Remote Host Port Number
184.73.209.168 80
204.0.5.41 80
204.0.5.58 80
204.0.5.59 80
207.38.101.12 80
208.43.117.134 80
216.178.38.168 80
63.135.80.58 80
63.135.86.25 80
63.135.86.37 80
205.234.236.32 1234 PASS xxx
NICK NEW-[USA|00|P|39592]
USER XP-5696 * 0 :COMPUTERNAME
MODE NEW-[USA|00|P|39592] -ix
JOIN #!nn! test
PONG 22 MOTD
* The data identified by the following URLs was then requested from the remote web server:
o http://adx.bidsystem.com/showAd.aspx?pid=50000021&plid=24013&adsize=728×90&fncback=C1Ve8Uo5Ok4A.b0Gs8Yj5Sn4V&fnlocid=270&fan=1
o http://adx.bidsystem.com/showAd.aspx?pid=50000021&plid=24013&adsize=160×600&fncback=C1Sc1Do0Xh2B.b2Ms1Fg0Aa2E&fnlocid=270&fan=1
o http://c2.ac-images.myspacecdn.com/images02/128/s_d94ed81e66484ec18cd1a6e2a32871c1.jpg
o http://c2.ac-images.myspacecdn.com/images02/120/s_90b768cf6dbf4bd78ce3f42b5c4aca89.jpg
o http://c2.ac-images.myspacecdn.com/images02/113/s_a07c455c49dc449291af8a92c158d509.jpg
o http://c2.ac-images.myspacecdn.com/images02/137/s_2cc5a7e332be492c8a941dcafda9ec51.jpg
o http://c2.ac-images.myspacecdn.com/images02/93/s_fffc11a300bb4791976842c2b5a21811.jpg
o http://c2.ac-images.myspacecdn.com/images02/140/s_525ada0e9f5443cc80d259094b6272c1.jpg
o http://c2.ac-images.myspacecdn.com/images02/144/s_ce770bdb69fd44bd92d173a409bb7369.jpg
o http://c1.ac-images.myspacecdn.com/images02/138/s_49d7ac92025f4fc48e27bd59be9a6840.jpg
o http://c1.ac-images.myspacecdn.com/images02/132/s_adeab60c987c4b7ca81482a623b4a098.jpg
o http://c3.ac-images.myspacecdn.com/images02/150/s_721d594bdba7474cbd966e6d832c51ce.jpg
o http://c3.ac-images.myspacecdn.com/images02/138/s_2d71510e09c94a10b84168941367b8a6.jpg
o http://c1.ac-images.myspacecdn.com/images02/133/s_1e5487f2642546bda5db09bcce9296dc.jpg
o http://c3.ac-images.myspacecdn.com/images02/108/s_d146a0d6b0f24d988b6c44e3ea976702.jpg
o http://c3.ac-images.myspacecdn.com/images02/80/s_bfd03d555ccc4cb7a00ef6392e861ce6.jpg
o http://c1.ac-images.myspacecdn.com/images02/86/s_90c0834b32dd48a6b76c66350cf8dec4.jpg
o http://c1.ac-images.myspacecdn.com/images02/127/s_e4b678c329e743a497242c45104e7b84.jpg
o http://c3.ac-images.myspacecdn.com/images02/102/s_d7012bf748ed4dffa69946d74e8abfaa.jpg
o http://c3.ac-images.myspacecdn.com/images02/124/s_e08399cbdff94e91960887c21bc1575e.jpg
o http://c1.ac-images.myspacecdn.com/images02/141/s_cde8dd44fd8a4eec8b26b4f798e29f4c.jpg
o http://c3.ac-images.myspacecdn.com/images02/64/s_28fb245875434cf28c4a222051676c96.jpg
o http://c1.ac-images.myspacecdn.com/images02/146/s_145f8d6101564c84a2790745c18cd320.jpg
o http://c1.ac-images.myspacecdn.com/images02/140/s_0deb76d29a9146ad871cba36ff05d3e4.jpg
o http://c1.ac-images.myspacecdn.com/images02/53/s_2a7ee1283cd04307827a480e4a5bf8c8.jpg
o http://c1.ac-images.myspacecdn.com/images02/101/s_1853983e0ad340fb9afe177876db60cc.jpg
o http://c1.ac-images.myspacecdn.com/images02/146/s_677aeb8731624a4899d1ff052fd71378.jpg
o http://c1.ac-images.myspacecdn.com/images02/119/s_f717e54f083043e6af833865456c2adc.jpg
o http://c1.ac-images.myspacecdn.com/images02/121/s_b89479a8a77140c99a9c50d55ca2c334.jpg
o http://c4.ac-images.myspacecdn.com/images01/93/s_b469dbb666d5a6ed0476ccac3c2d498b.jpg
o http://c4.ac-images.myspacecdn.com/images02/141/s_096428b63fe849038455f8aae96eacc3.jpg
o http://c4.ac-images.myspacecdn.com/images02/135/s_c1de2e5669d14993a83df0f1360e2d57.jpg
o http://c4.ac-images.myspacecdn.com/images02/137/s_547ecb32fe564f098d5b7f396c1fc0eb.jpg
o http://c4.ac-images.myspacecdn.com/images02/127/s_cbe146a100c44a99a7e469dc2c26a7cb.jpg
o http://c4.ac-images.myspacecdn.com/images02/14/s_52f73df3bee547509ac5a530f5734b9f.jpg
o http://c4.ac-images.myspacecdn.com/images02/148/s_11cf45142ad24fcb8f44651336ea44bf.jpg
o http://c4.ac-images.myspacecdn.com/images02/85/s_5b4bc3732d5c4f7eb73174a6909ac6a3.jpg
o http://c4.ac-images.myspacecdn.com/images02/78/s_53dc893a58544352a17d9813bdeda647.jpg
o http://c4.ac-images.myspacecdn.com/images02/136/s_c8f94d6080474ae492be4c80bbbe5cf3.jpg
o http://c4.ac-images.myspacecdn.com/images02/110/s_47874f41510049a7a3d127ba34be0ab7.jpg
o http://c4.ac-images.myspacecdn.com/images02/143/s_d291614dfb1341f98d627d1c915c5cdf.jpg
