He probably used that bypass...it gets executed similar to GGK(Start ggk, start maple)
Antivirus Version Last Update Result
AhnLab-V3 2008.5.28.0 2008.05.27 -
AntiVir 7.8.0.19 2008.05.27 TR/Crypt.TPM.Gen
Authentium 5.1.0.4 2008.05.27 -
Avast 4.8.1195.0 2008.05.27 -
AVG 7.5.0.516 2008.05.27 -
BitDefender 7.2 2008.05.28 -
CAT-QuickHeal 9.50 2008.05.26 -
ClamAV 0.92.1 2008.05.27 PUA.Packed.Themida
DrWeb 4.44.0.09170 2008.05.27 -
eSafe 7.0.15.0 2008.05.27 -
eTrust-Vet 31.4.5826 2008.05.27 -
Ewido 4.0 2008.05.27 -
F-Prot 4.4.4.56 2008.05.27 -
F-Secure 6.70.13260.0 2008.05.27 -
Fortinet 3.14.0.0 2008.05.27 -
GData 2.0.7306.1023 2008.05.27 -
Ikarus T3.1.1.26.0 2008.05.27 Generic.Sdbot
Kaspersky 7.0.0.125 2008.05.27 -
McAfee 5304 2008.05.27 -
Microsoft None 2008.05.27 -
NOD32v2 3136 2008.05.27 -
Norman 5.80.02 2008.05.27 -
Panda 9.0.0.4 2008.05.27 -
Prevx1 V2 2008.05.28 -
Rising 20.46.12.00 2008.05.27 -
Sophos 4.29.0 2008.05.27 Mal/Basine-C
Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.27 -
TheHacker 6.2.92.321 2008.05.27 -
VBA32 3.12.6.6 2008.05.27 -
VirusBuster 4.3.26:9 2008.05.27 Packed/Themida
Webwasher-Gateway 6.6.2 2008.05.28 Trojan.Crypt.TPM.Gen
Just the usual false positives...but w/e, use at you own risk...runs kernel mode functions that I want to keep private so I packed it with Themida.
Cheers.