Remote Host Port Number
204.0.5.41 80
204.0.5.42 80
204.0.5.48 80
204.0.5.56 80
207.38.101.10 80
207.38.101.12 80
216.178.38.103 80
216.178.38.168 80
63.135.86.21 80
63.135.86.25 80
205.234.231.194 1234 PASS xxx
NICK NEW-[USA|00|P|36443]
USER XP-9032 * 0 :COMPUTERNAME
MODE NEW-[USA|00|P|36443] -ix
JOIN #!nn! test
PONG 22 MOTD
* The data identified by the following URLs was then requested from the remote web server:
o http://c2.ac-images.myspacecdn.com/images02/125/s_fa05cfbba32d4fc0b4b41ee55ecd665d.jpg
o http://c2.ac-images.myspacecdn.com/images02/145/s_b790f41222d647ae8acc6ca83c80bae1.jpg
o http://c2.ac-images.myspacecdn.com/images02/57/s_9f53e4362ea240eabb66b2619af251f9.jpg
o http://c2.ac-images.myspacecdn.com/images02/40/s_877ccd579bce407ab09aa2d5540e79c5.jpg
o http://c2.ac-images.myspacecdn.com/images02/87/s_32646346318f4322b904f5acabd644b9.jpg
o http://c2.ac-images.myspacecdn.com/images02/134/s_e91cb5a4b947401196e32f68ffe07631.jpg
o http://c2.ac-images.myspacecdn.com/images02/118/s_ee7f72939bf34fc3a2f03588d45a2111.jpg
o http://c2.ac-images.myspacecdn.com/images02/29/s_9fd24fb09969414b94fb749451fe98b9.jpg
o http://c3.ac-images.myspacecdn.com/images02/90/s_cdc1a52d0dd840ff87b9e99bbd997c06.jpg
o http://c3.ac-images.myspacecdn.com/images02/85/s_136539da5a0945dd9543a0dd34854d32.jpg
o http://c3.ac-images.myspacecdn.com/images02/114/s_075d4a853d814b7588c757ae75dba312.png
o http://c3.ac-images.myspacecdn.com/images02/116/s_ccbe84c9de444c21bea4d333386cc982.jpg
o http://c3.ac-images.myspacecdn.com/images02/50/s_a2f28105b7e9448a9e500dabae89d3fe.jpg
o http://c3.ac-images.myspacecdn.com/images02/138/s_3e45bae477ad40eab3d5e8fcb2ba8a42.jpg
o http://c3.ac-images.myspacecdn.com/images02/43/s_ffe82bb03233439b80267ddfa45a71a6.jpg
o http://c3.ac-images.myspacecdn.com/images02/148/s_4173993d40d94b9aa5e03219e69b1dce.jpg
o http://c3.ac-images.myspacecdn.com/images02/111/s_f3dafba016a14ac5839e0e6d8cd26c7a.jpg
o http://c3.ac-images.myspacecdn.com/images02/89/s_d4e00fefa0aa48018e8787ad51a4d2fe.jpg
o http://c3.ac-images.myspacecdn.com/images02/150/s_7495957a5912497e8a33438904ad9502.jpg
o http://c3.ac-images.myspacecdn.com/images02/118/s_97d240e0a3234eb596bdc80c28b9f2e2.jpg
o http://c3.ac-images.myspacecdn.com/images02/125/s_9c34d5b186aa4ac18421e93065199f2e.jpg
o http://c1.ac-images.myspacecdn.com/images02/136/s_c18d7d79eff148ca85159593df78dd74.jpg
o http://c1.ac-images.myspacecdn.com/images02/93/s_fcfe43c63f9d4fb3b21eafe40b147ef4.jpg
o http://c1.ac-images.myspacecdn.com/images02/151/s_19ca480aeb9040c8a3d74336f1a80b28.jpg
o http://c1.ac-images.myspacecdn.com/images02/116/s_ea48c5bae6e64ebd887b8e2b5fd4a4f4.jpg
o http://c1.ac-images.myspacecdn.com/images02/120/s_4ed1757df90446719922d6ab95966344.jpg
o http://c1.ac-images.myspacecdn.com/images02/122/s_526d96dc19f349f2af03a2a3b74436b0.jpg
o http://c1.ac-images.myspacecdn.com/images02/134/s_c5410bab6a0644d08ec5e8463d0f1284.jpg
