Packed MD5 405ce10c9bd206185ddb798f09d9b74a 
Priority
First 10/17/2009 
Last 10/20/2009 
Count  
History  
Unpacked MD5 9f1a7125b9203e306794e4ed104d8b6d  
AV Hits 18 15 12 26 
AV Count 32 
CC Servers 218.93.205.30:65520 91.212.220.75:65520 
DNS Lookups US:dreamergroup.info US:search.biduplinks.co.uk CN:proxim.ircgalaxy.pl EU:gidromash.cn CN:dl.guarddog2009.com :nenastiya.cn CN:config1007.iwillhavesexygirls.com :wws.mobiec.net CN:maillist.iwillhavesexygirls.com US:xz.ub9.net CN:russia.2288.org CN:js.users.51.la CN:icon.ajiang.net CN:web2.51.la :in.7cy.net US:microsoft.com CN:web.51.la :in1.7cy.net :www.schooldesires.com :www.loanablecapital.com US:media.fastclick.net US:rd.apmebf.com :cncheck.com EU:sleepatnight.cn 
Failed Connects EU:91.206.201.39:80 74.220.220.81:80 CN:218.10.18.30:88 CN:218.10.18.30:888 CN:218.93.205.30:65520 
AV Name AhnLab-V3:Win-Xema.variant, AntiVir:TRDrop.Puzlice.A, Authentium:MISSED, Avast:_VB-LYG, AVG:Clicker.ACJF, BitDefender:Generic.2527032, CAT-QuickHeal:MISSED, ClamAV:MISSED, DrWeb:MulDrop.34065, eSafe:TrojanDropperP, eTrust-Vet:MISSED, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:PossibleThreat, F-Prot:MISSED, F-Secure:Generic.2527032, Ikarus:Trojan-Spy.VB, Kaspersky:Trojan-Dropper.VB.afbw, McAfee:MISSED, Microsoft:TrojanDropper_Puzlice.A, NOD32v2:MISSED, Norman:Smalltroj.SXCH, Panda:TrjCI.A, Prevx1:MISSED, Rising:MISSED, Sophos:TrojVB-EJN, Sunbelt:MISSED, Symantec:Downloader, TheHacker:MISSED, VBA32:MISSED, VirusBuster:MISSED, Webwasher-Gateway:MISSED  
WinXP Files  
WinXP Processes  
WinXP Registries  
WinXP Ports  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys  
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 StarForce 
Packer ID2  
Embedded DNS  
String Count  
String Link text
String MD5  
Timerange 365 Days 
Unpack Status unknown ( : 0 : Unpacking Provided Binary. (Code,Data) = (, )) 
Countries
Unpacked Link  
Callgraph  
API Resolution  
Comment none