C:\ABC\123\Finddir.exe - 特征码 'Trojan-Spy.Win32.Delf.rx' 被发现
- 00404103 PUSH Finddir.004054B8 ASCII "Find"
- 00404108 PUSH Finddir.004054C8 ASCII "dir.exe"
- 0040412F PUSH Finddir.004054D8 ASCII "Fin"
- 00404134 PUSH Finddir.004054E4 ASCII "ddir.exe"
- 004041D5 MOV EDX,Finddir.0040551C ASCII "xia1.exe"
- 004041E8 PUSH Finddir.00405528 ASCII "Http://down.v369v.com/update/update.exe"
- 0040425F PUSH Finddir.0040551C ASCII "xia1.exe"
- 0040428A MOV EDX,Finddir.0040551C ASCII "xia1.exe"
- 004042B3 MOV EDX,Finddir.004055A0 ASCII "xia2.exe"
- 004042C6 PUSH Finddir.004055AC ASCII "http://down.v369v.com/update/sms1s.exe"
- 00404326 MOV EDX,Finddir.004055A0 ASCII "xia2.exe"
- 0040435E PUSH Finddir.004055A0 ASCII "xia2.exe"
- 0040438D MOV EDX,Finddir.004055F4 ASCII "xia3.exe"
- 004043A0 PUSH Finddir.00405600 ASCII "http://down.v369v.com/update/sms2s.exe"
- 00404400 MOV EDX,Finddir.004055F4 ASCII "xia3.exe"
- 00404438 PUSH Finddir.004055F4 ASCII "xia3.exe"
- 0040446D MOV EDX,Finddir.00405648 ASCII "xia4.exe"
- 00404483 PUSH Finddir.00405654 ASCII "http://down.v369v.com/update/sms3s.exe"
- 004044FE MOV EDX,Finddir.00405648 ASCII "xia4.exe"
- 00404545 PUSH Finddir.00405648 ASCII "xia4.exe"
- 00404580 MOV EDX,Finddir.0040569C ASCII "xia5.exe"
- 00404596 PUSH Finddir.004056A8 ASCII "http://down.v369v.com/update/sms4s.exe"
- 00404611 MOV EDX,Finddir.0040569C ASCII "xia5.exe"
- 00404658 PUSH Finddir.0040569C ASCII "xia5.exe"
- 00404693 MOV EDX,Finddir.004056F0 ASCII "xia6.exe"
- 004046A9 PUSH Finddir.004056FC ASCII "http://down.v369v.com/update/sms5s.exe"
- 00404724 MOV EDX,Finddir.004056F0 ASCII "xia6.exe"
- 0040476B PUSH Finddir.004056F0 ASCII "xia6.exe"
- 004047A6 MOV EDX,Finddir.00405744 ASCII "xia7.exe"
- 004047BC PUSH Finddir.00405750 ASCII "http://down.v369v.com/update/sms6s.exe"
- 00404837 MOV EDX,Finddir.00405744 ASCII "xia7.exe"
- 0040487E PUSH Finddir.00405744 ASCII "xia7.exe"
- 004048B9 MOV EDX,Finddir.00405798 ASCII "xia8.exe"
- 004048CF PUSH Finddir.004057A4 ASCII "http://down.v369v.com/update/sms7s.exe"
- 0040494A MOV EDX,Finddir.00405798 ASCII "xia8.exe"
- 00404991 PUSH Finddir.00405798 ASCII "xia8.exe"
- 004049CC MOV EDX,Finddir.004057EC ASCII "xia9.exe"
- 004049E2 PUSH Finddir.004057F8 ASCII "http://down.v369v.com/update/sms8s.exe"
- 00404A5D MOV EDX,Finddir.004057EC ASCII "xia9.exe"
- 00404AA4 PUSH Finddir.004057EC ASCII "xia9.exe"
- 00404ADF MOV EDX,Finddir.00405840 ASCII "xia10.exe"
- 00404AF5 PUSH Finddir.0040584C ASCII "http://down.v369v.com/update/sms9s.exe"
- 00404B70 MOV EDX,Finddir.00405840 ASCII "xia10.exe"
- 00404BB7 PUSH Finddir.00405840 ASCII "xia10.exe"
- 00404BF2 MOV EDX,Finddir.00405894 ASCII "xia11.exe"
- 00404C08 PUSH Finddir.004058A0 ASCII "http://down.v369v.com/update/sms0s.exe"
- 00404C83 MOV EDX,Finddir.00405894 ASCII "xia11.exe"
- 00404CCA PUSH Finddir.00405894 ASCII "xia11.exe"
- 00404D05 MOV EDX,Finddir.004058E8 ASCII "xia12.exe"
- 00404D1B PUSH Finddir.004058F4 ASCII "PPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPP"
- 00404D96 MOV EDX,Finddir.004058E8 ASCII "xia12.exe"
- 00404DDD PUSH Finddir.004058E8 ASCII "xia12.exe"
- 00404E18 MOV EDX,Finddir.0040593C ASCII "xia13.exe"
- 00404E2E PUSH Finddir.00405948 ASCII "QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ"
- 00404EA9 MOV EDX,Finddir.0040593C ASCII "xia13.exe"
- 00404EF0 PUSH Finddir.0040593C ASCII "xia13.exe"
- 00404F2B MOV EDX,Finddir.00405990 ASCII "xia14.exe"
- 00404F41 PUSH Finddir.0040599C ASCII "RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR"
- 00404FBC MOV EDX,Finddir.00405990 ASCII "xia14.exe"
- 00405003 PUSH Finddir.00405990 ASCII "xia14.exe"
- 0040503E MOV EDX,Finddir.004059E4 ASCII "xia15.exe"
- 00405054 PUSH Finddir.004059F0 ASCII "SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS"
- 004050CF MOV EDX,Finddir.004059E4 ASCII "xia15.exe"
- 00405116 PUSH Finddir.004059E4 ASCII "xia15.exe"
- 00405151 MOV EDX,Finddir.00405A38 ASCII "xia16.exe"
- 00405167 PUSH Finddir.00405A44 ASCII "TTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT"
- 004051E2 MOV EDX,Finddir.00405A38 ASCII "xia16.exe"
- 00405229 PUSH Finddir.00405A38 ASCII "xia16.exe"
- 00405264 MOV EDX,Finddir.00405A8C ASCII "xia17.exe"
- 0040527A PUSH Finddir.00405A98 ASCII "KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK"
- 004052F5 MOV EDX,Finddir.00405A8C ASCII "xia17.exe"
- 0040533C PUSH Finddir.00405A8C ASCII "xia17.exe"
- 00405377 MOV EDX,Finddir.00405AE0 ASCII "xia18.exe"
- 0040538D PUSH Finddir.00405AEC ASCII "MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM"
- 00405408 MOV EDX,Finddir.00405AE0 ASCII "xia18.exe"
- 0040544F PUSH Finddir.00405798 ASCII "xia8.exe"
复制代码 |