Packed MD5 1c5e79f5f4caab5f5c9a69ab91d478b2 
Priority
First 10/10/2009 
Last 11/03/2009 
Count  
History  
Unpacked MD5 778da26bf31d99f578a270a94fcad19a  
AV Hits 17 34 39 7 10 30 
AV Count 32 
CC Servers 218.93.205.30:65520 91.212.220.75:65520 
DNS Lookups EU:proxima.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn CN:www.petdoso.com GB:www.businesstomb.com CN:proxim.ircgalaxy.pl EU:sleepatnight.cn CN:dl.guarddog2009.com :komojoke.cn :bfkq.com :jsactivity.com US:search.toptravellingtips.com CN:www.brans.pl EU:streq.cn :horobl.cn :sendfan.com :www.sendfan.com US:atmospherey.info EU:proxim.ircgalaxy.pl :ns2.mm1-shop.net CN:proxima.ircgalaxy.pl EU:mskfintrust.com US:getrichquickbusiness.com US:searchportal.information.com US:spi.domainsponsor.com US:ads1.revenue.net US:as.casalemedia.com US:activex.microsoft.com US:codecs.microsoft.com :xz.ub9.net :nenastiya.cn CN:config1007.iwillhavesexygirls.com :wws.mobiec.net :jnmr.com :hf.davinci.com CN:maillist.iwillhavesexygirls.com US:faxwelt.com :www.statcounter.com :c.statcounter.com US:www.themakecash.com :datingpopular.com US:emphasisi.com :incometaxliabilities.com :sqltop.net CA:bestgamingoffers.com US:dealandplay.com US:freeonly.net US:shopmastersdegree.info US:cellphonesdish.info US:totalinventories.info US:search.articleswave.co.uk :ectap.com :parkingbill.com 
Failed Connects 174.36.176.242:81 EU:91.212.220.75:65520 CN:202.97.184.196:81 US:66.96.221.101:8392 US:69.59.170.246:80 CN:218.93.205.30:65520 US:208.109.98.106:80 US:64.191.44.5:80 204.27.57.154:8392 US:208.43.250.167:80 93.174.92.220:80 
AV Name AhnLab-V3:Virut, AntiVir:Virut.A, Authentium:Virut.4960, Avast:_Nachi, AVG:Virut.A, BitDefender:Welchia.A, CAT-QuickHeal:Virut.A, ClamAV:Virut.A, DrWeb:Virut, eSafe:Virut.a, eTrust-Vet:Virut.5127, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:Virut.A, F-Prot:Virut.4960, F-Secure:Virut.a, Ikarus:Virut.a, Kaspersky:Virut.a, McAfee:Virut.a, Microsoft:MISSED, NOD32v2:Virut.5127, Norman:Virut.A, Panda:Virutas.B, Prevx1:MISSED, Rising:Virut.az, Sophos:Virut-T, Sunbelt:MISSED, Symantec:Virut.A, TheHacker:Virut.gen, VBA32:Virut.A, VirusBuster:Nachi, Webwasher-Gateway:Virut.A  
WinXP Files 2.tmp, 3.tmp, accwiz.exe, actmovie.exe, agentsvr.exe, ahui.exe, alg.exe, arp.exe, asr_fmt.exe, asr_ldm.exe, at.exe, atmadm.exe, attrib.exe, bootcfg.exe, bootok.exe, bootvrfy.exe, cacls.exe, calc.exe, charmap.exe, chkdsk.exe, chkntfs.exe, cidaemon.exe, cipher.exe, cisvc.exe, ckcnv.exe, cleanmgr.exe, cliconfg.exe, clipbrd.exe, clipsrv.exe, cmdl32.exe, cmmon32.exe, cmstp.exe, compact.exe, comp.exe, comrepl.exe, conime.exe, control.exe, convert.exe, cscript.exe, ctfmon.exe, dcomcnfg.exe, ddeshare.exe, defrag.exe, dfrgfat.exe, dfrgntfs.exe, diantz.exe, diskpart.exe, diskperf.exe, dllhost.exe, dllhst3g.exe, dmadmin.exe, dmremote.exe, doskey.exe, dplaysvr.exe, dpnsvr.exe, dpvsetup.exe, driverquery.exe, drwtsn32.exe, dumprep.exe, dvdplay.exe, dvdupgrd.exe, dxdiag.exe, esentutl.exe, eudcedit.exe, eventcreate.exe, eventtriggers.exe, eventvwr.exe, expand.exe, extrac32.exe, fc.exe, find.exe, findstr.exe, finger.exe, fixmapi.exe, fontview.exe, forcedos.exe, freecell.exe, fsutil.exe, ftp.exe, getmac.exe, gpresult.exe, gpupdate.exe, grpconv.exe, HelpCtr.exe, help.exe, HelpHost.exe, HelpSvc.exe, hh.exe, hostname.exe, ie4uinit.exe, iexpress.exe, imapi.exe, ipconfig.exe, ipsec6.exe, ipv6.exe, ipxroute.exe, label.exe, lights.exe, lnkstub.exe, locator.exe, lodctr.exe, logagent.exe, logman.exe, logoff.exe, logon.scr, logonui.exe, lpq.exe, lpr.exe, magnify.exe, makecab.exe, migload.exe, migpwd.exe, migwiz_a.exe, migwiz.exe, mmc.exe, mnmsrvc.exe, mobsync.exe, mofcomp.exe, mountvol.exe, mplay32.exe, mpnotify.exe, mqbkup.exe, mqsvc.exe, mqtgsvc.exe, mrinfo.exe, msconfig.exe, msdtc.exe, msg.exe, mshearts.exe, mshta.exe, msiexec.exe, msoobe.exe, mspaint.exe, msswchx.exe, mstinit.exe, mstsc.exe, narrator.exe, nbtstat.exe, nddeapir.exe, net1.exe, netdde.exe, net.exe, netsetup.exe, netsh.exe, netstat.exe, NOTEPAD.EXE, notiflag.exe, nppagent.exe, nslookup.exe, ntbackup.exe, ntsd.exe, ntvdm.exe, nwscript.exe, odbcad32.exe, odbcconf.exe, oobebaln.exe, openfiles.exe, osk.exe, osuninst.exe, packager.exe, pathping.exe, pentnt.exe, perfmon.exe, ping6.exe, print.exe, progman.exe, proquota.exe, proxycfg.exe, qappsrv.exe, qprocess.exe, qwinsta.exe, rasautou.exe, rasdial.exe, rasphone.exe, rcimlby.exe, rcp.exe, rdpclip.exe, rdsaddin.exe, rdshost.exe, recover.exe, relog.exe, replace.exe, reset.exe, rexec.exe, routemon.exe, rsh.exe, rsm.exe, rsmsink.exe, rsmui.exe, rsnotify.exe, rsopprov.exe, rstrui.exe, rsvp.exe, rtcshare.exe, runas.exe, rundll32.exe, runonce.exe, rwinsta.exe, savedump.exe, scardsvr.exe, schtasks.exe, scrcons.exe, scrnsave.scr, sdbinst.exe, secedit.exe, sessmgr.exe, sethc.exe, sfc.exe, shadow.exe, shmgrate.exe, shrpubw.exe, shutdown.exe, sigverif.exe, skeys.exe, smlogsvc.exe, sndrec32.exe, sndvol32.exe, sol.exe, sort.exe, spider.exe, srdiag.exe, ss3dfo.scr, ssbezier.scr, ssflwbox.scr, ssmarque.scr, ssmypics.scr, ssmyst.scr, sspipes.scr, ssstars.scr, sstext3d.scr, stimon.exe, subst.exe, SVCHOST.EXE, syncapp.exe, syskey.exe, sysocmgr.exe, systeminfo.exe, systray.exe, taskkill.exe, tasklist.exe, taskman.exe, taskmgr.exe, tcmsetup.exe, tcpsvcs.exe, telnet.exe, tftp.exe, tlntadmn.exe, tlntsess.exe, tlntsvr.exe, tourstart.exe, tracerpt.exe, tracert6.exe, tracert.exe, tscon.exe, tscupgrd.exe, tsdiscon.exe, tskill.exe, tsshutdn.exe, twunk_32.exe, typeperf.exe, unlodctr.exe, unsecapp.exe, UploadM.exe, upnpcont.exe, ups.exe, userinit.exe, usrmlnka.exe, usrprbda.exe, usrshuta.exe, utilman.exe, verifier.exe, vssadmin.exe, vssvc.exe, w32tm.exe, wbemtest.exe, wextract.exe, wiaacmgr.exe, winhlp32.exe, winmgmt.exe, winmine.exe, winmsd.exe, winver.exe, wmiadap.exe, wmiapsrv.exe, wmic.exe, wmiprvse.exe, wmpstub.exe, wpabaln.exe, wpnpinst.exe, write.exe, wuauclt.exe, wupdmgr.exe, xcopy.exe, 4.tmp, 5.tmp, VRT1.tmp, Install.txt, lsm32.sys, x1c50510.dll, 1.ico, 2.ico, 3.ico, SC.INS, VRT2.tmp, x1c68469.dll  
WinXP Processes CMD.EXE, CSRSS.EXE, DLLHOST.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE, defrag.exe, DfrgFat.exe, lsm32.sys, VRT1.tmp, LSM32.SYS, VRT2.tmp, wmiprvse.exe  
WinXP Registries HKEY_LOCAL_MACHINE@...Microsoft\\DownloadManager, HKEY_USERS@...InternetExplorer\\International, HKEY_CURRENT_USER@...Software\\ProtectionSystem, HKEY_USERS@...Software\\ProtectionSystem  
WinXP Ports 1031, 1034, 1036, 1035, 1038, 1066, 1069, 1045, 1048, 1074, 1039, 1037, 1050, 1052, 1056, 1058, 1049, 1051, 1055  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys  
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 tElock 
Packer ID2  
Embedded DNS  
String Count  
String Link text
String MD5  
Timerange 365 Days 
Unpack Status unknown (FAILED : 4 : Unpacking Timed Out) 
Countries
Unpacked Link  
Callgraph  
API Resolution  
Comment none