Packed MD5 cc545e1c99ca94f0d3f9d50b4d18e344 
Priority
First 05/30/2008 
Last 08/17/2008 
Count
History 4 hits: 05-30 to 08-17 
Unpacked MD5 97a4355156d7011f77d47eb954f71c02  
AV Hits 28 
AV Count 32 
CC Servers  
DNS Lookups  
Failed Connects  
AV Name AhnLab-V3:MISSED, AntiVir:Virut.AX, Authentium:Virut.7116, Avast:_Sasser-C, AVG:Virut, BitDefender:Sasser.C, CAT-QuickHeal:Virut.Z, ClamAV:Virut-17, DrWeb:Virut.30, eSafe:MISSED, eTrust-Vet:Virut.7115, Ewido:Sasser.a, FileAdvisor:MISSED, Fortinet:Virut.AV, F-Prot:Sasser.C, F-Secure:Virut.AG, Ikarus:Email-Plexus, Kaspersky:Sasser.a, McAfee:Virut.gen.a, Microsoft:MISSED, NOD32v2:Virut.AV, Norman:Virut.AG, Panda:Sasser.C.worm, Prevx1:MISSED, Rising:Virut.an, Sophos:Virut-W, Sunbelt:MISSED, Symantec:Sasser.C.Worm, TheHacker:MISSED, VBA32:Virut.2, VirusBuster:Virut.Gen.4, Webwasher-Gateway:Virut.AX  
WinXP Files 24534_up.exe, avserve2.exe  
WinXP Processes 24534_up.exe, CMD.EXE, CSRSS.EXE, dwwin.exe, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE  
WinXP Registries  
WinXP Ports 1028, 1091, 1093, 1100, 1101, 1106, 1112, 1114, 1119, 1140, 1156, 1161, 1230, 1250, 1259, 1278, 1332, 1344, 1447, 1460, 1533, 1546, 1669, 1672, 1715, 1733, 1769, 1789, 1830, 1848, 1852, 1873, 1902, 1908, 1910, 1918, 1935, 2028, 2045, 2053, 2064, 2078, 2107, 2142, 2143, 2150, 2165, 2196, 2224, 2282, 2291, 2490, 2503, 2576, 2583, 2603, 2604, 2621, 2634, 2743, 2766, 2982, 2985, 2988, 3000, 3079, 3092, 3150, 3174, 3187, 3210, 3312, 3329, 3330, 3351, 3386, 3416, 3520, 3541, 3598, 3623, 3719, 3734, 3812, 3820, 3833, 3834, 3838, 3871, 3873, 4048, 4062, 4199, 4207, 4305, 4319, 4325, 4354, 4458, 4471, 4478, 4496, 4612, 4624, 4713, 4728, 4920, 4933, 4947, 4954, 5554, 9996  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys  
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 none 
Packer ID2 none 
Embedded DNS  
String Count 90 
String Link text
String MD5 1fe7e5e820742637004068476cf9f858 
Timerange 365 Days 
Unpack Status good (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (80.78%, 14.03%)) 
Countries
Unpacked Link 97a4355156 [0
Callgraph ASM:Graph 
API Resolution 47% 
Comment none