- 00509A53 MOV EDX,Unistall.00509ACC ASCII "SYSTEM\CurrentControlSet\Services"
- 00509A67 MOV ECX,Unistall.00509AF0 ASCII "Description"
- 00509ACC ASCII "SYSTEM\CurrentCo"
- 00509ADC ASCII "ntrolSet\Service"
- 00509AEC ASCII "s",0
- 00509AF0 ASCII "Description",0
- 00509BBE MOV ECX,Unistall.00509C04 ASCII "Vermin.dll"
- 00509BD1 MOV EDX,Unistall.00509C18 ASCII "BoxIn"
- 00509C04 ASCII "Vermin.dll",0
- 00509C18 ASCII "BoxIn",0
- 00509CD6 MOV EDX,Unistall.00509DE0 ASCII "LocalSystem"
- 00509CEA MOV EDX,Unistall.00509DF4 ASCII "SYSTEM"
- 00509DE0 ASCII "LocalSystem",0
- 00509DF4 ASCII "SYSTEM",0
- 00509E7B MOV EDX,Unistall.00509EE4 ASCII "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options"
- 00509E8F MOV ECX,Unistall.00509F30 ASCII "Debugger"
- 00509EE4 ASCII "SOFTWARE\Microso"
- 00509EF4 ASCII "ft\Windows NT\Cu"
- 00509F04 ASCII "rrentVersion\Ima"
- 00509F14 ASCII "ge File Executio"
- 00509F24 ASCII "n Options",0
- 00509F30 ASCII "Debugger",0
- 00509F53 PUSH Unistall.0050A0D8 ASCII "NotifyWnd"
- 00509F71 PUSH Unistall.0050A0E4 ASCII "Afx:400000:0"
- 00509F83 PUSH Unistall.0050A0F4 ASCII "Button"
- 00509FA4 PUSH Unistall.0050A0FC ASCII "AVP.AlertDialog"
- 00509FC2 PUSH Unistall.0050A10C ASCII "AVP.Product_Notification"
- 00509FE3 PUSH Unistall.0050A134 ASCII "#32770"
- 0050A004 PUSH Unistall.0050A14C UNICODE "#32770"
- 0050A022 PUSH Unistall.0050A15C ASCII "###McAlertWindow###"
- 0050A05C PUSH Unistall.0050A134 ASCII "#32770"
- 0050A096 PUSH Unistall.0050A134 ASCII "#32770"
- 0050A0D8 ASCII "NotifyWnd",0
- 0050A0E4 ASCII "Afx:400000:0",0
- 0050A0F4 ASCII "Button",0
- 0050A0FC ASCII "AVP.AlertDialog",0
- 0050A10C ASCII "AVP.Product_Noti"
- 0050A11C ASCII "fication",0
- 0050A134 ASCII "#32770",0
- 0050A14C UNICODE "#32770",0
- 0050A15C ASCII "###McAlertWindow"
- 0050A16C ASCII "###",0
- 0050A338 PUSH EBP (初始 CPU 选择)
- 0050A394 MOV ECX,Unistall.0050A8A8 ASCII "inf"
- 0050A418 MOV EAX,Unistall.0050A8C4 ASCII "install"
- 0050A449 MOV ECX,Unistall.0050A8D4 ASCII "ctfmon.exe"
- 0050A44E MOV EDX,Unistall.0050A8E8 ASCII "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" 镜像劫持
- 0050A46E PUSH Unistall.0050A934 ASCII "Open"
- 0050A491 MOV EDX,Unistall.0050A8D4 ASCII "ctfmon.exe"
- 0050A51E MOV ECX,Unistall.0050A944 ASCII "Vermin.dll"
- 0050A534 MOV EDX,Unistall.0050A958 ASCII "mimo"
- 0050A539 MOV EAX,Unistall.0050A968 ASCII "page1"
- 0050A54D MOV EAX,Unistall.0050A8C4 ASCII "install"
- 0050A589 MOV EDX,Unistall.0050A978 ASCII "Ver"
- 0050A58E MOV EAX,Unistall.0050A984 ASCII "SOFTWARE\Microsoft\DataAccess"
- 0050A5F5 MOV EAX,Unistall.0050A9AC ASCII "Explorer.exe"
- 0050A64F PUSH Unistall.0050A9BC ASCII "FE9D1162-1B76-4C34-8CBA-3175B81B5CCF"
- 0050A67B PUSH Unistall.0050A9BC ASCII "FE9D1162-1B76-4C34-8CBA-3175B81B5CCF"
- 0050A6F8 MOV EAX,Unistall.0050A8D4 ASCII "ctfmon.exe"
- 0050A707 MOV EAX,Unistall.0050A9EC ASCII "KAVStart.exe"
- 0050A73E MOV ECX,Unistall.0050AA04 ASCII "ghost.exe"
- 0050A7C2 PUSH Unistall.0050AA10 ASCII "EA458F55-17CC-4B5B-A80F-78B211540E1B"
- 0050A843 PUSH Unistall.0050AA10 ASCII "EA458F55-17CC-4B5B-A80F-78B211540E1B"
-
复制代码 |