| Packed MD5 | 2905d384e23d29d91a0d549818074f08 |
| Priority | 0 |
| First | 07/03/2008 |
| Last | 07/04/2008 |
| Count | 3 |
| History | 3 hits: 07-03 to 07-04 |
| Unpacked MD5 | |
| AV Hits | 29 |
| AV Count | 32 |
| CC Servers | 217.170.244.2:443 |
| DNS Lookups | |
| Failed Connects | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
| AV Name | AhnLab-V3:Virut.B, AntiVir:Virut.Z, Authentium:Virut.AB, Avast:_Trojano-3403, AVG:Virut, BitDefender:Sdbot.OKR@mm, CAT-QuickHeal:Virut.H, ClamAV:Virut-2, DrWeb:Virut.8, eSafe:MISSED, eTrust-Vet:Virut.6556, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:SDBot.OKR@mm, F-Prot:Virut.AB, F-Secure:Virut.r, Ikarus:Rbot, Kaspersky:Virut.r, McAfee:Virut.d, Microsoft:MISSED, NOD32v2:Virut.S, Norman:SDBot.BFGX, Panda:Virutas.V, Prevx1:MISSED, Rising:Virut.r, Sophos:Virut-T, Sunbelt:MISSED, Symantec:Spybot.Worm, TheHacker:Virut.gen, VBA32:Virut.r, VirusBuster:RBot.DBI, Webwasher-Gateway:Virut.Z |
| WinXP Files | Abort |
| WinXP Processes | CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, uepupcq32.exe, WINLOGON.EXE |
| WinXP Registries | HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...Microsoft\\OLE |
| WinXP Ports | 1040, 3241, 3242, 3243, 3244, 3245, 3246, 3247, 3248, 3249, 3250, 3251, 3252, 3253, 3254, 3255, 3256, 3257, 3258, 3259, 3260, 3261, 3262, 3263, 3264, 3265, 3266, 3267, 3268, 3269, 3270, 3271, 3272, 3273, 3274, 3275, 3276, 3277, 3278, 3279, 3280, 3281, 3282, 3283, 3284, 3285, 3286, 3287, 3288, 3289, 3290, 3291, 3292, 3293, 3294, 3295, 3296, 3297, 3298, 3299, 3300, 3301, 3302, 3303, 3304, 3305, 3306, 3307, 3308, 3309, 3310, 3311, 3312, 3313, 3314, 3315, 3316, 3317, 3318, 3319, 3320, 3321, 3322, 3323, 3324, 3325, 3326, 3327, 3328, 3329, 3330, 3331, 3332, 3333, 3334, 3335, 3336, 3337, 3338, 3339, 3340, 3341, 3342, 3343, 3344, 3345, 3346, 3347, 3348, 3349, 3350, 3351, 3352, 3353, 3354, 3355, 3356, 3357, 3358, 3359, 3360, 3361, 3362, 3363, 3364, 3365, 3366, 3367, 3368, 3369, 3370, 3371, 3372, 3373, 3374, 3375, 3376, 3377, 3378, 3379, 3380, 3381, 3382, 3383, 3384, 3385, 3386, 3387, 3388, 3389, 3390, 3391, 3392, 3393, 3394, 3395, 3396, 3397, 3398, 3399, 3400, 3401, 3402, 3403, 3404, 3405, 3406, 3407, 3408, 3409, 3410, 3411, 3412, 3413, 3414, 3415, 3416, 40310, 44445 |
| Win-2Kf Files | |
| Win-2Kf Processes | qndekjq32.exe |
| Win-2Kf Registries | HKEY_LOCAL_MACHINE@...CurrentVersion\RunServices, HKEY_USERS@...InternetSettings\5.0, HKEY_USERS@...InternetSettings\Connections, HKEY_USERS@...Microsoft\OLE |
| Win-2Kf Ports | 44445 |
| Create Events | |
| Create Files | |
| Create RegKeys | |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | none |
| Packer ID2 | none |
| Embedded DNS | |
| String Count | |
| String Link | text |
| String MD5 | |
| Timerange | 365 Days |
| Unpack Status | unknown () |
| Countries | 1 |
| Unpacked Link | none[none] |
| Callgraph | none:none |
| API Resolution | |
| Comment | none |