Packed MD5 8ae058b2d061c59f72546c9df68aeb01 
Priority
First 05/01/2008 
Last 08/27/2008 
Count 12 
History 12 hits: 05-01 to 08-27 
Unpacked MD5 e6a9383b75bc38fb83230a525348c550  
AV Hits 30 
AV Count 32 
CC Servers  
DNS Lookups  
Failed Connects  
AV Name AhnLab-V3:Virut.B, AntiVir:Virut.AL, Authentium:Sasser.C, Avast:_Sasser-C, AVG:Virut, BitDefender:Sasser.C, CAT-QuickHeal:Virut.P, ClamAV:Virut-9, DrWeb:Virut.17, eSafe:Virut.gen, eTrust-Vet:Virut.6548, Ewido:Sasser.a, FileAdvisor:MISSED, Fortinet:Virut.AI, F-Prot:Sasser.C, F-Secure:Virut.AF, Ikarus:Email-Plexus, Kaspersky:Sasser.a, McAfee:Virut.gen.a, Microsoft:Virut.V, NOD32v2:Virut.NAT, Norman:Virut.AF, Panda:Sasser.C.worm, Prevx1:MISSED, Rising:Virut.ab, Sophos:Virut-S, Sunbelt:Sasser.C, Symantec:Sasser.C.Worm, TheHacker:Virut.gen, VBA32:Virut.ab, VirusBuster:Virut.Gen.4, Webwasher-Gateway:Virut.AL  
WinXP Files 22834_up.exe, avserve2.exe, 3633_up.exe  
WinXP Processes 22834_up.exe, CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE, 3633_up.exe  
WinXP Registries  
WinXP Ports 1155, 1171, 1290, 1310, 1353, 1382, 1715, 1725, 1918, 1933, 2015, 2212, 2231, 2474, 2493, 2525, 2550, 2733, 2751, 3014, 3017, 3161, 3162, 3177, 3179, 3184, 3205, 3690, 3707, 3829, 3843, 3847, 3915, 3927, 4381, 4398, 445, 4493, 4507, 4550, 4559, 4936, 4958, 5554, 9996, 1081, 1100, 1154, 1402, 1421, 1451, 1480, 1629, 1649, 1655, 1665, 1672, 1693, 1760, 1767, 2021, 2044, 2335, 2350, 2466, 2468, 2488, 2492, 2494, 2976, 2995, 3030, 3046, 3053, 3075, 3249, 3256, 3264, 3282, 3327, 3341, 3448, 3460, 3480, 3488, 3495, 3499, 3520, 3537, 3540, 3586, 3597, 3634, 3658, 3749, 3766, 3930, 3952, 4034, 4059, 4266, 4279, 4333, 4357, 4563, 4587, 4599, 4601, 4609, 4612, 4614, 4630, 4632, 4649, 4759, 4778, 4818, 4838, 4966, 4994  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys SOFTWARE\Microsoft\Windows\CurrentVersion\Run 
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 none 
Packer ID2 none 
Embedded DNS  
String Count 59 
String Link text
String MD5 02504f1d94cb975dc632f745ba16883b 
Timerange 365 Days 
Unpack Status good (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (83.77%, 13.39%)) 
Countries
Unpacked Link e6a9383b75 [0
Callgraph ASM:Graph 
API Resolution 97% 
Comment none