Remote Host Port Number
184.73.209.168 80
204.0.5.41 80
204.0.5.48 80
204.0.5.49 80
204.0.5.51 80
204.0.5.57 80
204.0.5.58 80
204.0.5.59 80
216.178.38.103 80
216.178.38.168 80
205.234.236.19 1234 PASS xxx
NICK NEW-[USA|00|P|36443]
USER XP-9032 * 0 :COMPUTERNAME
MODE NEW-[USA|00|P|36443] -ix
JOIN #!nn! test
PONG 22 MOTD
* The data identified by the following URLs was then requested from the remote web server:
o http://adx.bidsystem.com/showAd.aspx?pid=50000021&plid=24013&adsize=160×600&fncback=C1Wv0Gq6Pb1T.b2Vb0La6Uz1Z&fnlocid=270&fan=1
o http://adx.bidsystem.com/showAd.aspx?pid=50000021&plid=24013&adsize=728×90&fncback=C1Qp9Gd0Cx2V.b2Vr9Uk0Mw2P&fnlocid=270&fan=1
o http://js.myspacecdn.com/modules/common/static/js/atlas/richtexteditor_uvm5sqtf.js
o http://js.myspacecdn.com/modules/common/static/js/atlas/msglobal_uabkhbad.js
o http://js.myspacecdn.com/modules/browse/static/js/browsebundle_kwg2eboy.js
o http://c2.ac-images.myspacecdn.com/images02/121/s_4b8e1645961f422dbf7e110ab66975f1.jpg
o http://c2.ac-images.myspacecdn.com/images02/137/s_68f6c19403da452fa0c43f37e0490eb1.jpg
o http://c2.ac-images.myspacecdn.com/images02/70/s_a5465f10ca9347eb9c962da4735ca2fd.jpg
o http://c2.ac-images.myspacecdn.com/images02/127/s_b3ebe93fc9334a4994ad7330737ce2c1.jpg
o http://c2.ac-images.myspacecdn.com/images02/78/s_c948f2dcb5a94c179aa9f60d6ffb7fb9.jpg
o http://c2.ac-images.myspacecdn.com/images02/97/s_177b72d1c6874da99c69517b32322789.jpg
o http://c2.ac-images.myspacecdn.com/images02/71/s_f6fa8393e7424a9bbfcf5bb93e8fdab5.jpg
o http://c2.ac-images.myspacecdn.com/images02/116/s_006fccad5c1649d59296ff4d786782a9.jpg
o http://c2.ac-images.myspacecdn.com/images02/147/s_23f705ece5224a68811dc2a268569ba9.gif
o http://js.myspacecdn.com/modules/common/static/js/jquery/tracking/tynt_zcvgeagv.js?user=bjNOt4bfyr35kFadbiUt4I&lang=en
o http://js.myspacecdn.com/modules/common/static/js/atlas/quickpost_ujzxjul0.js
o http://cms.myspacecdn.com/cms/js/ad_wrapper0159.js
o http://c1.ac-images.myspacecdn.com/images02/119/s_c1fccaadfafd4cd4927c4890030d6f40.png
o http://c1.ac-images.myspacecdn.com/images02/93/s_4cc1738f656142cb85e7d587380288f0.jpg
o http://c1.ac-images.myspacecdn.com/images02/151/s_c252d9e759ab4ecd86f7be93d4406570.jpg
o http://c1.ac-images.myspacecdn.com/images02/143/s_75b1d6f15c7a401bbbff7a1d8541efec.jpg
o http://c1.ac-images.myspacecdn.com/images02/127/s_04d2362bbf8f4f6da2f5d4d6b412a8cc.jpg
o http://c1.ac-images.myspacecdn.com/images02/103/s_11910f73a572484a88d7c463616eea58.jpg
o http://c1.ac-images.myspacecdn.com/images02/129/s_f1f1fb736388429d9e62adad068236ac.jpg
o http://c1.ac-images.myspacecdn.com/images02/134/s_01c7cd812059482bb5f19946c0accaac.jpg
o http://servedby.adxpose.com/adxpose/find_ad.js
o http://x.myspacecdn.com/Modules/Common/Static/img/cornersSheet3.png
