Month: October 2010

team.radiozeri.de(lolbot hosted in France Clermont-ferrand Ovh Sas)

Uncategorized

Resolved : [team.radiozeri.de] To [91.186.15.64] Resolved : [team.radiozeri.de] To [66.187.108.124] Resolved : [team.radiozeri.de] To [66.187.101.231] Resolved : [team.radiozeri.de] To [94.23.8.138] Remote Host Port Number team.radiozeri.de 81 NICK n[USA|XP]0968364 USER s “” “lol” :s JOIN #newbin# NICK [USA|XP]2578635 NICK [USA|XP]9864029 Other details * To mark the presence in the system, the following Mutex object was created:Read more...

23u.no-ip.info

Uncategorized

Remote Host Port Number 23u.no-ip.info 51987 Resolved : [3u.no-ip.info] To [82.146.49.176] PASS google_cache2.tmp NICK NEW{EpicBot-USA|XP}615228 USER 7570 “” “TsGh” :7570 JOIN #Cheese# Registry Modifications * The newly created Registry Values are: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + Windows Simatic Updates = “%Windir%winlogon.exe” + UserFaultCheck = “%System%dumprep 0 -u” so that winlogon.exe runs every time Windows starts o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]Read more...

66.187.110.154

Uncategorized

Remote Host Port Number 66.187.110.154 81 NICK n[USA|XP|COMPUTERNAME]kspycmw USER n “” “lol” :n JOIN #biz# PONG 422 * The following directory was created: o %AppData%C-76947-8457-2745 Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + WindowsDriverControl = “%AppData%C-76947-8457-2745winmsngrn.exe” so that winmsngrn.exe runs every time Windows starts File System Modifications * The following filesRead more...

64.20.46.176

Uncategorized

Remote Host Port Number 64.20.46.176 81 67.195.145.141 80 * The data identified by the following URL was then requested from the remote web server: o http://wallprofiles.net/pic.exe NICK n[USA|XP|COMPUTERNAME]putuqyw USER n “” “lol” :n JOIN #biz# PONG 422 Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + WindowsDriverControl = “%AppData%C-76947-8457-2745wincdrsvn.exe” so that wincdrsvn.exeRead more...

184.106.215.31

Uncategorized

Remote Host Port Number 184.106.215.31 6667 NICK {XPUSA874460} JOIN ##spam## PRIVMSG ##spam## :.::[MSN]::. Enviando Mensaje. PONG irc.priv8net.com USER COMPUTERNAME * 0 :COMPUTERNAME MODE {XPUSA874460} -ix Registry Modifications * The newly created Registry Values are: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + Windows Services = “service.exe” so that service.exe runs every time Windows starts o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + Windows Update =Read more...

66.187.108.124

Uncategorized

Remote Host Port Number 66.187.108.124 81 NICK n[USA|XP|COMPUTERNAME]fgfbdpb USER n “” “lol” :n JOIN #biz# PONG 422 Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + WindowsDriverControl = “%AppData%C-76947-8457-2745wincdrsvn.exe” so that wincdrsvn.exe runs every time Windows starts File System Modifications * The following files were created in the system: # Filename(s) FileRead more...

dalga.co.cc

Uncategorized

NICK acelya USER ferda_54 “Cod” “dalga.co.cc” :Perihan^^^^ USERHOST acelya JOIN #x birtanem }. MODE #x NOTICE acelya :.VERSION mIRC v6.03 Khaled Mardam-Bey. NOTICE acelya :.version mIRC v6.16 Khaled Mardam-Bey. NOTICE IRC :.version mIRC v6.16 Khaled Mardam-Bey. NOTICE Version :.version mIRC v6.16 Khaled Mardam-Bey. PRIVMSG #x :Sahip , Sana Hizmete Haz.r.m ( v2 ) NICK Cansu4Read more...

173.1.102.35

Uncategorized

Remote Host Port Number 173.1.102.35 81 NICK n[USA|XP|COMPUTERNAME]stnlxlc USER n “” “lol” :n JOIN #biz# PONG 422 JOIN #USA# (null) Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + WindowsDriverControl = “%AppData%C-76947-8457-2745winmsngrn.exe” so that winmsngrn.exe runs every time Windows starts File System Modifications * The following files were created in the system:Read more...

91.211.117.33

Uncategorized

Remote Host Port Number 91.211.117.33 6667 NICK {XPUSA933915} JOIN ##spam## PONG irc.priv8net.com USER COMPUTERNAME * 0 :COMPUTERNAME MODE {XPUSA933915} -ix Registry Modifications * The newly created Registry Values are: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + Windows Services = “service.exe” so that service.exe runs every time Windows starts o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + Windows Update = “%Temp%service.exe” so that service.exe runsRead more...

updateserver.net

Uncategorized

Remote Host Port Number 66.187.108.125 81 NICK n[USA|XP|COMPUTERNAME]vdpunpf USER n “” “lol” :n JOIN #biz# PONG 422 JOIN #USA# (null) Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + WindowsDriverControl = “%AppData%C-76947-8457-2745winmsngrn.exe” so that winmsngrn.exe runs every time Windows starts File System Modifications * The following files were created in the system:Read more...