o http://c1.ac-images.myspacecdn.com/images02/149/s_261493aaf8dc401e98c952dfe17869b8.jpg
o http://c1.ac-images.myspacecdn.com/images01/48/s_3daee062c1b4e0af97319b70a35e75ac.jpg
o http://c4.ac-images.myspacecdn.com/images02/144/s_65af1d2e6ef84127a3174eda935c8347.jpg
o http://c4.ac-images.myspacecdn.com/images02/78/s_8e2afa6ffa124a609de07bc6a8bf7d4f.jpg
o http://c4.ac-images.myspacecdn.com/images02/115/s_699f32e563bf47999f117ab069095347.jpg
o http://c4.ac-images.myspacecdn.com/images02/147/s_eb76ec96571f4bbb8142a071e4ebc5ff.jpg
o http://c4.ac-images.myspacecdn.com/images02/84/s_7067417154a649968a80d9a01156733f.jpg
o http://c4.ac-images.myspacecdn.com/images02/103/s_b499e33cbe894a5a91156e09e503d7a7.jpg
o http://c4.ac-images.myspacecdn.com/images02/150/s_f6fc3961729847dca3c70d7e8f3972df.jpg
o http://c4.ac-images.myspacecdn.com/images02/136/s_36e58108ae96431a9e02834ed7e655a7.jpg
o http://c4.ac-images.myspacecdn.com/images01/70/s_41a17df2af2fab6aeeec67a0284b1ea7.jpg
o http://c4.ac-images.myspacecdn.com/images02/82/s_f06a4bf692e7434fbe4bb3e1c3e207bb.jpg
o http://ads.specificmedia.com/serve/v=5;m=2;l=10838;cxt=811200901:1966222;kw=;ts=985099;smuid=4TWzGDgOMLed2C;p=ui%3D4TWzGDgOMLed2C%3Btr%3D2xCfO0-_EXE%3Btm%3D0-0
o http://browseusers.myspace.com/Browse/Browse.aspx
o http://delb.opt.fimserve.com/adopt/?r=h&l=24000000&pos=leaderboard&rnd=580391442
o http://desk.opt.fimserve.com/adopt/?r=h&l=24000000&pos=skyscraper&rnd=580391442
o http://fim.adnxs.com/fpt?id=3594&size=728×90&flash=1&cookies=1&callback=C1Oh4Km2Df6V.b2Be4Hs2Cz6A&referrer=www.foxaudiencenetwork.com&age=&gender=&cb=1285590149484
o http://fim.adnxs.com/fpt?id=3594&size=160×600&flash=1&cookies=1&callback=C1If6Zm8Hd5V.b1Ja6Ue8Ak5S&referrer=www.foxaudiencenetwork.com&age=&gender=&cb=1285590149593
o http://js.myspacecdn.com/modules/common/static/js/atlas/msglobal_anyw2j9a.js
o http://cms.myspacecdn.com/cms/js/ad_wrapper0158.js
o http://js.myspacecdn.com/modules/browse/static/js/browsebundle_kwg2eboy.js
o http://js.myspacecdn.com/modules/common/static/js/jquery/tracking/tynt_zcvgeagv.js?user=bjNOt4bfyr35kFadbiUt4I&lang=en
o http://js.myspacecdn.com/modules/common/static/js/atlas/quickpost_ujzxjul0.js
o http://js.myspacecdn.com/modules/common/static/js/atlas/richtexteditor_uvm5sqtf.js
o http://x.myspacecdn.com/Modules/Common/Static/img/cornersSheet3.png
o http://x.myspacecdn.com/modules/common/static/css/Sprites/globalNavRefreshSprite.png
o http://x.myspacecdn.com/Modules/Splash/Static/img/bgSheet.png
o http://x.myspacecdn.com/modules/browse/static/img/btnicons_tiled.gif
o http://x.myspacecdn.com/modules/common/static/css/global_-cca62xx.css
o http://x.myspacecdn.com/modules/common/static/css/uploadcontrol_ioe1imsn.css
o http://x.myspacecdn.com/modules/browse/static/css/browse_qiz4yewv.css
o http://x.myspacecdn.com/modules/profilesdirectory/static/css/browsebyname_4vb3esmf.css