o http://x.myspacecdn.com/modules/common/static/css/Sprites/globalNavRefreshSprite.png
o http://x.myspacecdn.com/modules/common/static/css/global_-cca62xx.css
o http://x.myspacecdn.com/Modules/Splash/Static/img/bgSheet.png
o http://x.myspacecdn.com/modules/browse/static/img/btnicons_tiled.gif
o http://x.myspacecdn.com/modules/common/static/css/uploadcontrol_ioe1imsn.css
o http://x.myspacecdn.com/modules/browse/static/css/browse_qiz4yewv.css
o http://x.myspacecdn.com/modules/profilesdirectory/static/css/browsebyname_4vb3esmf.css
o http://x.myspacecdn.com/modules/common/static/img/spacer.gif
o http://x.myspacecdn.com/modules/common/static/img/onlinenow2.gif
o http://x.myspacecdn.com/modules/splash/static/img/moduleBg.gif
o http://1.download.advertise.myspace.com/03/1e/61/621e611b2da654cdb2aa3d2d268a084f_final.jpg
o http://c3.ac-images.myspacecdn.com/images02/28/s_3511bd1d62ea47d193c77a74db278f9a.jpg
o http://c3.ac-images.myspacecdn.com/images02/143/s_6cf79516e1a84248a5e1f29c6ad790a2.jpg
o http://c3.ac-images.myspacecdn.com/images02/150/s_69e83c603cb0490a9eba2bdc345ed3fa.jpg
o http://c3.ac-images.myspacecdn.com/images02/103/s_f7132ae53408455e823861c858470eca.jpg
o http://c3.ac-images.myspacecdn.com/images02/126/s_67d10e42264b4ae7a5da1b97da27cb2a.jpg
o http://c3.ac-images.myspacecdn.com/images02/91/s_b78be6bcc5d24b2685f55921de10fdca.jpg
o http://c3.ac-images.myspacecdn.com/images02/152/s_75b8f8a5557e400d8b5f0d7a7c5e4a2e.jpg
o http://c3.ac-images.myspacecdn.com/images01/25/s_bb8acbf3405de6799ccec8364155d9ea.jpg
o http://c3.ac-images.myspacecdn.com/images02/114/s_34d8092513714426a0ce6fac52b6252e.jpg
o http://c3.ac-images.myspacecdn.com/images02/105/s_1f7e4603bd624878ac6f4e1c3754b38e.jpg
o http://c3.ac-images.myspacecdn.com/images02/116/s_b044414cc90e454e9bad4c07b313c7ce.jpg
o http://c3.ac-images.myspacecdn.com/images02/127/s_3fd8fad79bc444ff8e45bb49acfcd43e.jpg
o http://c3.ac-images.myspacecdn.com/images02/27/s_b95a8bcaabd74273af6406d9bd47b3a2.jpg
o http://c4.ac-images.myspacecdn.com/images02/104/s_f6a66eae523346feb6ff66142478ae9b.jpg
o http://c4.ac-images.myspacecdn.com/images02/132/s_cd31974f29c6426ca93ba6bf4f152c1f.jpg
o http://c4.ac-images.myspacecdn.com/images02/100/s_717cef28effc4d5eb5c15694f30e8e13.jpg
o http://c4.ac-images.myspacecdn.com/images02/7/s_aa17975f7b72406b950c1937718188b7.jpg
o http://c4.ac-images.myspacecdn.com/images02/147/s_f85351c7db0646acb0b737306112dd1b.jpg
o http://c4.ac-images.myspacecdn.com/images02/91/s_333c76d9f2f34820818b7daf566f870b.jpg
o http://c4.ac-images.myspacecdn.com/images02/79/s_1f0957785e994ece9a3c89c0dd83e1b3.jpg
o http://c4.ac-images.myspacecdn.com/images02/143/s_29293741a4a7413d968cde4bc1a0c79b.jpg
o http://c4.ac-images.myspacecdn.com/images02/151/s_88b631b4566145ee9e41afd62f3df8c3.jpg
o http://c4.ac-images.myspacecdn.com/images02/70/s_5c0dcadbe1ec47aba5e984da1a8a1993.jpg
