Packed MD5 53bfe15e9143d86b276d73fdcaf66265 
Priority 100 
First 05/24/2009 
Last 11/05/2009 
Count  
History  
Unpacked MD5 147309135164dfdd6fdb4b1a16f04dbb  
AV Hits 33 0 
AV Count 32 
CC Servers  
DNS Lookups US:microsoft.com 
Failed Connects  
AV Name AhnLab-V3:MISSED, AntiVir:MISSED, Authentium:MISSED, Avast:MISSED, AVG:MISSED, BitDefender:MISSED, CAT-QuickHeal:MISSED, ClamAV:MISSED, DrWeb:MISSED, eSafe:MISSED, eTrust-Vet:MISSED, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:MISSED, F-Prot:MISSED, F-Secure:MISSED, Ikarus:MISSED, Kaspersky:MISSED, McAfee:MISSED, Microsoft:MISSED, NOD32v2:MISSED, Norman:MISSED, Panda:MISSED, Prevx1:MISSED, Rising:MISSED, Sophos:MISSED, Sunbelt:MISSED, Symantec:MISSED, TheHacker:MISSED, VBA32:MISSED, VirusBuster:MISSED, Webwasher-Gateway:MISSED  
WinXP Files DLLHOST.EXE, SVCHOST.EXE, cmd.ftp  
WinXP Processes CMD.EXE, CSRSS.EXE, DLLHOST.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE, defrag.exe, DfrgFat.exe  
WinXP Registries  
WinXP Ports 1031, 1033, 9996  
Win-2Kf Files  
Win-2Kf Processes DLLHOST.EXE  
Win-2Kf Registries  
Win-2Kf Ports 1027, 1030, 1031  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB823980,SOFTWARE\Microsoft\Updates\Windows XP\SP1\KB823980,SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB823980 
Service Starts RpcPatch 
Service Deletes RpcPatch,RpcTftpd 
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 Armadillo 
Packer ID2  
Embedded DNS  
String Count 90 
String Link text
String MD5 576341f09a798eb21fbc40ffda31b3e7 
Timerange 365 Days 
Unpack Status unknown (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (73.74%, 15.66%)) 
Countries 18 
Unpacked Link  
Callgraph  
API Resolution  
Comment none