Remote Host Port Number
94.102.208.149 4244
NICK pLagUe{Sion Lloyd}45858
NICK pLagUe{Sion Lloyd}18662
NICK pLagUe{Sion Lloyd}78460
NICK pLagUe{Sion Lloyd}94983
NICK pLagUe{Sion Lloyd}01890
NICK pLagUe{Sion Lloyd}43121
NICK pLagUe{Sion Lloyd}39280
NICK pLagUe{Sion Lloyd}76613
NICK pLagUe{Sion Lloyd}89738
NICK pLagUe{Sion Lloyd}56398
NICK pLagUe{Sion Lloyd}82894
NICK pLagUe{Sion Lloyd}82039
NICK pLagUe{Sion Lloyd}87885
NICK pLagUe{Sion Lloyd}23853
NICK pLagUe{Sion Lloyd}01645
NICK pLagUe{Sion Lloyd}88666
NICK pLagUe{Sion Lloyd}36740
NICK pLagUe{Sion Lloyd}54177
NICK pLagUe{Sion Lloyd}80205
NICK pLagUe{Sion Lloyd}14627
* The following ports were open in the system:
Port Protocol Process
1054 TCP services.exe (%Windir%services.exe)
1056 TCP services.exe (%Windir%services.exe)
Registry Modifications
* The newly created Registry Value is:
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
+ services = “services.exe”
so that services.exe runs every time Windows starts
Memory Modifications
* There was a new process created in the system:
Process Name Process Filename Main Module Size
services.exe %Windir%services.exe 352 256 bytes