弹个窗口
别的事情都没干成 - 0041B738 PUSH sv0host.0041B810 ASCII "advapi32.dll"
- 0041B757 PUSH sv0host.0041B810 ASCII "advapi32.dll"
- 0041B77A PUSH sv0host.0041B820 ASCII "QueryServiceConfig2A"
- 0041B78F PUSH sv0host.0041B838 ASCII "QueryServiceConfig2W"
- 0041B7AE PUSH sv0host.0041B850 ASCII "ChangeServiceConfig2A"
- 0041B7C3 PUSH sv0host.0041B868 ASCII "ChangeServiceConfig2W"
- 0041B810 ASCII "advapi32.dll",0
- 0041B820 ASCII "QueryServiceConf"
- 0041B830 ASCII "ig2A",0
- 0041B838 ASCII "QueryServiceConf"
- 0041B848 ASCII "ig2W",0
- 0041B850 ASCII "ChangeServiceCon"
- 0041B860 ASCII "fig2A",0
- 0041B868 ASCII "ChangeServiceCon"
- 0041B878 ASCII "fig2W",0
- 0041C70E PUSH sv0host.0041C72C ASCII "open"
- 0041C72C ASCII "open",0
- 0041C76C MOV EDX,sv0host.0041C7D8 ASCII "\Software\Microsoft\Internet Explorer\Main"
- 0041C78B MOV EDX,sv0host.0041C80C ASCII "Start Page"
- 0041C7D8 ASCII "\Software\Micros"
- 0041C7E8 ASCII "oft\Internet Exp"
- 0041C7F8 ASCII "lorer\Main",0
- 0041C80C ASCII "Start Page",0
- 0041C83C MOV EDX,sv0host.0041C8B0 ASCII "\Software\Microsoft\Windows\CurrentVersion\Policies\System"
- 0041C85B MOV EDX,sv0host.0041C8F4 ASCII "DisableRegistryTools"
- 0041C86C MOV EDX,sv0host.0041C8F4 ASCII "DisableRegistryTools"
- 0041C87D MOV EDX,sv0host.0041C8F4 ASCII "DisableRegistryTools"
- 0041C8B0 ASCII "\Software\Micros"
- 0041C8C0 ASCII "oft\Windows\Curr"
- 0041C8D0 ASCII "entVersion\Polic"
- 0041C8E0 ASCII "ies\System",0
- 0041C8F4 ASCII "DisableRegistryT"
- 0041C904 ASCII "ools",0
- 0041C964 DD sv0host.0041CACA ASCII 0A,"TSpySocket"
- 0041CACB ASCII "TSpySocket"
- 0041CD62 MOV EDX,sv0host.0041CDD8 ASCII "tcp"
- 0041CDD8 ASCII "tcp",0
- 0041CFE4 ASCII "
- ",0
- 0041CFF0 ASCII "-",0
- 0041D01D ASCII "spy_sckt"
- 0041D0A2 MOV EDX,sv0host.0041D40C ASCII ":"
- 0041D16D PUSH sv0host.0041D444 ASCII "
- "
- 0041D18C PUSH sv0host.0041D444 ASCII "
- "
- 0041D1D6 MOV EDX,sv0host.0041D40C ASCII ":"
- 0041D26B PUSH sv0host.0041D444 ASCII "
- "
- 0041D2BB PUSH sv0host.0041D444 ASCII "
- "
- 0041D40C ASCII ":",0
- 0041D418 ASCII " ",0
- 0041D424 ASCII "0",0
- 0041D444 ASCII "
- ",0
- 0041D56F MOV EDX,sv0host.0041D834 ASCII "\*.*"
- 0041D57E MOV EDX,sv0host.0041D844 ASCII "*.*"
- 0041D68F MOV EDX,sv0host.0041D85C ASCII ".."
- 0041D6BB MOV EDX,sv0host.0041D874 ASCII "1 "
- 0041D6CA MOV EDX,sv0host.0041D880 ASCII "0 "
- 0041D834 ASCII "\*.*",0
- 0041D844 ASCII "*.*",0
- 0041D850 ASCII ".",0
- 0041D85C ASCII "..",0
- 0041D868 ASCII " ",0
- 0041D874 ASCII "1 ",0
- 0041D880 ASCII "0 ",0
- 0041D88C ASCII "
- ",0
- 0041D921 DD sv0host.0041DB08 ASCII "1 "
- 0041D930 DD sv0host.0041DB14 ASCII "0 "
- 0041DAFC ASCII " ",0
- 0041DB08 ASCII "1 ",0
- 0041DB14 ASCII "0 ",0
- 0041DB20 ASCII "
- ",0
- 0041E058 MOV EDX,sv0host.0041E180 ASCII "OK"
- 0041E180 ASCII "OK",0
- 0041E2E5 MOV EDX,sv0host.0041E43C ASCII "OK"
- 0041E43C ASCII "OK",0
- 0041E459 ASCII "spy_sckt"
- 0041E535 MOV ECX,sv0host.0041E75C ASCII ".z"
- 0041E566 MOV EDX,sv0host.0041E75C ASCII ".z"
- 0041E75C ASCII ".z",0
- 0041E980 MOV ECX,sv0host.0041EA6C ASCII "\foxserv.ini"
- 0041E9A2 MOV EDX,sv0host.0041EA84 ASCII "COMMON"
- 0041E9B3 MOV ECX,sv0host.0041EA94 ASCII "127.0.0.1"
- 0041E9B8 MOV EDX,sv0host.0041EAA8 ASCII "ServerAddr"
- 0041E9D7 MOV ECX,sv0host.0041EABC ASCII "80"
- 0041E9DC MOV EDX,sv0host.0041EAC8 ASCII "ServerPort"
复制代码
[ 本帖最后由 promised 于 2007-9-14 17:51 编辑 ] |