Remote Host Port Number
184.73.209.168 80
204.0.5.41 80
204.0.5.42 80
204.0.5.48 80
204.0.5.56 80
216.178.38.103 80
216.178.38.168 80
63.135.86.21 80
64.208.138.220 80
64.208.241.27 80
75.102.21.13 1234 PASS xxx
MODE NEW-[USA|00|P|67055] -ix
JOIN #!nn! test
PONG 22 MOTD
NICK NEW-[USA|00|P|67055]
USER XP-7278 * 0 :COMPUTERNAME
* The data identified by the following URLs was then requested from the remote web server:
o http://adx.bidsystem.com/showAd.aspx?pid=50000021&plid=24013&adsize=160×600&fncback=C1Mk0Bi8Ej7V.b1Mk0Bi8Ej7V&fnlocid=270&fan=1
o http://c2.ac-images.myspacecdn.com/images02/148/s_da284a441c5f4464b1d6fcf740709065.jpg
o http://c2.ac-images.myspacecdn.com/images02/126/s_4d7ed2676ac74675a5552f7b24732f69.jpg
o http://c2.ac-images.myspacecdn.com/images02/93/s_2cea4d23bd8d4e08b405e9afb8427cc9.jpg
o http://c2.ac-images.myspacecdn.com/images02/137/s_2032c06594304ebabb3577bc7314148d.jpg
o http://c2.ac-images.myspacecdn.com/images02/122/s_ecb2945068064858b04a94815ed95475.jpg
o http://c2.ac-images.myspacecdn.com/images02/128/s_36b81e97299349e5a66f930e4bf2fc65.jpg
o http://c2.ac-images.myspacecdn.com/images02/66/s_f3d83cef7b3346348d256a5b85670921.jpg
o http://c2.ac-images.myspacecdn.com/images02/68/s_084eede539534198ba70f8b8bc05d24d.jpg
o http://c3.ac-images.myspacecdn.com/images02/137/s_f6c1b6242f9c43f79b34a08185316e16.jpg
o http://c3.ac-images.myspacecdn.com/images02/117/s_f8e90b9760db451e8c2b7dff2f7c86f6.jpg
o http://c3.ac-images.myspacecdn.com/images02/1/s_99f702b8f7cd423c912e514566458d86.jpg
o http://c3.ac-images.myspacecdn.com/images02/17/s_4b5ad8d3d49a473e90096944ae3cd16a.jpg
o http://c3.ac-images.myspacecdn.com/images02/148/s_db64d84668ad463ab8e9af3d43b4e36e.jpg
o http://c3.ac-images.myspacecdn.com/images02/102/s_3557d11428fd4e5ebe841b1db06c6ef2.jpg
o http://c3.ac-images.myspacecdn.com/images02/134/s_9b03a7dcc7e047d8ad75e982e845695e.jpg
o http://c3.ac-images.myspacecdn.com/images02/91/s_c634b937e90447be91dc8476e01a36c2.jpg
o http://c3.ac-images.myspacecdn.com/images02/123/s_93435fb3662d426c8a77890814e5998e.jpg
o http://c3.ac-images.myspacecdn.com/images02/119/s_4628f375419745809aaead7a1f477246.jpg
o http://c3.ac-images.myspacecdn.com/images02/124/s_3a67e9b7c1da4bf59c44187c0e819c3e.jpg
o http://c3.ac-images.myspacecdn.com/images02/149/s_70b5d2b92a524cec87e841d4f3c36d42.jpg
o http://c3.ac-images.myspacecdn.com/images02/98/s_b8803c78848d4e42a13862229b9f08ba.jpg
o http://c1.ac-images.myspacecdn.com/images02/111/s_4b89da9636614a7398ccdceb4ad95ef8.jpg
o http://c1.ac-images.myspacecdn.com/images02/116/s_7b56ba1252f944a39447d8ce385b1884.jpg
o http://c1.ac-images.myspacecdn.com/images02/129/s_51357b95257b44cb83e1a151ac53a2b4.jpg
o http://c1.ac-images.myspacecdn.com/images02/87/s_2f78d5eb03824aaf99c87a9cf28bec14.jpg
o http://c1.ac-images.myspacecdn.com/images02/118/s_d1f89f4606754bb6b82b4eaef89e3660.jpg