o http://x.myspacecdn.com/modules/common/static/img/spacer.gif
o http://x.myspacecdn.com/modules/common/static/img/onlinenow2.gif
o http://x.myspacecdn.com/modules/splash/static/img/moduleBg.gif
o http://bid.ace.advertising.com/bid/ebs=1/site=744646/size=728090/tags=1/callback=C1Oh4Km2Df6V.b1Se4Ps2Yz6Z/bnum=1285590149484
o http://bid.ace.advertising.com/ctst=1/bid/ebs=1/site=744646/size=728090/tags=1/callback=C1Oh4Km2Df6V.b1Se4Ps2Yz6Z/bnum=1285590149484
o http://ad.yieldmanager.com/getbid?Z=160×600&s=796240&_salt=1285590149593&r=1&callback=C1If6Zm8Hd5V.b0Gd6Rh8Lr5P&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx
o http://ad.yieldmanager.com/getbid?Z=728×90&s=796250&_salt=1285590149484&r=1&callback=C1Oh4Km2Df6V.b0Cy4Ao2Eh6Q&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx
o http://p.ic.tynt.com/b/p?id=bjNOt4bfyr35kFadbiUt4I&ts=1285590150124&t=Browse%20MySpace%20Friends%20and%20Profiles
o http://www.google-analytics.com/ga.js
o http://googleads.g.doubleclick.net/pagead/test_domain.js
o http://googleads.g.doubleclick.net/pagead/imgad?id=CJnNofPJ8OekTxCgARjCBDIIILmZe_THmS8
o http://pagead2.googlesyndication.com/pagead/show_ads.js
o http://pagead2.googlesyndication.com/pagead/expansion_embed.js
o http://pagead2.googlesyndication.com/pagead/render_ads.js
Other details
* The following ports were open in the system:
Port Protocol Process
1058 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1092 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
Registry Modifications
* The newly created Registry Values are:
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”
so that nvsvc32.exe runs every time Windows starts
Memory Modifications
* There was a new process created in the system:
Process Name Process Filename Main Module Size
nvsvc32.exe %Windir%nvsvc32.exe 3 129 344 bytes
* The following system service was modified:
Service Name Display Name New Status Service Filename
wuauserv Automatic Updates “Stopped” %System%svchost.exe -k netsvcs
File System Modifications
* The following files were created in the system:
# Filename(s) File Size File Hash Alias
1 %Windir%mdll.dl 2 351 bytes MD5: 0xEC5EA274DAE04031B7838891DD2D80C4
SHA-1: 0xF1A8E07B5B14F09CE81A1394900F2F7F7659C502 (not available)
2 %Windir%nvsvc32.exe
[file and pathname of the sample #1] 81 920 bytes MD5: 0x62B1CF2B9315C867C41C9B213C345E62
SHA-1: 0x1ECAD200D3C55B7D41A3BB39CB6EC8FC4EED032E Trojan.Win32.Jorik.IRCbot.gn [Kaspersky Lab]
Generic.dx!tvo [McAfee]
Mal/Generic-L [Sophos]
Backdoor:Win32/IRCbot.gen!M [Microsoft]
Win-Trojan/Seint.81920.V [AhnLab]
3 %Windir%wintybrd.png 3 416 bytes MD5: 0xD3A3A9391EA080EDFEF8BA202CC36D2E
SHA-1: 0xD771C5BA93DC6FC0438AF3FF1E909338F63EC283 (not available)
4 %Windir%wintybrdf.jpg 3 968 bytes MD5: 0xE246233F7DCFE923D7A54F29B63CC30E
SHA-1: 0xB512DA23F7D01E8BD23133583103A83DC6D5C787 (not available)