o http://geo-lb01.w55c.net/x/brs1009?cbid=C1Sc1Do0Xh2B.b1Tx1Ku0Im2M&cb=1287805865323&size=160×600&ess=MySpaceUGC
o http://browseusers.myspace.com/Browse/Browse.aspx
o http://delb.opt.fimserve.com/adopt/?r=h&l=24000000&pos=leaderboard&rnd=721808059
o http://desk.opt.fimserve.com/adopt/?r=h&l=24000000&pos=skyscraper&rnd=721808059
o http://fim.adnxs.com/fpt?id=3594&size=728×90&flash=1&cookies=1&callback=C1Ve8Uo5Ok4A.b2Ve8Uo5Ok4A&referrer=www.foxaudiencenetwork.com&age=&gender=&cb=1287805865244
o http://js.myspacecdn.com/modules/common/static/js/atlas/richtexteditor_uvm5sqtf.js
o http://js.myspacecdn.com/modules/common/static/js/atlas/msglobal_uabkhbad.js
o http://cms.myspacecdn.com/cms/js/ad_wrapper0159.js
o http://js.myspacecdn.com/modules/browse/static/js/browsebundle_kwg2eboy.js
o http://js.myspacecdn.com/modules/common/static/js/jquery/tracking/tynt_zcvgeagv.js?user=bjNOt4bfyr35kFadbiUt4I&lang=en
o http://js.myspacecdn.com/modules/common/static/js/atlas/quickpost_ujzxjul0.js
o http://x.myspacecdn.com/Modules/Common/Static/img/cornersSheet3.png
o http://x.myspacecdn.com/modules/common/static/css/Sprites/globalNavRefreshSprite.png
o http://x.myspacecdn.com/modules/common/static/css/global_-cca62xx.css
o http://x.myspacecdn.com/Modules/Splash/Static/img/bgSheet.png
o http://x.myspacecdn.com/modules/browse/static/img/btnicons_tiled.gif
o http://x.myspacecdn.com/modules/common/static/css/uploadcontrol_ioe1imsn.css
o http://x.myspacecdn.com/modules/browse/static/css/browse_qiz4yewv.css
o http://x.myspacecdn.com/modules/profilesdirectory/static/css/browsebyname_4vb3esmf.css
o http://x.myspacecdn.com/modules/common/static/img/spacer.gif
o http://x.myspacecdn.com/modules/common/static/img/onlinenow2.gif
o http://x.myspacecdn.com/modules/splash/static/img/moduleBg.gif
o http://www.facebook.com/home.php
o http://www.facebook.com/login.php
o http://www.google-analytics.com/ga.js
o http://googleads.g.doubleclick.net/pagead/test_domain.js
o http://pagead2.googlesyndication.com/pagead/show_ads.js
o http://pagead2.googlesyndication.com/pagead/expansion_embed.js
o http://pagead2.googlesyndication.com/pagead/render_ads.js
o http://ad.doubleclick.net/adi/N6275.126328.SPECIFICMEDIA/B4767814.11;sz=160×600;click=http://ads.specificmedia.com/click/v=5%3Bm=2%3Bl=10840%3Bc=104564%3Bb=620584%3Bp=ui%3Dl4A7BDSizhsPNC%3Btr%3DqvL89fTjz6A%3Btm%3D0-0%3Bts=20101022215113%3Bdct=;ord=20101022215113?
o http://ad.yieldmanager.com/getbid?Z=728×90&s=796250&_salt=1287805865244&r=1&callback=C1Ve8Uo5Ok4A.b1Ey8Iv5Kg4G&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx
o http://ad.yieldmanager.com/getbid?Z=160×600&s=796250&_salt=1287805865323&r=1&callback=C1Sc1Do0Xh2B.b0Fg1Aa0Ej2Q&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx
Other details
* The following ports were open in the system:
Port Protocol Process
1061 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1067 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1095 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
Registry Modifications
* The newly created Registry Values are:
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
Memory Modifications
* There was a new process created in the system:
Process Name Process Filename Main Module Size
nvsvc32.exe %Windir%nvsvc32.exe 3 125 248 bytes
* The following system service was modified:
Service Name Display Name New Status Service Filename
wuauserv Automatic Updates “Stopped” %System%svchost.exe -k netsvcs
File System Modifications
* The following files were created in the system:
# Filename(s) File Size File Hash
1 %Windir%ndl.dl 2 301 bytes MD5: 0xA62A5E9740B73BCB42E74A7DD4FF5A31
SHA-1: 0xF4D757A6C2DC9669B03650D821BC2C5206809665
2 %Windir%nvsvc32.exe
[file and pathname of the sample #1] 56 320 bytes MD5: 0xD91ADFDE68F0B0B935EB43D057A91AAD
SHA-1: 0x5C922BAD4EE7354C884C47A3EC033D81095D080F
3 %Windir%wibrf.jpg 3 968 bytes MD5: 0xE246233F7DCFE923D7A54F29B63CC30E
SHA-1: 0xB512DA23F7D01E8BD23133583103A83DC6D5C787
4 %Windir%wiybr.png 3 416 bytes MD5: 0xD3A3A9391EA080EDFEF8BA202CC36D2E
SHA-1: 0xD771C5BA93DC6FC0438AF3FF1E909338F63EC283