o http://c1.ac-images.myspacecdn.com/images02/146/s_ea9417e01c054f598b405fc4c38a6320.jpg
o http://c1.ac-images.myspacecdn.com/images02/57/s_0b554479fbc44c1d825edb012a7f5f68.jpg
o http://c4.ac-images.myspacecdn.com/images02/152/s_73f7909d7c924dd39641a4406b6f9443.jpg
o http://c4.ac-images.myspacecdn.com/images02/150/s_b9e8a59eee9e454f84f2d4036ddccca3.jpg
o http://c4.ac-images.myspacecdn.com/images02/52/s_ba061a6813d64d88b741286df457d56f.jpg
o http://c4.ac-images.myspacecdn.com/images02/141/s_ae4394b4c7904abf826bcdc645d37653.jpg
o http://c4.ac-images.myspacecdn.com/images02/144/s_af3d4004828149438ad2fe0cd3bbb307.jpg
o http://c4.ac-images.myspacecdn.com/images02/4/s_c0ab04fcce264ad9ac2bcd1a8749cd17.jpg
o http://c4.ac-images.myspacecdn.com/images02/74/s_ad5a52edd7e34e8c94bcf1042c1a6607.jpg
o http://c4.ac-images.myspacecdn.com/images02/126/s_31c95fca23ea4393819935591e4d1cff.jpg
o http://c4.ac-images.myspacecdn.com/images02/135/s_b7eee2e0c8be41929595f58395e47893.jpg
o http://c4.ac-images.myspacecdn.com/images02/103/s_dac79a3ce603463686fe4a3c5bda2a63.jpg
o http://c4.ac-images.myspacecdn.com/images02/120/s_c17f19513c2147d99012cbdfdbbbd1eb.jpg
o http://c4.ac-images.myspacecdn.com/images01/76/s_a11b1f8331eea8eec79b43e9497ea35f.jpg
o http://browseusers.myspace.com/Browse/Browse.aspx
o http://desk.opt.fimserve.com/adopt/?r=h&l=24000000&pos=skyscraper&rnd=021902594
o http://delb.opt.fimserve.com/adopt/?r=h&l=24000000&pos=leaderboard&rnd=021902594
o http://fim.adnxs.com/fpt?id=3594&size=160×600&flash=1&cookies=1&callback=C1Mk0Bi8Ej7V.b2Xm0Fc8Pv7L&referrer=www.foxaudiencenetwork.com&age=&gender=&cb=1288927496893
o http://x.myspacecdn.com/modules/splash/static/img/bgSheet.png
o http://x.myspacecdn.com/modules/splash/static/img/moduleBg.gif
o http://x.myspacecdn.com/Modules/Common/Static/img/cornersSheet3.png
o http://x.myspacecdn.com/modules/common/static/css/Sprites/globalNavRefreshSprite.png
o http://x.myspacecdn.com/modules/browse/static/img/btnicons_tiled.gif
o http://cms.myspacecdn.com/cms/js/ad_wrapper0159.js
o http://x.myspacecdn.com/modules/common/static/css/global_-cca62xx.css
o http://x.myspacecdn.com/modules/browse/static/css/browse_qiz4yewv.css
o http://x.myspacecdn.com/modules/profilesdirectory/static/css/browsebyname_4vb3esmf.css
o http://x.myspacecdn.com/modules/common/static/img/spacer.gif
o http://x.myspacecdn.com/modules/common/static/img/onlinenow2.gif
o http://js.myspacecdn.com/modules/common/static/js/atlas/richtexteditor_uvm5sqtf.js
o http://js.myspacecdn.com/modules/common/static/js/atlas/msglobal_uabkhbad.js
o http://js.myspacecdn.com/modules/browse/static/js/browsebundle_kwg2eboy.js
o http://js.myspacecdn.com/modules/common/static/js/jquery/tracking/tynt_zcvgeagv.js?user=bjNOt4bfyr35kFadbiUt4I&lang=en
