文本字符串参考位于 1:.Upack
地址 反汇编 文本字符
004015AA cmp eax,-1 (初始 CPU 选择)
00401770 mov edx,1.004017B0 ASCII "hj.dll"
0040183B mov edx,1.00401858 ASCII "KVXP_Monitor"
0040186B mov edx,1.00401888 ASCII "Q360SafeMonClass"
0040195C mov edx,1.00401984 ASCII "AVP.Tray"
004019C5 mov edx,1.00401A80 ASCII "AVP.Tray"
00401A01 mov edx,1.00401A8C ASCII "AVP.TrafficMonConnectionTerm"
00401A26 mov edx,1.00401AAC ASCII "AVP.Button"
00401AF1 mov edx,1.00401C68 ASCII "$kmu87ytg.bat"
00401B7E mov edx,1.00401C78 ASCII "
"
00401BA0 mov edx,1.00401C7C ASCII "if exist "
00401BBA mov edx,1.00401C88 ASCII "goto try
"
00401BDC mov edx,1.00401C94 ASCII "del %0"
00401DAF mov edx,1.004040E7 ASCII 0A,"ccc0318f0f"
00401DC6 mov edx,1.00402048 ASCII "HJ"
00401DFE mov edx,1.0040204C ASCII "VerClsid.exe"
00401EAD mov edx,1.00402060 ASCII "dllfile"
00401F03 push 1.00402068 ASCII "jksHook"
00401F18 push 1.00402070 ASCII "jtzHook"
00401F2D mov edx,1.00402078 ASCII "LKOL93KFGKM7DX"
是厄,木马应该是的,不过懒得往下跟,要替换一个系统文件,不想折腾了 |