP Files DLLHOST.EXE, SVCHOST.EXE  
WinXP Processes CMD.EXE, CSRSS.EXE, DLLHOST.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE  
WinXP Registries  
WinXP Ports 1031  
Win-2Kf Files  
Win-2Kf Processes DLLHOST.EXE  
Win-2Kf Registries  
Win-2Kf Ports 1027  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB823980,SOFTWARE\Microsoft\Updates\Windows XP\SP1\KB823980,SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB823980 
Service Starts RpcPatch 
Service Deletes RpcPatch,RpcTftpd 
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 Armadillo 
Packer ID2  
Embedded DNS  
String Count 91 
String Link text
String MD5 30018e66fb67056f1acf6962b1677d8e 
Timerange 365 Days 
Unpack Status unknown (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (67.82%, 22.56%)) 
Countries
Unpacked Link  
Callgraph  
API Resolution  
Comment none