o http://js.myspacecdn.com/modules/common/static/js/atlas/quickpost_ujzxjul0.js
o http://bid.ace.advertising.com/bid/ebs=1/site=744646/size=728090/tags=1/callback=C1Ce5Sz7Vp3U.b1Fn5Hg7Rv3C/bnum=1288927497065
o http://bid.ace.advertising.com/ctst=1/bid/ebs=1/site=744646/size=728090/tags=1/callback=C1Ce5Sz7Vp3U.b1Fn5Hg7Rv3C/bnum=1288927497065
o http://www.facebook.com/home.php
o http://www.facebook.com/login.php
o http://p.ic.tynt.com/b/p?id=bjNOt4bfyr35kFadbiUt4I&ts=1288927497830&t=Browse%20MySpace%20Friends%20and%20Profiles
o http://ad.turn.com/server/bid/fan.bid?pub=10063193&cch=10063206&l=728×90&requestId=C1Ce5Sz7Vp3U.b0Ry5Ce7Sz3V&ref=http%3A%2F%2Fmyspace-ugc-foxaudiencenetwork.com&rand=1288927497065
o http://ad.turn.com/server/bid/fan.bid?pub=10063193&cch=10063206&l=160×600&requestId=C1Mk0Bi8Ej7V.b0Jg0Of8Hp7R&ref=http%3A%2F%2Fmyspace-ugc-foxaudiencenetwork.com&rand=1288927496893
o http://www.google-analytics.com/ga.js
o http://googleads.g.doubleclick.net/pagead/test_domain.js
o http://googleads.g.doubleclick.net/pagead/imgad?id=COaz6pqtlsOtmwEQoAEYwgQyCPvh_ZWH_GQf
o http://pagead2.googlesyndication.com/pagead/show_ads.js
o http://pagead2.googlesyndication.com/pagead/expansion_embed.js
o http://pagead2.googlesyndication.com/pagead/render_ads.js
o http://ad.yieldmanager.com/getbid?Z=728×90&s=796240&_salt=1288927497065&r=1&callback=C1Ce5Sz7Vp3U.b2Fk5Ho7Ry3C&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx
Other details
* The following ports were open in the system:
Port Protocol Process
1054 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1058 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1098 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
Registry Modifications
* The newly created Registry Values are:
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
Memory Modifications
* There was a new process created in the system:
Process Name Process Filename Main Module Size
nvsvc32.exe %Windir%nvsvc32.exe 3 125 248 bytes
* The following system service was modified:
Service Name Display Name New Status Service Filename
wuauserv Automatic Updates “Stopped” %System%svchost.exe -k netsvcs
File System Modifications
* The following files were created in the system:
# Filename(s) File Size File Hash
1 %Windir%ndl.dl 2 293 bytes MD5: 0xF80E4F20D63E212B92CE115BC268F185
SHA-1: 0x1D33F09F2298DD3B72A44BA1F11C5880F0CA471A
2 %Windir%nvsvc32.exe
[file and pathname of the sample #1] 90 112 bytes MD5: 0x47DC9B72EC28005FC52C450235ED15C5
SHA-1: 0xA79FEDD202F276AA940D527562643F504445818E
3 %Windir%wibrf.jpg 3 968 bytes MD5: 0xE246233F7DCFE923D7A54F29B63CC30E
SHA-1: 0xB512DA23F7D01E8BD23133583103A83DC6D5C787
4 %Windir%wiybr.png 3 416 bytes MD5: 0xD3A3A9391EA080EDFEF8BA202CC36D2E
SHA-1: 0xD771C5BA93DC6FC0438AF3FF1E909338F63EC283
infos about hoster :
http://whois.domaintools.com/75.102.21.13