Packed MD5 639a247ececd70fed47053ea3641c592 
Priority 12 
First 04/28/2008 
Last 06/27/2008 
Count 37 
History 37 hits: 04-28 to 06-27 
Unpacked MD5 29d53eec72ee8c9f274008e4b6da7fa0  
AV Hits 10 
AV Count 32 
CC Servers 211.96.97.44:7000 222.177.11.165:7000 209.250.232.240:7000 
DNS Lookups CN:hail.dns2go.com CN:scorti1.dns2go.com HK:hail.dns2go.com US:scorti1.dns2go.com US:hail.dns2go.com 
Failed Connects CN:211.96.97.44:7000 CN:222.177.11.165:7000 CN:218.93.14.236:7000 US:209.250.232.240:7000 
AV Name AhnLab-V3:MISSED, AntiVir:TRInject.FW.47, Authentium:MISSED, Avast:MISSED, AVG:MISSED, BitDefender:Inject.FW, CAT-QuickHeal:MISSED, ClamAV:MISSED, DrWeb:Trojan, eSafe:MISSED, eTrust-Vet:MISSED, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:MISSED, F-Prot:Heuristic-119!Eldorado, F-Secure:MISSED, Ikarus:Inject.FW, Kaspersky:MISSED, McAfee:MISSED, Microsoft:VirTool_DelfInject.gen!K, NOD32v2:MISSED, Norman:MISSED, Panda:MISSED, Prevx1:MISSED, Rising:MISSED, Sophos:MalBehav-154, Sunbelt:MISSED, Symantec:MISSED, TheHacker:MISSED, VBA32:MISSED, VirusBuster:MISSED, Webwasher-Gateway:Inject.FW.47  
WinXP Files msnmanegers.exe  
WinXP Processes CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE, defrag.exe, DfrgFat.exe, msnmanegers.exe  
WinXP Registries HKEY_LOCAL_MACHINE@...CurrentVersion\RunServices, HKEY_USERS@...CurrentVersion\RunOnce, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...CurrentVersion\\RunOnce  
WinXP Ports 21072, 1040, 21526, 1038, 11642, 4040, 1039, 18028  
Win-2Kf Files  
Win-2Kf Processes msnmanegers.exe  
Win-2Kf Registries HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...CurrentVersion\\Run  
Win-2Kf Ports 1030, 3622, 4827, 4828, 1041, 19908, 1044, 11782, 1233, 1234, 1235, 1236, 1237, 1238, 1239, 1240, 1241, 1242, 1243, 1244, 1245, 1246, 1247, 1248, 1249, 1250, 1251, 1252, 1253, 1254, 1255, 1256, 1257, 1258, 1259, 1260, 1261, 1262, 1263, 1264, 1265, 1266, 1267, 1268, 1269, 1270, 1271, 1272, 1273, 1274, 1275, 1276, 1277, 1278, 4419, 1052, 2967, 5348, 10591, 1056, 16693, 13930, 14745  
Create Events  
Create Files  
Create RegKeys Software\Microsoft\Windows\CurrentVersion\Run,Software\Microsoft\Windows\CurrentVersion\RunServices 
Open RegKeys SOFTWARE\Borland\Delphi\RTL,Software\Borland\Locales,Software\Borland\Delphi\Locales,Software\Microsoft\Windows\CurrentVersion\Run,Software\Microsoft\Windows\CurrentVersion\RunServices 
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 StarForce 
Packer ID2  
Embedded DNS  
String Count 132 
String Link text
String MD5 cb658527e72d3f618ddd88f9255b6295 
Timerange 365 Days 
Unpack Status good (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (84.22%, 11.31%)) 
Countries 18 
Unpacked Link 29d53eec72 [0
Callgraph ASM:Graph 
API Resolution 77% 
Comment none