| MD5 | 597139773c381b120974f98790421560 |
| SHA1 | 35c6484e9bced6db72d27a13d746f6467ec2b403 |
| Domains | [fd-fp3.wg1.b.yahoo.com] [www.yahoo.com] [bacarduk.ru] [poland-kemp.ru] [magicaring.ru] |
| IP Addresses | [98.139.183.24] [98.138.252.30] [98.138.253.109] [98.139.180.149] |
| Antivirus | [Malware-gen*Win32*Malware-gen] |
| [PWS*Win32/Zbot.CF] | |
| [TR/AD.Rovnix.Y.40] | |
| [Trojan-Spy.Win32.Zbot.vyne] | |
| [Trojan.DownLoader16.25594] | |
| [Trojan.FakeMS] | |
| [Trojan.Girtk.DTXA.genf] | |
| [Trojan.Zbot.Win32.187447] | |
| [TSPY_ZCLICK.SMA] | |
| [W32/Kryptik.DTXA!tr] |