Remote Host Port Number
quasar.mooo.com 7000
NICK vinithap
USER arthur “” “quasar.mooo.com” :gun
USERHOST nick
PART channel
SILENCE +*!*@*,~*!*@*undernet.org
MODE vinithap +iwx
MODE nick +iwx
NICK jadan
USER mckayla “” “quasar.mooo.com” :zeros
MODE jadan +iwx
USER arthur “” “lidingo.se.eu.undernet.org” :gun
USERHOST vinithap
NICK :thiame
MODE vinithap +i
ISON andrei Denisa devil Jumper liliana Linux maria mordor Petri play pOrn ReBe Robert Roberto sex sexy shaty unix
USER mod “” “lidingo.se.eu.undernet.org” :suzanna
NICK :nevadag
USER minye “” “lidingo.se.eu.undernet.org” :tool
NICK :mayaj
USER mckayla “” “lidingo.se.eu.undernet.org” :zeros
USERHOST jadan
NICK :mekhih
MODE jadan +i
USER santiago “” “lidingo.se.eu.undernet.org” :deborah
NICK :gripee
 * There was application-defined hook procedure installed into the hook chain (e.g. to monitor keystrokes). The installed hook is handled by the following module:
 o %Windir%tempspoolsvspoolsv.exe
Registry Modifications
 * The following Registry Keys were created:
 o HKEY_LOCAL_MACHINESOFTWAREClasses.cha
 o HKEY_LOCAL_MACHINESOFTWAREClasses.chat
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFile
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileDefaultIcon
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShell
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopen
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopencommand
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexec
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexecApplication
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexecifexec
 o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexecTopic
 o HKEY_LOCAL_MACHINESOFTWAREClassesirc
 o HKEY_LOCAL_MACHINESOFTWAREClassesircDefaultIcon
 o HKEY_LOCAL_MACHINESOFTWAREClassesircShell
 o HKEY_LOCAL_MACHINESOFTWAREClassesircShellopen
 o HKEY_LOCAL_MACHINESOFTWAREClassesircShellopencommand
 o HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexec
 o HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexecApplication
 o HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexecifexec
 o HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexecTopic
 o HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallmIRC
 o HKEY_LOCAL_MACHINESYSTEMControlSet001Servicessvchost
 o HKEY_LOCAL_MACHINESYSTEMControlSet001ServicessvchostParameters
 o HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessvchost
 o HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessvchostParameters
 o HKEY_CURRENT_USERSoftwareMicrosoftMicrosoft Agent
 o HKEY_CURRENT_USERSoftwaremIRC
 o HKEY_CURRENT_USERSoftwaremIRCChannels
 o HKEY_CURRENT_USERSoftwaremIRCLicense
 o HKEY_CURRENT_USERSoftwaremIRCLockOptions
 o HKEY_CURRENT_USERSoftwaremIRC%UserName%
 o HKEY_CURRENT_USERSoftwareWinRAR SFX
 * Notes:
 o %UserName% is a variable that refers to the current user name.
 * The newly created Registry Values are:
 o [HKEY_LOCAL_MACHINESOFTWAREClasses.cha]
 + (Default) = “ChatFile”
 o [HKEY_LOCAL_MACHINESOFTWAREClasses.chat]
 + (Default) = “ChatFile”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexecTopic]
 + (Default) = “Connect”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexecifexec]
 + (Default) = “%1”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexecApplication]
 + (Default) = “svchost”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopenddeexec]
 + (Default) = “%1”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopencommand]
 + (Default) = “”%Windir%tempspoolsvspoolsv.exe” -noconnect”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesChatFileDefaultIcon]
 + (Default) = “”%Windir%tempspoolsvspoolsv.exe””
 o [HKEY_LOCAL_MACHINESOFTWAREClassesChatFile]
 + (Default) = “Chat File”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexecTopic]
 + (Default) = “Connect”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexecifexec]
 + (Default) = “%1”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexecApplication]
 + (Default) = “svchost”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesircShellopenddeexec]
 + (Default) = “%1”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesircShellopencommand]
 + (Default) = “”%Windir%tempspoolsvspoolsv.exe” -noconnect”
 o [HKEY_LOCAL_MACHINESOFTWAREClassesircDefaultIcon]
 + (Default) = “”%Windir%tempspoolsvspoolsv.exe””
 o [HKEY_LOCAL_MACHINESOFTWAREClassesirc]
 + (Default) = “URL:IRC Protocol”
 + EditFlags = 02 00 00 00
 + URL Protocol = “”
 o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
 + spoolsv = “”%Windir%tempspoolsvspoolsv.exe””
 so that spoolsv.exe runs every time Windows starts
 o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallmIRC]
 + DisplayName = “mIRC”
 + UninstallString = “”%Windir%tempspoolsvspoolsv.exe” -uninstall”
 o [HKEY_LOCAL_MACHINESYSTEMControlSet001ServicessvchostParameters]
 + Application = “”%Windir%tempspoolsvspoolsv.exe””
 + AppDirectory = “”%Windir%tempspoolsvspoolsv.exe””
 o [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessvchostParameters]
 + Application = “”%Windir%tempspoolsvspoolsv.exe””
 + AppDirectory = “”%Windir%tempspoolsvspoolsv.exe””
 o [HKEY_CURRENT_USERSoftwareMicrosoftMicrosoft Agent]
 + VoiceEnabled = 0x00000001
 + UseVoiceTips = 0x00000001
 + KeyHoldHotKey = 0x00000091
 + UseBeepSRPrompt = 0x00000001
 + SRTimerDelay = 0x000007D0
 + SRModeID = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
 + EnableSpeaking = 0x00000001
 + UseBalloon = 0x00000001
 + UseCharacterFont = 0x00000001
 + UseSoundEffects = 0x00000001
 + SpeakingSpeed = 0x00000005
 + PropertySheetX = 0x000F423F
 + PropertySheetY = 0x000F423F
 + PropertySheetWidth = 0x00000000
 + PropertySheetHeight = 0x00000000
 + PropertySheetPage = 0x00000000
 + CommandsWindowLeft = 0xFFFFFFFF
 + CommandsWindowTop = 0xFFFFFFFF
 + CommandsWindowWidth = 0x000000C8
 + CommandsWindowHeight = 0x000000C8
 + CommandsWindowLocationSet = 0x00000000
 o [HKEY_CURRENT_USERSoftwaremIRC%UserName%]
 + (Default) = “WhiteHat”
 o [HKEY_CURRENT_USERSoftwaremIRCLockOptions]
 + (Default) = “0,4096”
 o [HKEY_CURRENT_USERSoftwaremIRCLicense]
 + (Default) = “5662-546732”
 o [HKEY_CURRENT_USERSoftwareWinRAR SFX]
 + C%%Windows%temp%spoolsv% = “%Windir%tempspoolsv”