o http://browseusers.myspace.com/Browse/Browse.aspx
o http://delb.opt.fimserve.com/adopt/?r=h&l=24000000&pos=leaderboard&rnd=496325758
o http://desk.opt.fimserve.com/adopt/?r=h&l=24000000&pos=skyscraper&rnd=496325758
o http://media.fastclick.net/w/get.media?sid=54674&tp=5&d=j&t=n
o http://media.fastclick.net/w/get.media?sid=54674&tp=5&d=j&t=n&no_cj_c=1&upsid=042638895028
o http://rd.apmebf.com/w/get.media?sid=54674&tp=5&d=j&t=n&host=media.fastclick.net
o http://fim.adnxs.com/fpt?id=3594&size=728×90&flash=1&cookies=1&callback=C1Qp9Gd0Cx2V.b0Mw9Pq0Sn2O&referrer=www.foxaudiencenetwork.com&age=&gender=&cb=1286506458975
o http://fim.adnxs.com/fpt?id=3594&size=160×600&flash=1&cookies=1&callback=C1Wv0Gq6Pb1T.b0Py0Tf6Do1K&referrer=www.foxaudiencenetwork.com&age=&gender=&cb=1286506459085
o http://p.ic.tynt.com/b/p?id=bjNOt4bfyr35kFadbiUt4I&ts=1286506459632&t=Browse%20MySpace%20Friends%20and%20Profiles
o http://www.google-analytics.com/ga.js
o http://googleads.g.doubleclick.net/pagead/test_domain.js
o http://pagead2.googlesyndication.com/pagead/show_ads.js
o http://pagead2.googlesyndication.com/pagead/expansion_embed.js
o http://pagead2.googlesyndication.com/pagead/render_ads.js
o http://ad.yieldmanager.com/getbid?Z=728×90&s=796240&_salt=1286506458975&r=1&callback=C1Qp9Gd0Cx2V.b1Vr9Uk0Mw2P&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx
o http://ad.yieldmanager.com/getbid?Z=160×600&s=796240&_salt=1286506459085&r=1&callback=C1Wv0Gq6Pb1T.b1Kk0Ou6Sg1V&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx
Other details
* The following ports were open in the system:
Port Protocol Process
1059 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1098 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
Registry Modifications
* The newly created Registry Values are:
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
Memory Modifications
* There was a new process created in the system:
Process Name Process Filename Main Module Size
nvsvc32.exe %Windir%nvsvc32.exe 3 129 344 bytes
* The following system service was modified:
Service Name Display Name New Status Service Filename
wuauserv Automatic Updates “Stopped” %System%svchost.exe -k netsvcs
File System Modifications
* The following files were created in the system:
# Filename(s) File Size File Hash
1 %Windir%mdlu.dl 2 301 bytes MD5: 0xC7E002DE8C6E8FC32C6A1FD9705C4429
SHA-1: 0xC71BCC53704BE739F892EEA40FDB1082269BAB2F
2 %Windir%nvsvc32.exe
[file and pathname of the sample #1] 59 392 bytes MD5: 0x62E33BDE137BC9D3F9A22959765AB99D
SHA-1: 0xB90896A97D9E93C77EEA272623C47468E97C680D
3 %Windir%wintybrd.png 3 416 bytes MD5: 0xD3A3A9391EA080EDFEF8BA202CC36D2E
SHA-1: 0xD771C5BA93DC6FC0438AF3FF1E909338F63EC283
4 %Windir%wintybrdf.jpg 3 968 bytes MD5: 0xE246233F7DCFE923D7A54F29B63CC30E
SHA-1: 0xB512DA23F7D01E8BD23133583103A83DC6D5C787