Packed MD5 4ab5b0788c99990e2131796d3130387d 
Priority
First 04/21/2008 
Last 06/25/2008 
Count 13 
History 13 hits: 04-21 to 06-25 
Unpacked MD5 272da55ef88001468f90a908beb709a1  
AV Hits 29 
AV Count 32 
CC Servers 85.114.143.208:65520 
DNS Lookups :proxim.ircgalaxy.pl UA:citi-bank.ru DE:proxim.ircgalaxy.pl DE:kidos-bank.ru 
Failed Connects UA:194.54.90.246:80 DE:85.114.137.60:65520 DE:85.114.143.208:65520 
AV Name AhnLab-V3:Virut.D, AntiVir:Virut.Gen, Authentium:Korgo.P, Avast:_Korgo-P, AVG:Korgo.A, BitDefender:Korgo.Q, CAT-QuickHeal:Virut.D, ClamAV:MISSED, DrWeb:Virut.5, eSafe:Virut.gen, eTrust-Vet:Virut.9276, Ewido:Padobot.g, FileAdvisor:MISSED, Fortinet:Virut.E, F-Prot:Korgo.P, F-Secure:Horst.gen33, Ikarus:Korgo.P, Kaspersky:Virut.n, McAfee:Virut.gen, Microsoft:Virut.AK, NOD32v2:Virut.E, Norman:Virut.BF, Panda:Virutas.G, Prevx1:MISSED, Rising:Proxy.Horst.a, Sophos:Virut-L, Sunbelt:MISSED, Symantec:MISSED, TheHacker:Virut.F, VBA32:Virut.3, VirusBuster:Virut.Gen, Webwasher-Gateway:Virut.Gen  
WinXP Files accwiz.exe, actmovie.exe, agentsvr.exe, ahui.exe, alg.exe, arp.exe, asr_fmt.exe, asr_ldm.exe, at.exe, atmadm.exe, attrib.exe, bootcfg.exe, bootok.exe, bootvrfy.exe, cacls.exe, calc.exe, cckaa.exe, charmap.exe, chkdsk.exe, chkntfs.exe, cidaemon.exe, cipher.exe, cisvc.exe, ckcnv.exe, cleanmgr.exe, cliconfg.exe, clipbrd.exe, clipsrv.exe, cmd.exe, cmdl32.exe, cmmon32.exe, cmstp.exe, compact.exe, comp.exe, comrepl.exe, conime.exe, control.exe, convert.exe, cscript.exe, ctfmon.exe, dcomcnfg.exe, ddeshare.exe, defrag.exe, dfrgfat.exe, dfrgntfs.exe, diantz.exe, diskpart.exe, diskperf.exe, dllhost.exe, dllhst3g.exe, dmadmin.exe, dmremote.exe, doskey.exe, dplaysvr.exe, dpnsvr.exe, dpvsetup.exe, driverquery.exe, drwtsn32.exe, dumprep.exe, dvdplay.exe, dvdupgrd.exe, dxdiag.exe, esentutl.exe, eudcedit.exe, eventcreate.exe, eventtriggers.exe, eventvwr.exe, expand.exe, extrac32.exe, fc.exe, find.exe, findstr.exe, finger.exe, fixmapi.exe, fontview.exe, forcedos.exe, freecell.exe, fsutil.exe, ftp.exe, ftpupd.exe, getmac.exe, gpresult.exe, gpupdate.exe, grpconv.exe, HelpCtr.exe, help.exe, HelpHost.exe, HelpSvc.exe, hh.exe, hostname.exe, ie4uinit.exe, iexpress.exe, imapi.exe, ipconfig.exe, ipsec6.exe, ipv6.exe, ipxroute.exe, label.exe, lights.exe, lnkstub.exe, locator.exe, lodctr.exe, logagent.exe, logman.exe, logoff.exe, logon.scr, logonui.exe, lpq.exe, lpr.exe, magnify.exe, makecab.exe, migload.exe, migpwd.exe, migwiz_a.exe, migwiz.exe, mmc.exe, mnmsrvc.exe, mobsync.exe, mofcomp.exe, mountvol.exe, mplay32.exe, mpnotify.exe, mqbkup.exe, mqsvc.exe, mqtgsvc.exe, mrinfo.exe, msconfig.exe, msdtc.exe, msg.exe, mshearts.exe, mshta.exe, msiexec.exe, msoobe.exe, mspaint.exe, msswchx.exe, mstinit.exe, mstsc.exe, narrator.exe, nbtstat.exe, nddeapir.exe, net1.exe, netdde.exe, net.exe, netsetup.exe, netsh.exe, netstat.exe, NOTEPAD.EXE, notiflag.exe, nppagent.exe, nslookup.exe, ntbackup.exe, ntsd.exe, ntvdm.exe, nwscript.exe, odbcad32.exe, odbcconf.exe, oobebaln.exe, openfiles.exe, osk.exe, osuninst.exe, packager.exe, pathping.exe, pentnt.exe, perfmon.exe, phqghu.exe, ping6.exe, print.exe, progman.exe, proquota.exe, proxycfg.exe, qappsrv.exe, qprocess.exe, qwinsta.exe, rasautou.exe, rasdial.exe, rasphone.exe, rcimlby.exe, rcp.exe, rdpclip.exe, rdsaddin.exe, rdshost.exe, recover.exe, relog.exe, replace.exe, reset.exe, rexec.exe, routemon.exe, rsh.exe, rsm.exe, rsmsink.exe, rsmui.exe, rsnotify.exe, rsopprov.exe, rstrui.exe, rsvp.exe, rtcshare.exe, runas.exe, rundll32.exe, runonce.exe, rwinsta.exe, savedump.exe, scardsvr.exe, schtasks.exe, scrcons.exe, scrnsave.scr, sdbinst.exe, secedit.exe, sessmgr.exe, sethc.exe, sfc.exe, shadow.exe, shmgrate.exe, shrpubw.exe, shutdown.exe, sigverif.exe, skeys.exe, smlogsvc.exe, sndrec32.exe, sndvol32.exe, sol.exe, sort.exe, spider.exe, srdiag.exe, ss3dfo.scr, ssbezier.scr, ssflwbox.scr, ssmarque.scr, ssmypics.scr, ssmyst.scr, sspipes.scr, ssstars.scr, sstext3d.scr, stimon.exe, subst.exe, syncapp.exe, syskey.exe, sysocmgr.exe, systeminfo.exe, systray.exe, taskkill.exe, tasklist.exe, taskman.exe, taskmgr.exe, tcmsetup.exe, tcpsvcs.exe, telnet.exe, tftp.exe, tlntadmn.exe, tlntsess.exe, tlntsvr.exe, tourstart.exe, tracerpt.exe, tracert6.exe, tracert.exe, tscon.exe, tscupgrd.exe, tsdiscon.exe, tskill.exe, tsshutdn.exe, twunk_32.exe, typeperf.exe, unlodctr.exe, unsecapp.exe, UploadM.exe, upnpcont.exe, ups.exe, userinit.exe, usrmlnka.exe, usrprbda.exe, usrshuta.exe, utilman.exe, verifier.exe, vssadmin.exe, vssvc.exe, w32tm.exe, wbemtest.exe, wextract.exe, wiaacmgr.exe, winhlp32.exe, winmgmt.exe, winmine.exe, winmsd.exe, winver.exe, wmiadap.exe, wmiapsrv.exe, wmic.exe, wmiprvse.exe, wmpstub.exe, wpabaln.exe, wpnpinst.exe, write.exe, wuauclt.exe, wupdmgr.exe, xcopy.exe, mjosm.exe, lpqmkrk.exe, iqxrys.exe, jmzqshe.exe, wikvla.exe, ywnld.exe, pjnvjs.exe, ckdtz.exe, naknfnei.exe  
WinXP Processes cckaa.exe, CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE, mjosm.exe, lpqmkrk.exe, iqxrys.exe, jmzqshe.exe, wikvla.exe, ywnld.exe, pjnvjs.exe, ckdtz.exe, naknfnei.exe  
WinXP Registries HKEY_LOCAL_MACHINE@...Microsoft\\Wireless  
WinXP Ports 1032, 3466, 1048, 3775, 1047, 1007, 1037, 6687, 1534, 1040, 2937, 4354, 1072, 3469, 1038, 1144, 3180, 1070, 1872, 1039  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys .exe,Windows Update,SOFTWARE\Microsoft\Windows\CurrentVersion\Run,ID,Client 
Open RegKeys Windows Update,SOFTWARE\Microsoft\Windows\CurrentVersion\Run,Software\Microsoft\Wireless,ID,Client 
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 PolyEnE 
Packer ID2  
Embedded DNS  
String Count 114 
String Link text
String MD5 122527dcd971ef6799945e941fde1cea 
Timerange 365 Days 
Unpack Status good (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (60.43%, 17.68%)) 
Countries
Unpacked Link 272da55ef8 [0
Callgraph ASM:Graph 
API Resolution 100% 
Comment none